Inside Singapore’s push for proactive defence against cyberthreats
SINGAPORE - Singapore’s cyber defenders have continued to encounter attacks by advanced persistent threat (APT) groups since it was publicly revealed in July 2025 that state-sponsored cyber espionage group UNC3886 had infiltrated the city-state’s critical information infrastructure (CII).
But these attacks are being detected and dealt with more effectively than before through more proactive sharing of information between CII operators, cybersecurity firms and government agencies, said Centre for Strategic Infocomm Technologies (CSIT) chief executive Darren Teo.
This greater willingness to collaborate on suspicious network activity that may not cross the threshold into an actual attack - so-called “weak signals” - is crucial as APT groups continue to refine their methods to stay hidden within victims’ networks, he added.
Teo was speaking to The Straits Times ahead of TechCon 2026 on Oct 9, an annual closed-door conference hosted by CSIT, which is an agency under MINDEF focused on developing advanced cybersecurity capabilities to safeguard the Republic’s digital infrastructure.
At the previous TechCon in Oct 2025, Coordinating Minister for National Security K. Shanmugam had announced the setting up of a new digital defence unit within CSIT focused on countering sophisticated cyber threat actors such as APT groups.
One year on, the Digital Defence Hub (DDH) has raised the willingness of the various stakeholders to exchange weak signals early and to carry out joint investigations together, said Teo.
This is a stark change from previous practice, when each part of the industry “more or less stayed in our own lane”, he said. For instance, a CII operator used to only reach out to their IT vendor when they encountered a cyber problem.
“That (wasn’t) the best way, because each of us probably have a little piece of the information needed to deal with our threat,” he said. The infrastructure operators also did not benefit from the broader visibility that agencies like CSIT had due to its capabilities and partnerships with threat intelligence firms.
The attacks by UNC3886 on Singapore’s major telcos was a “good wake-up call” and argument for greater coordination, he added, but even so there was a need to establish ways to share sensitive information while addressing firms’ concerns about data privacy and competition.
CSIT and DDH have thus been building these partnerships. On Oct 9, the agency signed one such agreement with Google Cloud Security, which clearly lays out each party’s obligations when they exchange data and how sensitive information must be protected.
Establishing clear protocols on what can be exchanged and how will hopefully speed up the flow of information, which also aids the proactive hunting of threats in computer networks here, said Teo.
Apart from building partnerships, the agency has also put in place sensors in Singapore’s CII networks to better detect APT activities.
This combination of threat information and telemetric data is crucial to uncovering APT attacks, given that such groups are motivated to be very stealthy and have the resources and advanced technology to stay undetected as they move from network to network, said Teo.
The latest Singapore Cyber Landscape report published on June 30 said APT groups have shifted tactics to prioritise the accumulation of credentials, with the goal of maintaining “persistent network footholds over immediate disruption”.
State-sponsored cyber activity in 2026 will likely continue to focus on gaining access to CII networks and focus on “strategic optionality” over disruptive attacks, the report added.
Teo said cyber agencies here expect artificial intelligence to amplify the speed and scale by which threat groups can launch attacks, though they have not yet resulted in novel methods or exploits.
“It’s the basic stuff that is now being done a lot faster...what used to require a whole team is now just being done by a few people and many tens of thousands of agents acting on their behalf,” he said.
“So you would see that these attacks will probably reduce in cost, because you no longer need to assemble a team of very highly-skilled attackers.”
Cyber defense therefore needs to be significantly more proactive and anticipatory, rather than kicking in only when an attack has happened, he said.
On its part, CSIT has “somebody experimenting with some kind of AI” across each of its functions, which include threat intelligence, cyber security engineering and red-teaming, which refers to simulating a real-world adversary.
For instance, the agency has created a tool called AETHER that uses AI to automate the time-consuming work of reverse engineering malware, so as to detect their presence in computer systems.
Teo said CSIT has always placed very strong emphasis on developing cyber security talent, but it is also investing heavily in its AI efforts.
“We think that AI will make a very, very big impact on cybersecurity work, but at the same time we believe that it is best paired with a human expert,” he said.
“It is the man-machine teaming that will make the most effective cybersecurity capability.”
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.