Safeware Glasswall APAC Partner Book a demo

Explore

What is CDRZero TrustThe detection gapCapabilitiesUse cases

Products

ProductsIntegrationFile support

Compliance

Compliance hub
Country guidesSingaporeAustraliaJapanSouth KoreaIndiaIndonesiaMalaysiaThailandVietnamPhilippinesTaiwanNew ZealandMongoliaAPAC overview

More

Trust & certificationsAboutDocumentation Book a demo

Regulatory landscape ยท Southeast Asia

Singapore: file security and audit obligations

Singapore regulates file security through a designated CII regime: the Cybersecurity Act sets the statutory duties, the Cybersecurity Code of Practice sets the technical controls, and the PDPA sets the obligation to protect the data inside the files.

At a glance

How Singapore regulates file security

  • 01

    Regime

    Sector-designated CII regime under a statutory code of practice

  • 02

    File security

    CCoP malware protection and content inspection at trust boundaries

  • 03

    Audit and evidence

    Logs retained to support investigation and audit verification on demand

Overview

The regulatory picture

Singapore has the most prescriptive file-security regime in the region, and it is the one most likely to be written into a tender. Three instruments matter to anyone moving files across a trust boundary here.

The Cybersecurity Act 2018 gives the Cyber Security Agency of Singapore (CSA) power to designate Critical Information Infrastructure across eleven sectors and to bind the owners of that infrastructure to a statutory Code of Practice. The Cybersecurity (Amendment) Act 2024 extended that reach materially: from 31 October 2025 a new Part 3A captures providers of essential services who do not own the CII they depend on, together with cloud service providers and data centre operators. Organisations that previously sat outside the regime because they rented rather than owned their infrastructure are now inside it.

The Cybersecurity Code of Practice (CCoP) is where the technical obligations live. CCoP 2.0 requires continuous monitoring, anomaly detection across both IT and OT, and retention policies that support investigation and audit verification on demand. CSA announced on 22 July 2026 that the CCoP will be updated again to address advanced persistent threats and AI-enabled attacks, with a separate Code for Cloud Services on the same timetable.

Alongside these, the PDPA imposes the Protection Obligation on any organisation holding personal data, and the MAS Technology Risk Management Guidelines set the expectations for financial institutions specifically. For file-borne risk, the practical effect of all four is the same: untrusted content must be treated as untrusted at the boundary, and you must be able to show an assessor what happened to each file.

The landscape

Instruments that reach file security and audit

InstrumentAuthorityStatusRelevance
Cybersecurity Act 2018 (as amended 2024)CSAIn forceDirect
Cybersecurity Code of Practice for CII (CCoP 2.0)CSAIn forceDirect
Personal Data Protection Act 2012PDPCIn forceDirect
MAS Technology Risk Management GuidelinesMASIn forceDirect
CSA Cyber Essentials and Cyber Trust marksCSAIn forceIndirect

CSA

Cybersecurity Act 2018 (as amended 2024)

Establishes the CII regime, CSA's designation and investigation powers, and the statutory basis for the Cybersecurity Code of Practice. The 2024 amendment added Part 3A covering third-party-owned CII, cloud service providers and data centres, commencing 31 October 2025.

Why it matters for file security. Designation is what makes the Code of Practice binding rather than advisory. If an organisation is designated, or is now captured as a 3PO CII, cloud or data centre provider under Part 3A, the file-handling controls in the CCoP become a statutory obligation with reporting duties attached.

Source: CSA

CSA

Cybersecurity Code of Practice for CII (CCoP 2.0)

The binding technical control set for designated CII owners across eleven sectors: Energy, Info-communications, Water, Healthcare, Banking and Finance, Security and Emergency Services, Aviation, Land Transport, Maritime, Government and Media. Requires continuous monitoring, behavioural anomaly detection across IT and OT, and retention supporting investigation and audit verification on demand.

Why it matters for file security. This is the clearest file-security mandate in APAC. Malware protection and content inspection obligations apply to content crossing into the CII environment, and the retention requirement means a per-file verdict record is the evidence an assessor asks for. Detection-based controls alone are difficult to evidence against the "known-good" standard the Code implies.

How Glasswall addresses it. Glasswall CDR rebuilds every file crossing into the CII environment against its format specification, so the control is deterministic rather than dependent on a detection verdict, which is what makes it straightforward to evidence against the Code's content-inspection expectations. The per-file verdict record gives an assessor the processing history for each file and is exportable to SIEM, so it can be held under whatever retention policy the Code obliges you to operate. Deployment sits at the boundary: ICAP for proxies and gateways, or the email relay for inbound attachments.

Content Disarm and ReconstructionPer-file verdict recordICAP ClientEmail CDR RelayGlasswall Halo / Glasswall Meteor

Source: CSA

PDPC

Personal Data Protection Act 2012

Imposes the Protection Obligation, reasonable security arrangements to prevent unauthorised access, collection, use, disclosure or similar risks, plus mandatory notification of notifiable data breaches.

Why it matters for file security. Files are the most common uncontrolled carrier of personal data in an organisation. Removing named data patterns before documents are stored, shared or forwarded is a direct Protection Obligation control, and reduces the population of files that could trigger a notifiable breach.

