Singapore’s Cyber Security Agency just updated its Critical Information Infrastructure Code of Practice, and it puts the blame squarely on the C-suite.
The new rules hold boards directly accountable for cyber resilience, cloud safety, and AI threats, shifting liability straight to senior management.
For the rest of Asia-Pacific, the move sets a benchmark regulatory standard and a supply-chain baseline across interconnected regional networks.
Takanori Nishiyama, SVP APAC and Country Manager Japan, Keeper Security
Boards overseeing critical information infrastructure will now need to maintain a documented cyber resilience framework, reviewed at least annually, covering risk tolerance, mitigation, and recovery.
That elevates cyber risk to the same level as financial and operational risk, where it has always belonged.
Cybersecurity failures rarely stem from a lack of policy. More often, they occur when responsibility for identity, Operational Technology (OT), cloud infrastructure, third-party access, and regulatory compliance sits across separate teams with limited shared visibility.
Executive accountability only improves resilience when those functions operate from the same view of risk rather than as parallel programmes.
Modern attacks increasingly exploit organisational complexity rather than technical weaknesses. AI is accelerating reconnaissance and automation, but attackers still rely on compromised identities, excessive privileges, and inconsistent access controls.
Perimeter-only thinking assumes the outside is dangerous and the inside is safe. That assumption breaks down the moment a single human or machine identity is compromised.
As critical infrastructure becomes more interconnected, human users, service accounts, APIs, and AI-driven agents are all interacting across IT, OT, and cloud environments, making identity the common control layer across the organisation.
Keeper’s 2026 research found that only 38% of APAC organisations have Privileged Access Management (PAM) fully deployed, despite operating in environments where machine identities already outnumber human ones.
For boards facing this mandate, the practical starting point is establishing who and what has privileged access. Organisations must enforce least-privilege access by default, make privileged sessions continuously auditable, and ensure access controls are applied consistently across IT and OT environments.
Those that treat compliance as an integrated operating model rather than an annual reporting exercise will be far better positioned as regulatory expectations continue to evolve across the region.
