{
  "id": 8826370,
  "title": "Why Singapore SMEs should treat cybersecurity as a sales issue",
  "url": "https://urgent.news/2026/09/21/why-singapore-smes-should-treat-cybersecurity-as-a-sales-issue",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-21T03:00:15.000Z",
  "source": {
    "name": "e27",
    "slug": "e27",
    "url": "https://e27.co/why-singapore-smes-should-treat-cybersecurity-as-a-sales-issue-20260920/"
  },
  "original_language": "en",
  "account": "Small services firms preparing for significant corporate accounts often encounter new questions about cybersecurity. These inquiries are not about understanding the supplier's product but rather about ensuring customers can safely depend on the business. Treating cybersecurity as part of an SME's growth strategy is crucial because winning a customer's interest and becoming an acceptable supplier are two distinct challenges. A compelling proposal does not establish trust on its own.\n\nMicrosoft exemplifies how security is linked to supplier eligibility through its Supplier Security and Privacy Assurance program. Enrolled suppliers must undergo annual self-attestation against applicable requirements, with additional assurance for higher-risk activities. This demonstrates a clear commercial distinction: possessing the ability to deliver a service does not guarantee the right to do so. When pursuing larger customers, SMEs should inquire about security expectations alongside budget, scope, and delivery dates.\n\nA supplier's risk extends beyond the business itself. For instance, DBS reported a ransomware incident at its printing vendor, Toppan Next Tech, which potentially compromised personal information of about 8,200 customers. Although DBS's systems remained unaffected, the customer's exposure highlights the importance of supplier due diligence. Asking about access controls or incident response helps understand what happens after information leaves the company's environment.\n\nWhile a company's choice of a trusted cloud provider like Amazon Web Services indicates security measures, it does not fully address the customer's concerns. AWS operates under a shared responsibility model, where customers retain control over data, permissions, applications, and security configurations. For SMEs, this means explaining their operating practices and substantiating claims rather than merely naming a reputable provider.\n\nTo prepare for significant customer requests, SMEs should compile a collection of security evidence before being asked. Start by documenting the services delivered, external providers involved, access approval processes, incident handling, and relevant certifications. Maintain records that can be retrieved by authorized staff. This distinction between assertions and evidence is crucial. While a statement about the existence of backups differs from a record showing their restoration, maintaining proper documentation establishes credibility with potential customers.",
  "summary": "Consider a small services firm preparing to win its first major corporate account. The proposal is strong. The pricing is competitive. The team has shown that it can deliver. Then the prospective customer asks a different set of questions. Where will our information be stored? Who can access it? What happens when an employee leaves? […] The post Why Singapore SMEs should treat cybersecurity as a…",
  "key_points": [],
  "editors_take": "Singapore SMEs must integrate cybersecurity into their sales strategies to win over larger customers, who increasingly require assurance that their suppliers can safeguard sensitive information and systems.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}