Keynote address by Minister Josephine Teo at the Operational Technology Cybersecurity Expert Panel Forum 2026
22 July 2026
Minister Josephine Teo highlighted AI-driven cyber threats to critical infrastructure, citing Operation Cyber Guardian and recent OT attacks. She outlined Singapore’s strategy to "lock down, find first, fix fast" through stronger standards, AI-enabled defence, threat intelligence and industry collaboration.
Image credit: Ministry of Digital Development and Information (MDDI)
Distinguished guests,
Colleagues and friends
Introduction
1 I am pleased to join you at this year’s OTCEP Forum. Since its founding, the Forum has become a community of practitioners. Through your deep knowledge of OT systems, we are gaining valuable insights on how to better protect Singapore's Critical Information Infrastructure (CII) and for that we are grateful. Thank you for your contributions.
2 As we all know, AI is increasingly reshaping the threat landscape for OT defenders. No single organisation can mount an adequate response on its own. We must therefore work collectively to build stronger capabilities and design more resilient defences. Let me explain our thinking.
3 Earlier this year, I shared that Singapore’s telecommunications sector had been the target of cyberattacks by UNC3886, an Advanced Persistent Threat actor. The campaign was methodical, and all four of our major telcos were hit.
4 Following the detection, CSA, relevant government agencies, and our telcos mounted a coordinated cyber response. We called it “Operation Cyber Guardian”, and it was the largest of its kind in Singapore.
5 Years of planning, conducting regular exercises and building trust made it possible for several organisations that usually operate independently from each other to come together and support this operation. As a result, the attack was contained before the threat actor caused a service disruption or stole sensitive customer data.
6 “Operation Cyber Guardian” reinforces a fundamental reality. Our collective cyber resilience is only as strong as our weakest link. Sophisticated threat actors will be relentless in their search for vulnerabilities and will not hesitate to exploit every opening to go deep into interconnected systems. This makes cybersecurity a shared responsibility for everyone across the entire ecosystem.
7 The UNC3886 campaign is not the first to target Singapore’s CII, nor will it be the last. AI has also challenged a longstanding assumption that the complexity of OT systems keeps them safe from attack.
8 Earlier this year, Dragos documented an attempted breach of a municipal water utility in Monterrey, Mexico. The attacker had no prior OT knowledge. Using commercial AI tools, not the most sophisticated ones, it gained access to the utility's IT network, identified a server connected to the SCADA environment, researched the vendor documentation, and generated login credentials for an automated attack.
9 Fortunately, the attack was unsuccessful. However, the attacker had shown how AI could easily enable amateurs and reduce their preparation time. By compromising an IT network, an attacker can also move quickly into OT environments, given how interconnected the systems are nowadays.
10 Sophisticated attackers are using AI to inflict greater harm. In late December 2025, an attacker in Poland targeted more than 30 wind and solar farms, along with a combined heat and power plant and a manufacturing company. The attacks did not affect ongoing electricity generation or the stability of the Polish power generation system. But they showed that an attacker can coordinate disruptive activities across multiple sites, including OT environments.
11 We are also seeing a more structured threat ecosystem. One group gains initial access through IT systems while a second, more specialised group conducts the OT operations. Their immediate activity often looks like espionage operations for stealing network diagrams or process configurations. But that stolen knowledge is the foundation for creating operational impact sometime in the future.
12 As these developments unfold, most OT environments remain opaque. We often cannot see what is happening inside them, nor do we get detection alerts that will trigger investigations. Instead, we are caught by surprise when someone notices finally that something seems wrong with operations. By then, the attacker may have compromised the system for weeks, if not longer.
13 We need to organise ourselves better for this new threat environment. In Singapore, we believe that our response should consist of three priorities that reinforce one another: lock down, find first, and fix fast.
14 Lock down is about strengthening our baseline defences and our ability to quickly detect and respond when attacked. The goal is to deny the attacker an easy win.
