Singapore Changes Cyber Strategy as AI-Powered Threats Grow

The420.in Staff
6 Min Read

Singapore has shifted its cyber defence strategy after attacks linked to UNC3886, deploying artificial intelligence tools across government systems and stepping up efforts to detect attackers who may already be inside critical networks.

The new approach moves beyond simply trying to keep hackers out. Authorities are placing greater emphasis on continuous monitoring, threat hunting and finding suspicious activity within networks before attackers can cause further damage.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

Why Is Singapore Changing Its Cyber Strategy?

The shift follows an attack on the country’s four major telecommunications operators by state-sponsored cyber espionage group UNC3886. The attacks were first made public in July 2025 and could have disrupted telecommunications and internet services, posing a threat to national security.

Gwenda Fong, chief executive of the Cyber Security Agency of Singapore, said one of the key lessons from the incident was that cyber defences could no longer focus only on preventing attackers from entering networks.

Advanced persistent threat actors can pursue specific targets and remain a persistent danger. The new approach therefore assumes that an attacker may already have gained access and focuses on finding and stopping them before they can cause further harm.

How Is AI Being Used for Cybersecurity?

The Government Technology Agency of Singapore has developed artificial intelligence tools that can perform some of the security work required to protect government systems.

One AI-powered tool carries out automated penetration testing across about 2,000 government systems, including some containing citizen data and transactions. The testing simulates cyberattacks to identify vulnerabilities that hackers could potentially exploit.

A second AI tool examines the source code of government applications and systems for security weaknesses. This is intended to help agencies identify and fix gaps before attackers can take advantage of them.

The agencies did not disclose which government bodies have deployed the tools.

How Will Singapore Find Attackers Already Inside?

Singapore’s strategy places greater emphasis on monitoring internal network traffic, detecting unusual behaviour and conducting continuous threat hunting.

Fong said organisations need to monitor internal traffic and identify anomalous activity rather than relying only on perimeter security.

The approach reflects the possibility that sophisticated attackers may successfully enter a network despite preventive measures. Security teams must therefore be prepared to detect their presence after an initial breach.

What Is Changing for Critical Infrastructure?

Authorities also plan to expand the use of AI security tools into other critical information infrastructure sectors.

Singapore has 11 such sectors, covering government, aviation, healthcare, land transport, maritime, media, security and emergency services, water, banking and finance, energy and info-communications.

The expansion remains under evaluation, with authorities considering operational requirements, effectiveness and the specific needs of individual sectors.

Following the UNC3886 incident, the Cyber Security Agency has also begun regularly scanning internet-facing systems belonging to critical infrastructure operators. The scans look for possible entry points, including unpatched software and weak configurations, before attackers exploit them.

The scans are external and do not involve active probing of the systems.

What Other Cyber Defences Are Being Strengthened?

Singapore has also rolled out proprietary threat-detection tools developed by a technical agency under the Ministry of Defence to critical infrastructure operators and is sharing classified threat intelligence with them.

Authorities are also examining cybersecurity risks within supply chains. An attack against a vendor could compromise data or disrupt services further down the chain.

The Cyber Security Agency is considering requiring some vendors and suppliers of critical infrastructure operators to obtain Cyber Essentials or Cyber Trust mark certifications, potentially as early as 2027.

Why Is Singapore Treating Cybersecurity as a Strategic Issue?

Singapore increasingly views cybersecurity as more than a technical problem. Authorities see it as a strategic issue affecting national security, the digital economy and public trust.

The shift has been linked to the use of cyber operations in strategic competition, geopolitical tensions surrounding access to technologies such as advanced chips and frontier AI models, and society’s growing reliance on digital infrastructure.

The wider concern is that disruptions to digital systems can now affect almost every part of work and everyday life. Singapore’s response is therefore moving towards a model in which preventing intrusion remains important, but detecting and containing attackers who get through the first line of defence is equally critical.

The420 Takeaway

Singapore’s strategy reflects a major shift in cybersecurity thinking. Keeping hackers out is no longer enough. As sophisticated attackers and AI-powered threats grow, organisations must also continuously monitor their networks, detect unusual activity and be prepared to find attackers who have already gained access.

About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected