Singapore Revamps Cyber Defence with AI-Driven Threat Hunting Amid Rising Cyber Threats
September 26, 2026
Singapore has overhauled its cyber defence to shift from perimeter protection to continuous monitoring and active threat hunting, following the UNC3886-linked attacks on the four major telecoms and leveraging AI tools to secure around 2,000 government systems.
The new approach assumes attackers may already be inside networks, focusing on detection, internal traffic monitoring, and anomaly detection to halt threats from causing further harm.
Authorities declined to specify which agencies have deployed the AI tools and plan to expand deployment to other critical information infrastructure sectors, potentially mandating Cyber Essentials or Cyber Trust certifications for some vendors by 2027.
Regular external scans of internet-facing systems at critical infrastructure operators have begun to identify entry points like unpatched software and weak configurations.
The shift is framed against rising concerns about AI-powered threats and geopolitical tensions, underscoring protection of a digitally dependent society and essential services.
The strategy emphasizes detecting and hunting attackers within networks, rather than solely preventing initial entry.
CSA’s Gwenda Fong notes the core lesson: defenders must assume intruders are inside and prioritize internal monitoring and anomaly detection to identify and neutralize threats.
Cybersecurity is treated as a strategic issue impacting national security, the digital economy, and public trust, moving toward proactive detection and containment of breaches.
AI-powered tools are used to bolster government cybersecurity, with automated penetration testing across about 2,000 systems and automated source-code security analysis, though deployment specifics aren’t disclosed.
Two AI-powered tools were developed for the effort: one for automated penetration testing of roughly 2,000 government systems and another for scanning source code for security weaknesses.
Singapore is rolling out proprietary threat-detection tools to critical infrastructure operators, sharing classified threat intelligence, and evaluating supply-chain cybersecurity risks with possible Cyber Essentials or Cyber Trust certifications for vendors by 2027.
Authorities plan to extend AI security tools to 11 critical information infrastructure sectors, including government, aviation, healthcare, transport, energy, banking, and info-communications, after evaluation.
Summary based on 2 sources
Get a daily email with more Tech stories
Sources

The Straits Times • Sep 26, 2026
Singapore shifts cyber strategy after UNC3886 attacks, deploys AI security tools
The420.in • Sep 27, 2026
Singapore Changes Cyber Strategy as AI-Powered Threats Grow