Cybersecurity

Why Singapore’s Regulator Wrote to Boards

  1. Home
  2. /
  3. Our Blog
  4. /
  5. Why Singapore’s Regulator Wrote to Boards.

 

By Resham Ganglani, CEO of Halodata Group  

Something significant happened in Singapore this May, and every board across Asia-Pacific should take note. The Cyber Security Agency of Singapore wrote directly to the boards and chief executives of the organisations that run our critical infrastructure, instructing them to review their cyber risk in light of AI-accelerated threats as a matter of urgency. 

The choice of recipients is interesting. For years, those of us in the security industry have argued that cybersecurity belongs in the boardroom first, and the server room after that. We have made that case on conference panels, in vendor briefings, and in blogs like this. Now a national regulator has made the case for us, in writing, with enforcement powers behind it. 

What Actually Changed

The substance of the directive is sobering. Commissioner of Cybersecurity David Koh warned that recent advances have materially shifted the cybersecurity baseline and that the assumptions underpinning many existing risk models may no longer hold. Senior Minister of State Tan Kiat How put it more plainly in parliament: vulnerabilities that once took weeks to detect are now discoverable in hours or sometimes minutes. 

The operational consequences are enormous. Frontier AI models compress the time between a vulnerability being shipped and hackers discovering it. The defensive routines many organisations have built their security around, such as scheduled patch windows, quarterly reviews, and annual penetration tests, all assume that defenders have time. That assumption is what is now in question. 

 

Two Shifts the Boardroom Has Not Absorbed

I would highlight two implications that most boards have not yet fully taken on board. 

The first concern is scarcity. Until recently, the pool of people skilled enough to find and weaponise a serious vulnerability was reasonably small, and that scarcity functioned as a natural brake on the volume of sophisticated attacks. AI potentially removes that brake. The skill that used to reside in a handful of expert minds is now within reach of anyone willing to misuse it, on demand and at scale. 

The second concerns timing. The long-held belief that a critical vulnerability can safely wait for the next maintenance window no longer holds. When the gap between discovery and exploitation narrows to hours, a patch cycle measured in weeks is not a cycle at all. It is an open door. 

Neither of these is a technical detail. Both are business risks and belong on the same agenda as other board-level business risks.  

 

This Matters Beyond Critical Infrastructure 

Singapore regulates nine critical sectors, including banking and finance, healthcare, transport, and energy, and the directive formally applies to the operators of that infrastructure. Yet the logic behind the directive does not stop with critical infrastructure. It applies to all organisations. Singapore has simply named the problem first and named it most clearly for a specific sector. 

For the rest of Asia-Pacific, the practical question is not whether your regulator will follow. Several are already signalling that they will. The question is whether your organisation can act at the speed the new threat environment demands. 

Where The Channel Sits 

I will be candid about my vantage point. Halodata sits between the global vendors who build security technology and the managed and IT service providers who deploy it for end customers across the region. From that seat, I can tell you that the gap this directive exposes is not primarily a tool gap. It is a gap in security operations. 

Most regional organisations do not lack security products. They lack the operational muscle to continuously monitor their attack surface, triage findings by business impact, and respond in hours rather than days. The Singapore government itself has reached the same conclusion, fast-tracking its own AI capabilities for vulnerability detection and attack surface monitoring rather than relying on periodic review.  

A strong managed service relationship enables organisations to plug gaps in their security operations. The service providers we support are the ones who can close this gap for the wider market. Our job, alongside theirs, is to translate a regulatory warning into a faster operating model: continuous visibility, business-aligned prioritisation, and a patching rhythm that responds to the threat rather than the calendar. 

 

Three Questions for The Boardroom 

If you sit on a board or run a business, I would pose three questions to your own people this quarter. 

 

  • First, how long does it take us to move from the discovery of a critical vulnerability to remediation across our systems? If the honest answer is weeks, you have found your primary focus for security operations changes. 
  • Second, do we perform continuous discovery and visibility into all our IT assets, or do we only discover them during an audit? Rapid regional growth and cloud expansion often create assets that go unnoticed until an audit. 
  • Third, when security needs investment, does the conversation happen at the board level, or does it stall two levels below? The Cyber Security Agency of Singapore has just told our most important organisations where that conversation belongs. 

 

The Letter Was Addressed to All of Us 

Tan Kiat How was right to point out that there are no one-off fixes. The organisations that emerge from this period strongest will not be the ones that spend the most. They will be the ones that move rapidly, treat security as a Board responsibility rather than an IT errand, and build the operating discipline to act in hours rather than weeks. 

The Cyber Security Agency of Singapore targeted specific recipients with their letter. The rest of us should act as if they also wrote to us, because in every way that matters, they did. 

 

Talk to one of our experts and discover the benefits of Halodata for your company.

It’s Time to Get Started with Halodata

Request Demo

Contact Us

Please complete this form to be contacted by one of our experts.

[hubspot type=form portal=25515721 id=d6181c33-f2bb-4030-8cb7-108bef5e36c9]