Urgent.News

What's breaking now, across thousands of outlets.

Tech

Why Singapore SMEs should treat cybersecurity as a sales issue

Consider a small services firm preparing to win its first major corporate account. The proposal is strong. The pricing is competitive. The team has shown that it can deliver. Then the prospective customer asks a different set of questions. Where will our information be stored? Who can access it? What happens when an employee leaves? […] The post Why Singapore SMEs should treat cybersecurity as a…

Why Singapore SMEs should treat cybersecurity as a sales issue

Small services firms preparing for significant corporate accounts often encounter new questions about cybersecurity. These inquiries are not about understanding the supplier's product but rather about ensuring customers can safely depend on the business. Treating cybersecurity as part of an SME's growth strategy is crucial because winning a customer's interest and becoming an acceptable supplier are two distinct challenges. A compelling proposal does not establish trust on its own.

Microsoft exemplifies how security is linked to supplier eligibility through its Supplier Security and Privacy Assurance program. Enrolled suppliers must undergo annual self-attestation against applicable requirements, with additional assurance for higher-risk activities. This demonstrates a clear commercial distinction: possessing the ability to deliver a service does not guarantee the right to do so.

When pursuing larger customers, SMEs should inquire about security expectations alongside budget, scope, and delivery dates.

A supplier's risk extends beyond the business itself. For instance, DBS reported a ransomware incident at its printing vendor, Toppan Next Tech, which potentially compromised personal information of about 8,200 customers. Although DBS's systems remained unaffected, the customer's exposure highlights the importance of supplier due diligence. Asking about access controls or incident response helps understand what happens after information leaves the company's environment.

While a company's choice of a trusted cloud provider like Amazon Web Services indicates security measures, it does not fully address the customer's concerns. AWS operates under a shared responsibility model, where customers retain control over data, permissions, applications, and security configurations. For SMEs, this means explaining their operating practices and substantiating claims rather than merely naming a reputable provider.

To prepare for significant customer requests, SMEs should compile a collection of security evidence before being asked. Start by documenting the services delivered, external providers involved, access approval processes, incident handling, and relevant certifications. Maintain records that can be retrieved by authorized staff. This distinction between assertions and evidence is crucial.

While a statement about the existence of backups differs from a record showing their restoration, maintaining proper documentation establishes credibility with potential customers.

Written by urgent.news from e27's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at e27.co →

More in Tech

A Determinism Check Has to Leave the Process

Code: Megapixel99/nondet The obvious way to check whether a Python function is deterministic is to call it twice and compare.

  • nondet tool detects nondeterminism in Python functions
  • Re-runs functions with fixed input ladder in fresh processes
  • Identifies hash-order defects and environment-based nondeterminisms

Keeping forces fighting fit in digital age

LUMUT: Defence technology specialist Mindmatics Sdn Bhd is spearheading the digital transformation of the armed forces’ Health Services Division through the implementation of Phase 2 of the Centralised Medical Repository System (Centromeres).

Shield Your 2026 World Cup Tickets: A Python Bot‑Detection Guide

How to Secure Your 2026 World Cup Tickets — A Practical Guide (with a Simple Python Watcher) Introduction The 2026 FIFA World Cup is already triggering a flood of searches like “how to buy World Cup tickets safely” and “detect ticket‑selling bots.” With three host nations and a record‑breaking 48‑team format, genuine fans are battling…

  • Official ticketing process involves FIFA account, verification, and purchase token
  • Bots exploit site's IP throttling and bypass CAPTCHA, prohibited by BOTS Act 2016
  • Python script checks official API for tickets under face value every 30 seconds

More from Monday 21 September →