Mon, 27 Jul 2026

Critical infrastructures still operating without adequate security oversight

Photo by Сергей Велов: https://www.pexels.com/photo/electric-towers-10964248/

Organisations are still running critical information infrastructures (CIIs) without adequate security oversight, even as they digitalise their operations and face new risks as they begin adopting to artificial intelligence (AI).

In its efforts to address this, Singapore wants to hold the higher-ups responsible for the safe operations of their critical infrastructures.

Boards and senior management will face more accountability for their CII organisation's cybersecurity posture, namely, maintaining a documented cyber resilience framework covering risk tolerance, mitigation, transfer, and recovery.

Compromising an IT network allows attackers to move quickly into OT (operational technology) environments due to how interconnected the systems are these days, said Josephine Teo, minister for Digital Development and Information and Minister-in-charge of Cybersecurity and Smart Nation Group.

She pointed to a security incident in late-December 2025, which targeted more than 30 wind and solar farms in Poland, including a heat and power plant and manufacturing company.

The attack did not impact ongoing electricity generation or the country’s power generation system, but revealed how a threat actor was able to coordinate disruptive activities across multiple sites, including OT environments, said Teo, during her speech at the OT Cybersecurity Expert Panel Forum, hosted by Singapore’s Cyber Security Agency (CSA).

She highlighted a more structured threat ecosystem today, where one group would gain initial access through IT systems while a second, more specialised group, would conduct the OT operations.

The stolen and compromised data could lay the foundation for creating operational impact in the future, she said.

Josephine Teo

And amidst these developments, most OT environments remain opaque, she noted.

“We often cannot see what is happening inside them, nor do we get detection alerts that will trigger investigations,” she said. “Instead, we are caught by surprise when someone notices finally that something seems wrong with operations. By then, the attacker may have compromised the system for weeks, if not longer.”

An attack on IT is an attack on OT

The threat landscape has expanded, said Robert M. Lee, CEO and co-founder of OT security vendor, Dragos.

He noted that critical infrastructures, such as power grids, pipelines, manufacturing plants, water facilities, and data centres now depend on systems well outside the traditional control environment.

However, most security programs do not cover these infrastructures, Lee said during his presentation at the forum.

Focus has increased on the cybersecurity of traditional IT systems and AI models themselves, but similar investments in OT have lagged.

OT security incidents often are wrongly labelled as IT-only because the breached workstations run on Windows operating systems, even though they sit on a Scada server, he explained.

Scada, or supervisory control and data acquisition, systems are used in industrial environments to remotely monitor and control physical processes and equipment.

Increased digitalisation in OT environments have created new attack surfaces that are not always adequately secured, Lee said.

With AI expected to be integrated into OT, attack surfaces will further widen, he said, stressing the need for organisations ensure their cyber resiliency.

And the risks for OT sectors are only increasing.

Citing Dragos research, Lee noted that ransomware groups targeting industrial organisations climbed 49% year-on-year, from 90 to 119, affecting 3,300 industrial organisations worldwide last year. Manufacturing companies accounted for more than two-thirds of those impacted.

The average dwell time for ransomware in OT environments clocked at 42 days.

Gartner defines OT as hardware and software that detect or trigger a change through direct monitoring or control of physical industrial devices within an organisation.

AI arms average threat actors with OT capabilities

Teo noted that a cyberattack earlier this year, which targeted a municipal water utility in Monterrey, Mexico, were carried out by threat actors with no prior OT knowledge.

They used commercial AI tools that were not the most sophisticated, to gain access to the utility’s IT network and identify a server connected to the Scada environment, she said. The attackers then researched the vendor documentation and generated login credentials for an automated attack.

While eventually unsuccessful, the Monterrey attack demonstrated how AI could easily enable amateurs and reduce their preparation time to launch attacks, Teo said.

As it is, 65% believe an AI-enabled attack against their organisation is inevitable within the next year, revealed a Mimecast study, which polled 500 cybersecurity and IT decision makers in Singapore and Australia.

