Multi-factor authentication
Enforced on every account, with no standing exceptions. The single most effective control available to a small business, and the one most often skipped because it's mildly annoying.
Home/Cybersecurity
CybersecurityWe came from offensive security — breaking into companies for a living — before we started running IT for small businesses. The basics are included in every managed plan. This page is the deeper work you buy when you need it.
Almost nobody chooses to attack a 15-person company in Singapore. What happens instead is automated: scanners sweep the internet constantly, find a service that shouldn't be exposed or a password that's been reused, and get in without a human ever deciding you were interesting.
That's genuinely good news, because it means you don't need enterprise defences. You need the boring fundamentals done properly and kept that way — which is exactly what small businesses tend to be missing, because nobody owns it.
The other pressure is commercial. More and more Singapore SMEs are being handed security questionnaires by enterprise customers, insurers and government buyers. Failing those quietly costs you contracts you never hear about.
Common results from a first review
Not an add-on, not a separate invoice. Configuring this properly costs us the same as configuring it badly.
Enforced on every account, with no standing exceptions. The single most effective control available to a small business, and the one most often skipped because it's mildly annoying.
Disk encryption on every laptop, screen locks, endpoint protection that's monitored rather than just installed, and staff who don't run as local administrators.
Operating systems and common applications updated on a defined cadence, with compliance reported to you every month rather than quietly assumed.
Spam, phishing and impersonation filtering — plus SPF, DKIM and DMARC configured so nobody can send email pretending to be your company.
New starters set up with only what they need. Leavers revoked the same day — not next month when somebody remembers. Access reviewed quarterly.
Backup of Microsoft 365, Google Workspace and your servers — with a restore actually performed every quarter and the result written into your report.
Buy these when a client starts asking questions, when you're chasing a certification, or when you want to know what an attacker would actually find.
We attack your systems the way a real attacker would — logged in, patiently, looking for the logic nobody thought to protect. Scanners find known patterns; they don't notice that changing a number in a URL shows another customer's records, or that a discount can be applied twice.
You get an executive summary your director can act on, a technical section your developer can fix from, and a free retest afterwards so the engagement ends with a clean letter you can show clients and insurers.
Compliance has a bad reputation because it's usually sold as paperwork. Done properly it's just security with the evidence written down.
Under the PDPA, every organisation in Singapore — including a five-person one — must appoint a Data Protection Officer and make reasonable arrangements to protect the personal data in its care. If a significant breach happens you may need to notify the PDPC and the affected individuals, and you'll be asked what you had done beforehand. We help you have a good answer.
We are consultants, not a certification body and not your lawyers. We prepare you for assessment; the certification decision sits with the appointed certification body, and legal advice sits with a qualified practitioner.
Your firewall has never once approved a fraudulent invoice. A person did that.
We run realistic campaigns using the lures that actually circulate in Singapore — parcel delivery SMS, government-lookalike notices, and the classic message to finance asking for an urgent transfer before a deadline. Increasingly these are AI-written, with none of the spelling mistakes staff were taught to look for.
Always run with management authorisation. We report aggregate trends; individual results are for coaching, not discipline.
The first hour decides how bad it gets. That's a bad time to be searching for someone to call.
Managed clients: use your direct line. Everyone else: email nick.t@onedegreeai.com with URGENT in the subject — it's monitored, and we'll come straight back with a number to call.
You need the baseline, and it's included in your managed plan — so the honest answer is that you're probably already covered for what matters most. The project work on this page becomes relevant when a customer starts asking security questions, when you're handling a lot of personal data, or when you're chasing a certification to win bigger contracts.
We test conservatively and agree the rules of engagement with you in writing first — systems that are off-limits, testing windows outside business hours, and a contact who can stop us immediately. Destructive techniques and denial-of-service are excluded unless you specifically ask for them in a controlled environment.
Antivirus is one control out of many, and on its own it wouldn't have stopped most of the incidents we've been called to. The common causes are a stolen password with no MFA behind it, a staff member tricked into transferring money, or a service exposed to the internet that nobody remembered was running. None of those are things antivirus is designed to catch.
Yes, and this is one of the most common reasons small businesses call us. We complete it accurately on your behalf, flag anything we can't honestly answer yet, and tell you which gaps are worth closing to win the contract. Managed clients get this as part of the service.
Yes. Get in touch first and don't start deleting things — preserving evidence matters both for understanding what happened and for your position with the PDPC. We'll help you contain it, work out what was accessed, advise on whether it's notifiable, and get you operating again. Managed clients get agreed response times; we take other emergencies when we have capacity.
We take the minimum evidence needed to prove a finding and stop there — we don't extract bulk data to make a point. Anything we hold is encrypted, kept in Singapore, covered by an NDA, and destroyed on an agreed schedule. Nothing is subcontracted offshore and nothing of yours is used to train anything.
The free review covers the security basics too. No cost, no obligation, and you keep the report either way.