Back to Insights
Technology Risk7 min readSeptember 2026

Cybersecurity Act 2026 Update: Cyber Risk Is Now a Board Duty, Not a CISO Problem

RC

Raymond Cheung

Chartered Actuary · CRO · Board Adviser · Singapore

Singapore's Cyber Security Agency has rewritten the rules for critical infrastructure owners: board-level accountability, mandatory Cyber Trust Mark Level 5 certification, and personal director liability for cyber failures traced back to a lack of skill, care and diligence. Most boards are still treating this as an IT reporting line, not a governance duty.

I have sat in a board meeting where the cyber risk update was five minutes long: a green status on the dashboard, a line about the annual penetration test, and a question from the chair about whether the insurance was still in force. Nobody in that room could have told you what their organisation's actual recovery time objective was for its most critical system, or what 'board-level accountability for cyber resilience' was supposed to mean in practice. That gap — between a status update and genuine board ownership — is exactly what Singapore's regulators have just stopped tolerating for the organisations that matter most.

What actually changed on 29 July 2026

Singapore's Cyber Security Agency issued an updated Cybersecurity Code of Practice for Critical Information Infrastructure on 29 July 2026, and it is a materially different document from what came before it. Two changes matter most to a board. First, it imposes explicit board-level accountability on CII owners — not senior management, not the CISO, the board. Second, it mandates Cyber Trust Mark Level 5 certification, the highest tier available, for CII owners and their auditors, covering 22 cybersecurity domains that now explicitly include cloud security, operational technology security and AI security. CII owners have a two-year grace period to reach that standard, with a hard deadline of end-2027 for the non-CII systems that support core operations, while auditors and licensed cybersecurity service providers face an earlier cut-off of 31 December 2026. Layered on top of this, a separate requirement — expected to be codified in the first quarter of 2026 — obliges board members of CII owners to undergo cybersecurity training directly, not delegate that learning to a management briefing.

“The regulator did not ask boards to buy better cyber tools. It asked boards to personally own the resilience framework those tools sit inside.”

The line CSA is drawing: governance, not just implementation

The substantive requirement underneath the certification headline is the one boards tend to skip past. Boards and senior management at CII owners must now maintain a documented cyber resilience framework that explicitly covers risk tolerance, mitigation, risk transfer and recovery — reviewed at least annually as a board-level record, not a technical appendix management produces for its own use. That framework has to exist in a form that can be audited and defended, because Singapore's legal position on director liability for cyber failures is now unambiguous: if an organisation fails to prevent, mitigate, manage or respond to an incident because of a lack of honesty, or a lack of the requisite skill, care and diligence on the part of its directors, that can constitute a breach of directors' duties. That is not a CISO's exposure. It is personal, individual director exposure, and it turns the annual cyber briefing from a courtesy update into the primary evidence of whether a director actually exercised the diligence the law now expects.

Where boards get this wrong

The most common failure I see is structural: cyber risk sits permanently on the IT or technology sub-committee's agenda and only reaches the full board as a summarised status line, the same way the CDL boardroom dispute I wrote about separately this month sat invisibly below the surface until it became impossible to ignore. A board that has never read its own organisation's documented resilience framework — never asked what 'recovery' actually means in hours for the systems that matter most, never tested whether the risk tolerance statement in that document matches what the board would actually accept in a real incident — cannot credibly claim to have exercised the skill, care and diligence the law now expects of it. The second failure is treating Cyber Trust Mark Level 5 as a procurement exercise to be handed to IT, when the certification's 22 domains include governance and organisational accountability as first-class requirements, not technical add-ons. A board that outsources the entire certification process without engaging with the governance domains has not actually met the standard the certification exists to prove.

What good cyber governance looks like on a board

A board that is genuinely ahead of this has read its own cyber resilience framework document in full, at least once, and can state in plain language what the organisation's risk tolerance and recovery objectives actually are — not recite the name of the framework. It treats the shift to Cyber Trust Mark Level 5 as a governance project with a named board sponsor and a realistic timeline against the 2027 deadline, not a checkbox IT will handle. And every director on a CII owner's board has personally completed the cybersecurity training the regulation now requires, rather than nominating someone else in the organisation to sit through it on the board's behalf.

  • Read the organisation's documented cyber resilience framework in full at board level at least once a year, rather than accepting a management summary of it
  • Assign a named board sponsor and realistic milestone plan for reaching Cyber Trust Mark Level 5 well ahead of the 2027 deadline, treating the governance domains as seriously as the technical ones
  • Confirm every director has personally completed the cybersecurity training now expected of CII owner boards, and document that completion the same way other governance training is recorded

None of this requires a director to become a security engineer. It requires the board to stop treating the cyber update as a status report to be noted and start treating it as what the regulator has now made explicit: a governance duty carrying personal accountability, exercised continuously, not rediscovered the week after an incident makes the newspapers.

Common Questions

What changed in Singapore's Cybersecurity Code of Practice in 2026?

On 29 July 2026, Singapore's Cyber Security Agency issued an updated Cybersecurity Code of Practice for Critical Information Infrastructure that imposes explicit board-level accountability on CII owners and mandates Cyber Trust Mark Level 5 certification, the highest tier, for CII owners and their auditors across 22 domains including cloud, operational technology and AI security.

Can a Singapore director be personally liable for a cybersecurity failure?

Yes. Singapore's legal position is that if an organisation fails to prevent, mitigate, manage or respond to a cyber incident due to a lack of honesty or a lack of the requisite skill, care and diligence on the part of its directors, that can constitute a breach of directors' duties — making cyber governance a matter of personal director accountability, not just a management or CISO responsibility.

What is Cyber Trust Mark Level 5 and who needs it?

Cyber Trust Mark Level 5 is the highest tier of Singapore's cybersecurity certification, requiring demonstrated preparedness across 22 domains including governance, asset protection, cloud security, operational technology security and AI security. It is now mandatory for Critical Information Infrastructure owners and their auditors, with CII owners given a grace period to end-2027 and auditors facing an earlier 31 December 2026 deadline.

About the author

Raymond Cheung is a Chartered Actuary, C-suite executive and board adviser with more than 20 years of experience across Asia in risk management, insurance, ESG and corporate governance. He is the CEO of CER Consultancy and an accredited trainer at SMU Academy and the Singapore College of Insurance.

All insights