Most small businesses in Singapore do not get breached by a Hollywood hacker – they get caught by a phishing email, a reused password, or a missing backup. This is the cyber security checklist Singapore SMEs actually need: written to fix exactly those gaps, in priority order, without enterprise jargon or an enterprise budget.
We have organised it around the five areas of the CSA Cyber Essentials mark – the Cyber Security Agency of Singapore's baseline for SMEs – so that working through this list also moves you toward a recognised standard. Start at the top; the earliest items block the most common attacks.
Why Singapore SMEs are targeted
Attackers go after SMEs because they assume the defences are thin – and too often they are right. The Cyber Security Agency of Singapore has repeatedly flagged phishing as the leading way attackers get in, and reported that a large majority of organisations here have faced at least one cyber incident in the past year. In 2026, phishing has become harder to spot: AI-written emails now imitate vendor invoices, bank notices and government letters with near-perfect local detail.
The good news: the controls that stop these attacks are mostly cheap or free. The hard part is doing them consistently. That is what the checklist below is for.
1. Know what you have (asset management)
You cannot protect what you do not know exists. This is the first Cyber Essentials domain and the foundation of everything else.
- Do first: list every device (laptops, desktops, phones, servers, NAS) and every business account (Microsoft 365, Google Workspace, accounting, CRM, banking).
- Do first: list who has access to what, and remove accounts for anyone who has left.
- Then: record what software runs where, so you know what needs patching and what is out of support.
- Mature: keep the inventory live through a managed endpoint tool rather than a spreadsheet that goes stale.
2. Lock down access (the single biggest win)
Most SME breaches in Singapore involve an account that had no MFA. Fixing access control is the highest-return item on this entire checklist.
- Do first: turn on multi-factor authentication (MFA) on every business account – email, cloud, accounting, banking, remote access. Even if a password is phished, MFA usually stops the attacker.
- Do first: stop password reuse – use a password manager so every account has a unique, strong password.
- Then: apply least privilege – staff get only the access they need, and admin accounts are separate from daily-use accounts.
- Then: have a strict offboarding routine – the moment someone leaves, their access is revoked the same day.
- Mature: enforce these with policy (conditional access, blocked legacy logins) rather than trusting people to comply.
3. Protect every device (secure configuration, updates, malware)
Three Cyber Essentials domains live here – secure configuration, software updates and malware protection. In plain terms: keep devices current and defended.
- Do first: turn on automatic updates for operating systems and key apps – unpatched software is a top ransomware entry point.
- Do first: run reputable endpoint protection (antivirus/EDR) on every device, and make sure it is actually active, not expired.
- Then: enable disk encryption (BitLocker or FileVault) so a lost laptop is not a data breach.
- Then: change default passwords on routers, NAS and any device that shipped with one.
- Mature: centralise patching and EDR through managed IT so nothing slips through the cracks.
4. Beat phishing (train the humans)
Phishing is the number-one initial-access method for a reason: it targets people, not firewalls. Technology helps, but habits matter more.
- Do first: turn on email security/filtering (built into Microsoft 365 and Google Workspace) to catch the obvious ones.
- Do first: set the golden rule for finance – any change to bank or payment details is verified by phone, using a known number, never the one in the email.
- Then: run short, regular phishing-awareness training so staff can spot fake invoices, delivery and login lures.
- Then: configure SPF, DKIM and DMARC on your domain so criminals cannot easily spoof your company's email.
- Mature: run simulated phishing campaigns and coach the people who click – without blame.
5. Back up so ransomware cannot win
A tested backup is what turns a ransomware attack from a business-ending event into a bad afternoon. The standard is the 3-2-1 rule.
- Do first: back up critical data at least daily.
- Do first: keep the 3-2-1 rule – 3 copies of your data, on 2 types of media, with 1 copy offline or immutable (so ransomware cannot encrypt it too).
- Then: test a full restore at least once a quarter – an untested backup is a guess, not a safety net.
- Mature: define your recovery time and recovery point objectives (how fast, how recent) and back them with managed cloud backup and disaster recovery.
6. Detect and respond (have a plan before you need one)
You will not stop every attack, so the question becomes how fast you notice and how calmly you react. A one-page plan beats panic every time.