15 Many of the vulnerabilities in OT environments arise from poor cyber hygiene, such as weak passwords and outdated software. Threat actors can use AI to exploit these weak links within hours. They often find hundreds or thousands of vulnerabilities. Stronger cyber hygiene is essential to reduce the entry points that attackers can exploit. But we must still assume that some attacks will still succeed. That is why continuous monitoring, proactive detection, swift response and recovery are equally important.
16 To raise the baseline for every CII owner, CSA is releasing an updated Cybersecurity Code of Practice (CCoP).
17 CII owners will be expected to detect, respond, and recover from attacks. It reflects a fundamental shift from relying on perimeter defences to actively defending against threats. Boards and senior management will be held directly accountable for cyber resilience. Leaders at every level must have the cybersecurity knowledge needed to govern and manage cyber risks effectively. This starts with having clear oversight of their critical assets and putting in place continuous monitoring; after all, you cannot defend assets you did not see, and you cannot recover assets you did not know you have.
18 With CII owners increasingly adopting cloud technologies, “locking down” must also extend to cloud environments and raise their security baseline. That is why CSA will be launching a separate Cybersecurity Code of Practice (CCoP) for Cloud later this year. It will lay out cybersecurity requirements governing the secure deployment, operation, and management of CII systems hosted on cloud.
19 These measures that I have described are focused on CII owners. But the risk does not stop at an organisation's boundary. A compromised vendor or partner can be just as vulnerable an entry point as a misconfigured internal system.
20 This is why we must also strengthen the cybersecurity posture of the manufacturers, vendors and technology partners that develop and supply the technologies underpinning our critical infrastructure. I am encouraged that leading original equipment manufacturers (OEM) and technology providers of OT have committed to be certified under Singapore's Cyber Trust Mark. This will demonstrate that they have implemented robust cybersecurity practices within their own organisations, and that the products and services they deliver meet a recognised standard.
21 We encourage more OEMs, vendors and technology partners to do the same. A trusted and secure supply chain is not optional – it is foundational to the resilience of our critical infrastructure.
22 Even as we try to raise the standards to a much higher level, we cannot close every vulnerability. Some vulnerabilities will remain unknown to us – and what we do not know, we cannot anticipate. We must therefore develop the skills to uncover our vulnerabilities first – identify them before our adversaries do, and fix them before they can be exploited.
23 However, in this race, a private operator rarely has the resources to match an adversary with the state-level backing that many threat actors will have. AI can help. AI-assisted security operations have been shown to compress months of security testing into days. With AI, the bottleneck has also shifted from discovery to action.
24 CSA has therefore launched a sandbox that focuses on using AI for cybersecurity. It will partner vendors and solution providers to pilot AI-enabled security operations across our critical infrastructure. We intend to share the learnings from the pilot with the wider community of cyber defenders. This will boost capabilities in the entire ecosystem, and not just the organisations with the resources to experiment.
25 Our third priority is to be able to fix fast. This requires more efficient prioritisation, greater automation, and practical mitigation measures where systems cannot be patched immediately.
26 To support CII owners in this effort, CSA will continue to share classified threat intelligence. In parallel, every asset owner must grow its capacity to act on the knowledge and insights, and share them.
27 As part of this effort, CSA is renewing its Memorandum of Understanding with Dragos for deeper exchange of threat intelligence and joint capability development. We encourage asset owners to make full use of this initiative to act more quickly to fix their vulnerabilities.
28 In closing, let me return to the theme of this year's Forum which poses the important question of how to defend against advanced OT cyberattacks. The answer is not to wait and respond only when hit. It is to be proactive – lock down, find first, and fix fast.
29 AI has allowed attackers without OT expertise to target critical infrastructure in ways that were not possible before. But it has also put detection and response capability within reach of defenders who previously lacked it. The question is who moves faster.
30 Singapore intends to be on the right side of that race, and the Government is committed to working alongside all of you to protect our critical infrastructure.
31 On that note, I wish you useful discussions and fruitful takeaways. Thank you.
