International Edition
Latest News
Technology

Singapore Deploys AI Tools to Secure 2,000 Government Systems

The Cyber Security Agency of Singapore (CSA) has deployed in-house artificial intelligence tools to secure approximately 2,000 government systems amid an expanded operational focus on active threat hunting. Speaking to The Straits Times in an interview published in…

Singapore Deploys AI Tools to Secure 2,000 Government Systems

The Cyber Security Agency of Singapore (CSA) has deployed in-house artificial intelligence tools to secure approximately 2,000 government systems amid an expanded operational focus on active threat hunting. Speaking to The Straits Times in an interview published in September 2025, CSA Chief Executive Gwenda Fong stated that the shift from perimeter defense to internal network monitoring follows a cyberespionage campaign by state-backed group UNC3886 against Singapore’s four major telecommunications providers.

AI-Powered Threat Detection Across Government Infrastructure

Developed by the Government Technology Agency of Singapore (GovTech), the newly deployed AI systems address two distinct security vectors within the public sector. The first tool executes automated penetration testing across roughly 2,000 government systems, simulating cyberattacks to uncover vulnerabilities before malicious actors exploit them. The second tool reviews source code across government applications to identify security flaws.

While CSA and GovTech withheld the names of the specific agencies currently utilizing these tools, officials confirmed plans to expand the deployment across Singapore’s 11 designated Critical Information Infrastructure (CII) sectors. These sectors comprise government, aviation, healthcare, land transport, maritime, media, security and emergency services, water, banking and finance, energy, and info-communications.

Shifting Strategy Post-UNC3886

The operational pivot comes after public disclosures in July 2025 regarding the UNC3886 intrusion. Fong noted that advanced persistent threat (APT) groups target specific entities for state-backed objectives, meaning traditional preventative perimeters are insufficient. Defenders must assume that well-resourced actors will breach network boundaries.

Singapore Deploys AI Tools to Secure 2,000 Government Systems

“You also have to assume that the most well-resourced and qualified attackers will find a way in at some point,” Fong said in the Sept. 3 interview. Consequently, CII operators must monitor internal traffic, analyze anomalous behavioral patterns, and execute continuous threat hunting to intercept actors moving laterally toward sensitive data.

External Scanning and Supply Chain Security

Alongside internal AI deployments, the CSA initiated regular external scans of all internet-facing systems operated by CII entities. These checks identify open entry points such as unpatched software and misconfigurations without conducting active network probing.

To mitigate downstream risks, the agency is preparing to tighten cybersecurity requirements for vendors and suppliers connected to CII operators. By 2027, CSA plans to mandate that select suppliers obtain baseline Cyber Essentials or tiered Cyber Trust mark certifications. Voluntary uptake remains limited, with official figures as of August showing 874 Cyber Essentials certifications and 346 Cyber Trust mark certifications issued since the program’s launch in March 2022.

About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”