- Do first: write down who to call and what to do if a device is compromised or accounts are locked – before it happens.
- Then: enable logging and alerting on email and key systems so unusual logins are noticed early.
- Then: know how to report an incident to SingCERT, and understand your PDPA duty to notify if personal data is affected.
- Mature: use 24/7 monitoring and a tested incident-response process, usually through a managed security partner.
7. Govern it (PDPA, policy and the Cyber Essentials mark)
The final layer is turning good intentions into standing practice – and, if it fits, an external stamp of credibility.
- Then: meet your PDPA obligations – control who can access personal data, and have a breach-response process.
- Then: write short, real policies (acceptable use, passwords, data handling) that staff actually read.
- Mature: work toward the CSA Cyber Essentials mark – a recognised SME baseline that reassures clients and, increasingly, is asked for in tenders and cyber-insurance applications.
If you only do five things
Short on time? These five block the overwhelming majority of real-world SME attacks. Start here today:
- Turn on MFA on every business account.
- Get a tested backup with one copy offline or immutable (3-2-1).
- Turn on automatic updates and active endpoint protection on every device.
- Enforce the verify-payment-changes-by-phone rule and basic phishing awareness.
- Write a one-page incident plan: who to call, what to do.
Frequently asked questions
What are the most important cyber security steps for a Singapore SME?
The highest-impact steps are: enable multi-factor authentication (MFA) on every account, keep devices patched and protected with endpoint security, train staff to recognise phishing, back up data on the 3-2-1 rule with one copy offline, and have a written incident-response plan. These five block the large majority of attacks that actually hit SMEs.
Does MFA really stop most attacks?
It stops most account-takeover attacks, which are the most common. Even if an attacker phishes or guesses a password, MFA adds a second factor they usually cannot provide, so they are locked out. Nearly all SME phishing breaches in Singapore involve accounts that did not have MFA enabled – which is why it is the single best control to turn on first.
How do I protect my SME from ransomware?
Layer three things: prevent entry (patching, MFA, email filtering, phishing awareness), limit spread (least privilege, endpoint protection), and guarantee recovery (a tested 3-2-1 backup with an offline or immutable copy). The offline backup is the decisive control – it lets you restore instead of paying, because ransomware cannot encrypt a copy it cannot reach.
What is the CSA Cyber Essentials mark?
Cyber Essentials is a cybersecurity certification from the Cyber Security Agency of Singapore, designed as a realistic baseline for SMEs. It focuses on five areas: asset management, secure configuration, access control, software updates and malware protection. Achieving it signals to clients and insurers that your business meets a recognised minimum standard.
How much does cyber security cost for a small business in Singapore?
Many of the highest-impact controls – MFA, automatic updates, the verify-by-phone rule, basic email filtering – are free or already included in tools you own like Microsoft 365. Costs rise when you add managed endpoint protection, tested backup, monitoring and an incident-response retainer, which are usually bundled into a per-user managed IT or security plan. Start with the free controls first.
How can I tell if an email is a phishing attempt?
Watch for urgency, a request to change payment or login details, a mismatched or lookalike sender address, and links that do not match the real website. In 2026, grammar is no longer a reliable tell because AI writes clean phishing emails. The safest habit is a rule, not a guess: never act on a payment or credential request from email alone – verify it through a separate, known channel.
Do small businesses in Singapore need to worry about PDPA in a cyber attack?
Yes. If a cyber incident exposes personal data, PDPA obligations apply – including protecting that data with reasonable security and notifying affected individuals and the PDPC where a breach is likely to cause significant harm. Good access control, encryption and a breach-response plan are both security best practice and PDPA compliance.
Where do I start if my SME has done nothing so far?
Start with MFA on every account and a tested backup with an offline copy – those two remove the most risk fastest. Then turn on automatic updates and endpoint protection, add phishing awareness and the verify-by-phone rule, and write a one-page incident plan. From there, a managed IT or security partner can take you to a full CSA Cyber Essentials baseline.
About the author
Written by the Rezolva IT team – we secure Singapore SMEs day to day, from MFA and endpoint protection to email security, tested backups and incident response. This checklist reflects the controls we actually deploy first for clients, ordered by how much real-world risk each one removes.