Some 79% are concerned about the use of AI as an attack vector against their organisation, with 60% admitting they are not fully prepared to handle AI-enabled threats that exploit human vulnerabilities.

Related:  What banks worry about in 2023

In fact, 66% believe an employee in their enterprise are likely to be hoodwinked by cybercriminals using AI in their social engineering attack.

The study further found that 9% are aware of the threats, but lack a robust defence strategy against such risks.

Teo stressed the need to “organise ourselves better” for the new threat landscape, highlighting three priorities: lock down, find first, and fix fast.

Efforts here should focus on boosting baseline defences and ability to quickly detect and respond when attacked.

“The goal is to deny the attacker an easy win,” Teo said.

Robert M. Lee

She noted that many vulnerabilities in OT environments were the result of poor cyber hygiene, such as outdated software, allowing attackers to use AI to exploit the weak links within hours.

Along with stronger cyber hygiene, she also pointed to the need for continuous monitoring, proactive detection, swift response and recovery.

To raise the baseline for CII owners, Singapore's CSA has updated its Cybersecurity Code of Practice for CII and will introduce a new Cybersecurity Code of Practice for cloud services.

The updated CII code of practice is necessary to strengthen CII governance, visibility, and detection and readiness, including providing technical guidance around adversarial attack simulation, penetration testing, and threat hunting, CSA said.

It outlined several key changes, in particular, increasing board and senior management accountability and oversight for cybersecurity.

For example, boards will be expected to maintain a documented cyber resilience framework covering risk tolerance, mitigation, transfer, and recovery. This must be reviewed annually.

CII owners also will be required to attain Cyber trust Mark Level 5 certification and to maintain oversight of interconnected systems that connect with and communicate with CII. The latter aims to strengthen visibility of the broad network architecture and improve cybersecurity risk management, CSA said.

The government agency in March had mandated a Cyber Trust Mark Level 5 certification for all CII owners by end of 2027, and for CII auditors by end of this year.

Level 5 is highest tier of the Cyber Trust Mark, established by CSA to assess and certify an organisation’s cybersecurity readiness.

The emergence of frontier AI has enabled threat actors to discover vulnerabilities faster, shortening the window period for exploitation, and launch attacks at greater scale, CSA said.

CII owners need to raise their cybersecurity posture as part of efforts to combat Advanced Persistent Threats (APTs) and AI-enabled security risks.

Singapore’s Cybersecurity Act identifies 11 sectors as CIIs, including energy, water, banking and finance, healthcare, transport, and government.

The Code is established to specify the minimum requirements CII operators must implement to ensure the cybersecurity of their CII is in accordance with the Cybersecurity Act.

Defence lines must beyond the perimeter

Teo said: “CII owners will be expected to detect, respond, and recover from attacks. It reflects a fundamental shift from relying on perimeter defences to actively defending against threats.

“Boards and senior management will be held directly accountable for cyber resilience. Leaders at every level must have the cybersecurity knowledge needed to govern and manage cyber risks effectively,” she said, on the updated Cybersecurity Code of Practice.

“This starts with having clear oversight of their critical assets and putting in place continuous monitoring; after all, you cannot defend assets you did not see, and you cannot recover assets you did not know you have," she noted.

Baseline security measures also have to extend to cloud environments as CII owners increasingly adopting cloud technologies, she said.

Singapore will release the new Code of Practice for cloud services later this year, requiring CII operators to adhere to cybersecurity measures governing the deployment, operation, and management of their systems hosted on cloud platforms.

Gwenda Fong

The updated Code of Practice reflects a shift in how CII security will be governed in the region, said Takanori Nishiyama, Keeper Security’s Asia-Pacific senior vice president and country manager for Japan.

With boards now expected to maintain a documented cyber resilience framework, the Code elevates cyber risk to the same level as financial and operational risk, Nishiyama wrote in a note commenting on CSA’s announcement.

“Assigning direct accountability to senior management is significant because cybersecurity failures rarely stem from a lack of policy,” he said. “More often, they occur when responsibility for identity, OT, cloud infrastructure, third-party access, and regulatory compliance sits across separate teams with limited shared visibility.”