How Glasswall addresses it. Find & Redact removes named data patterns from documents before they are stored or shared, which supports the Protection Obligation directly by shrinking the amount of personal data sitting in loose files. Storage Monitor applies the same treatment to material already at rest in Microsoft 365 and records a per-tenant trail of what was processed. Fewer documents carrying unnecessary personal data means a smaller population of files capable of becoming a notifiable breach.

Find & RedactStorage Monitor + SM AuditContent Disarm and ReconstructionGlasswall Halo

Source: PDPC

MAS

MAS Technology Risk Management Guidelines

Sets MAS expectations for financial institutions on technology risk governance, system security, network perimeter defence and secure software delivery.

Why it matters for file security. The perimeter-defence and system-security sections are the relevant ones: untrusted files arriving by email, upload portal or third-party exchange are expected to be handled at the boundary rather than admitted on a detection verdict alone.

How Glasswall addresses it. The perimeter-defence expectation maps onto rebuilding untrusted files at the point they arrive, inbound mail, customer upload portals, third-party document exchange, rather than admitting them and relying on detection downstream. The per-file verdict record supports the evidence trail MAS-regulated institutions are expected to maintain for technology risk controls.

Content Disarm and ReconstructionEmail CDR RelayICAP ClientPer-file verdict recordGlasswall Halo

Source: MAS

CSA

CSA Cyber Essentials and Cyber Trust marks

Voluntary certification marks. Cyber Essentials targets smaller organisations; Cyber Trust is a risk-based mark with tiered levels for larger enterprises.

Why it matters for file security. Increasingly used as a procurement filter rather than a badge. The 22 July 2026 CCoP announcement referenced Cyber Trust Mark Level 5 certification in connection with the updated Code, which moves the mark from voluntary signalling toward supply-chain expectation for CII-adjacent vendors.

Source: CSA

Latest developments

What has changed in Singapore

Most recent first.

  1. ConsultationHigh impact

    CCoP for CII to be updated to address APT and AI-enabled threats

    CSA announced that the Cybersecurity Code of Practice for CII will be updated to address advanced persistent threats and AI-enabled threats, with changes expected to take effect in the later part of 2026. The update covers board accountability with annually reviewed cyber resilience frameworks, Cyber Trust Mark Level 5 certification, oversight of interconnected systems, threat detection deployment, cybersecurity exercise planning, and network monitoring and detection management. A separate Code of Practice for Cloud Services is planned on the same timetable.

    Why it matters for file security. AI-enabled threats raise the ceiling on file-borne attacks specifically: polymorphic document payloads and machine-generated lures degrade signature and heuristic detection faster than they degrade deterministic rebuild. CII owners reviewing their control set against the updated Code should expect content-inspection and known-good reconstruction to be scrutinised more closely than detection tuning.

    How Glasswall addresses it

    This is the development most worth acting on ahead of the Code landing. AI-generated document payloads and machine-tailored lures degrade signature and heuristic detection considerably faster than they degrade deterministic rebuild, because rebuild does not need to recognise the threat, it removes the active content regardless. CII owners revisiting their control set before the updated Code takes effect should expect content inspection and known-good reconstruction to attract more scrutiny than detection tuning. Macro intelligence covers the Office macro surface specifically, and Large Archive reaches the container formats inline scanning cannot open.

    Content Disarm and ReconstructionMacro intelligenceLarge ArchiveGlasswall Halo / Glasswall Meteor

    • cii
    • government
    • banking
    • healthcare
    • telco
    • energy
    • transport

    Source: CSA

  2. In forceHigh impact

    Cybersecurity (Amendment) Act 2024 key provisions commence

    Key provisions of the Cybersecurity (Amendment) Act 2024 came into force, introducing Part 3A to regulate providers of essential services that do not own the CII they rely on, and extending CSA oversight to cloud service providers and data centre operators.

    Why it matters for file security. The practical consequence is scope. Organisations that assumed the CII control set did not apply because they rent rather than own infrastructure are now potentially in scope, and inherit the Code's content-inspection and retention expectations for files entering the essential-service environment.

    • cii
    • government
    • banking
    • healthcare
    • telco
    • energy
    • transport

    Source: CSA

  3. AmendmentMedium impact

    Cybersecurity (Amendment) Act 2024 passed by Parliament

    Parliament passed the Cybersecurity (Amendment) Act 2024, expanding the Cybersecurity Act 2018 to cover third-party-owned CII, cloud service providers, data centre operators and entities of special cybersecurity interest.

    Why it matters for file security. Set the legislative basis for the October 2025 scope expansion. Relevant when assessing whether a deployment sits inside or outside the CII control perimeter.

    • cii
    • government
    • banking
    • telco

    Source: Singapore Statutes Online

Scope

About this page

This page is a working reference for organisations operating in Singapore.

It is not legal advice. Regulatory obligations depend on how an organisation is designated, which sector it operates in and how its systems are architected, take local advice before relying on any of this for a compliance decision. Where we describe how Glasswall relates to an obligation, we are describing a control, not certifying an outcome.

Planning a deployment in Singapore?