For years, the working assumption inside most Critical Information Infrastructure (CII) organizations has been that a clean audit equals a secure environment. On 22 July 2026, Singapore’s Cyber Security Agency (CSA) said, in effect, that assumption is over. Announcing the first update to the Cybersecurity Code of Practice (CCoP) since 2022, Minister Josephine Teo framed the shift in three words: lock down, find first, fix fast. That’s not a compliance slogan. It’s an admission that activity — audits completed, controls documented, boxes ticked — was never the same thing as safety.
Raising the Bar for CII Owners
The CCoP 2026 update, layered on top of the Cybersecurity Act amendments already in force since May 2024, raises the bar in four concrete ways for CII owners. Boards and senior management now own cyber resilience directly. They are required to create a documented framework covering risk tolerance, mitigation, transfer, and recovery, reviewed at least annually, rather than a program security teams attest to on their behalf.
CII owners must also attain Cyber Trust Mark Level 5 certification, the highest tier in Singapore’s cybersecurity rating scheme. Oversight extends beyond the CII itself to the networks, vendors, and third-party environments that touch it. And CSA will work directly with CII owners to deploy threat detection across network segments, with guidance on adversarial simulation and penetration testing, plus threat hunting practices, following later this year; a companion Code of Practice for Cloud Services arrives in the second half of 2026.
The rationale Teo gave wasn’t abstract. AI now lets attackers find vulnerabilities and scale attacks faster than defenders can review a quarterly report, which compresses the response window from days to hours.
This is Already Happening, Not Hypothetical
Two recent incidents make the case for CSA better than any press release could. The advanced persistent threat group UNC3886 targeted all four of Singapore’s major telcos, triggering what Teo called the country’s largest-ever coordinated cyber response. It’s contained now, but it’s a live example of why “collective resilience is only as strong as our weakest link” just became a board-level requirement.
Separately, a breach inside an IBM-managed development environment exposed the NRIC numbers and addresses of roughly 70,000 people tied to the Singapore Land Authority: a textbook case of the third-party, interconnected-system exposure the amended Act and CCoP 2026 now require organizations to see and disclose.
Why Paperwork Alone Won’t Get Organizations There
The new requirements are tricky for CII owners in a few different ways.Annual board reviews and certification renewals are activity. So are vendor questionnaires. None of them, by themselves, shorten the distance between when a threat actor starts probing and when a security team knows it matters to their specific environment. That distance is exactly what CSA is now asking boards to close across every system connected to the CII. And they want it done continuously, not just once a year.
Meeting that bar requires fusing external threat signal with internal environment context (assets, controls, alert history, and business priority) so that intelligence arrives already tailored to what’s actually exposed, and routes into detection and response without an analyst rebuilding the picture from scratch every time. That’s a different operating model than most CII security programs were built around, and it’s where Dataminr for Cyber Defense’s three solutions each answer a specific part of what CCoP 2026 now demands.
How Dataminr Supports CCoP 2026 Compliance
Client-Tailored Threat Intelligence (CTTI) answers the “find first” mandate directly. By continuously fusing signal from 1M+ sources with an organization’s own exposed assets and controls, CTTI has detected threats with real lead time: 38 days ahead of a Fortinet CVE landing in the CISA Known Exploited Vulnerabilities catalog, and 6+ months of early warning ahead of the PowerSchool breach. That’s the kind of margin boards now need to show they have, not assume they do.
Agentic TI Ops answers the interconnected-systems and cross-team consistency mandate. It operationalizes intelligence into detection, hunting, and response workflows automatically, so the response doesn’t depend on which analyst is on shift or which agency picks up the thread first. A Forbes 2000 healthcare system running this model cut total incident response time from 7 hours to 37 minutes.
Predictive Threat Exposure Management (PTEM) answers the board-accountability mandate itself. A framework reviewed once a year is a snapshot; the exposure it’s meant to cover moves hourly. PTEM continuously quantifies that exposure in financial terms from live telemetry: what’s actually reachable and what it would cost if exploited. Then it shows which fix moves the number, updated as conditions change rather than certified once a year. That’s the difference between a documented program and a defensible one.
Singapore’s regulator has effectively said that resilience has to be continuously provable, not just declared once a year. That’s a higher bar. For organizations willing to treat it as an operating model rather than a filing deadline, it’s also a clearer one.

The Only Intel-driven Threat and Exposure Management Solution Suite
Transform intelligence into a preemptive cyber advantage from first signal to risk-prioritized action.
Learn More