“Executive accountability only improves resilience when those functions operate from the same view of risk rather than as parallel programmes,” he added. “The reforms reflect the reality that modern attacks increasingly exploit organisational complexity rather than technical weaknesses.”

Related:  New identity security platform boosts cybersecurity

He noted that AI is accelerating reconnaissance and automation, but attackers still rely on compromised identities, excessive privileges and inconsistent access controls to move through systems once initial access has been gained.

Nishiyama cautioned companies against assuming that protecting the network perimeter could keep their organisation safe, when a breach would occur once a human or machine identity was compromised.

OT complexity is no security shield

AI also has challenged a longstanding assumption that the complexity of OT systems keeps them safe from attack, Teo said.

With threat actors relentless in their search for vulnerabilities and goal to exploit every gap to go deep into interconnected systems, cybersecurity must be a shared responsibility for every stakeholder across the ecosystem, the Singapore minister said.

The cybersecurity posture of manufacturers, vendors, and technology players that build the technologies supporting critical infrastructures must be strengthened, she said.

She added that AI also can help facilitate the development of tools to bolster defence capabilities.

Lee also urged OT organisations to look at both IT and OT security in their cyberdefence strategy, particularly with the integration of AI, including agentic, into their operations.

The technology increasingly will have significant impact on operations, making autonomous decisions about systems that affect the physical realm, he said.

He advocates adhering to Sans Institute’s recommended framework for OT cybersecurity, which outlines five critical controls for ICS (industrial control systems).

These encompass having an incident response plan, a defensible architecture, ICS network monitoring visibility, secure remote access, and risk-based vulnerability management.

In addition, OT organisations need to establish root cause analysis, which is essential to enable them to correctly restore operations, meet regulatory requirements, and prevent future incidents, Lee said.

They must be able to understand why something went wrong, why a process failed, or why quality or production dipped, he added.

And they cannot do this without monitoring their OT environments, he said, noting that organisations cannot assume their IT security monitoring tools automatically encompass OT systems.

Marco Ayala

Citing research from Dragos, he said 88% and 94% of organisations struggle with incident detection and containment, respectively.

Another 82% lack clear criteria for when operational anomalies should trigger a cybersecurity investigation.

Lee suggested organisations learn from adversaries and understand how the latter launch attacks, as these lessons will be useful for organisations to make their own systems safer.  

Never forget the fundamentals

The basics matter, too, and organisations are struggling even with this, said Marco Ayala, technical director of ABS Consulting’s Cybersecurity Centre of Excellence for global energy, during a panel discussion at the forum.

Enterprises are still failing to observe fundamental security practices, such as checking for misconfigurations, changing default passwords, and removing credentials when there are changes in personnel, Ayala said.

Companies that start using AI without first ensuring basic security measures are in place risk masking problems in their environments, he said.

They need to make sure they are carrying out due diligence and thinking about security as an enablement and intertwining it with safety, he noted.

Gwenda Fong, CSA’s chief executive and commissioner of cybersecurity, said: “The environment in which we operate is evolving rapidly. Greater connectivity, increasing digitalisation and advances in AI are creating vast opportunities across our industries.

“At the same time, they are changing how cyber threats emerge and evolve. Capabilities that once required significant expertise are becoming more accessible, and defenders must continue to adapt just as quickly,” Fong said at the forum. “We want to strengthen capabilities before a crisis occurs because every exercise completed, every assessment conducted, and every lesson shared makes our collective defences stronger.”

CSA also launched a sandbox that can be tapped to experiment with AI-enabled cybersecurity solutions, such as code scanning or pen testing.

Available to locally-registered companies that plan to implement these solutions within their Singapore operations, the sandbox will operate until end-February next year.

CSA will offer funding of up to 70% of project costs. The organisations will have to co-fund the remaining 30% in cash.

These grants will be given based on CSA’s assessment for eligibility, scope alignment, and strategic value.

Approved projects must be completed within three months of the grant award, though, extensions may be considered on a case-by-case basis.

Related Stories

MORE STORIES