Home/Cybersecurity

Cybersecurity

The security your IT provider should have set up on day one

We came from offensive security — breaking into companies for a living — before we started running IT for small businesses. The basics are included in every managed plan. This page is the deeper work you buy when you need it.

The short version

Small businesses aren't targeted. They're swept up.

Almost nobody chooses to attack a 15-person company in Singapore. What happens instead is automated: scanners sweep the internet constantly, find a service that shouldn't be exposed or a password that's been reused, and get in without a human ever deciding you were interesting.

That's genuinely good news, because it means you don't need enterprise defences. You need the boring fundamentals done properly and kept that way — which is exactly what small businesses tend to be missing, because nobody owns it.

The other pressure is commercial. More and more Singapore SMEs are being handed security questionnaires by enterprise customers, insurers and government buyers. Failing those quietly costs you contracts you never hear about.

What we usually find

Common results from a first review

  • Ex-staff accounts still activeOften months after they left Common
  • No MFA on emailThe single highest-value fix there is Common
  • Backups never restore-testedNobody knows whether they work Common
  • Everyone is a local adminOne bad click compromises the machine Frequent
  • Forgotten exposed servicesAn old server or open remote-access port Frequent
  • No domain anti-spoofingAnyone can send email as your company Frequent
None of these are expensive to fix. All of them are expensive to ignore.
Included as standard

What every managed plan already covers

Not an add-on, not a separate invoice. Configuring this properly costs us the same as configuring it badly.

Multi-factor authentication

Enforced on every account, with no standing exceptions. The single most effective control available to a small business, and the one most often skipped because it's mildly annoying.

Device hardening

Disk encryption on every laptop, screen locks, endpoint protection that's monitored rather than just installed, and staff who don't run as local administrators.

Patching on a schedule

Operating systems and common applications updated on a defined cadence, with compliance reported to you every month rather than quietly assumed.

Email security

Spam, phishing and impersonation filtering — plus SPF, DKIM and DMARC configured so nobody can send email pretending to be your company.

Access lifecycle

New starters set up with only what they need. Leavers revoked the same day — not next month when somebody remembers. Access reviewed quarterly.

Tested backups

Backup of Microsoft 365, Google Workspace and your servers — with a restore actually performed every quarter and the result written into your report.

Specialist services

The deeper work, quoted as projects

Buy these when a client starts asking questions, when you're chasing a certification, or when you want to know what an attacker would actually find.

Penetration testing

We attack your systems the way a real attacker would — logged in, patiently, looking for the logic nobody thought to protect. Scanners find known patterns; they don't notice that changing a number in a URL shows another customer's records, or that a discount can be applied twice.

  • Web applications and customer portals, tested with real user accounts
  • REST and GraphQL APIs, including endpoints you forgot were public
  • External network testing of everything you have facing the internet
  • Microsoft 365 and cloud configuration review
  • iOS and Android applications

You get an executive summary your director can act on, a technical section your developer can fix from, and a free retest afterwards so the engagement ends with a clean letter you can show clients and insurers.

At a glance

Length
5–10 working days of testing
Safety
Written rules of engagement agreed first. No destructive testing or denial-of-service unless you specifically ask, in an isolated environment
Critical findings
Phoned through the same day. You don't wait for the report to learn your database is exposed
Retest
Included free after your fixes
From
S$3,800
Scope a test
Compliance

PDPA & CSA Cyber Essentials

Compliance has a bad reputation because it's usually sold as paperwork. Done properly it's just security with the evidence written down.

Under the PDPA, every organisation in Singapore — including a five-person one — must appoint a Data Protection Officer and make reasonable arrangements to protect the personal data in its care. If a significant breach happens you may need to notify the PDPC and the affected individuals, and you'll be asked what you had done beforehand. We help you have a good answer.

What's covered

  • PDPA gap assessment across collection, use, disclosure, retention and transfer
  • Data inventory — what personal data you hold, where it lives, who can reach it
  • DPO support: policies, consent notices, and handling access requests
  • Breach response plan with a clear notification decision tree
  • CSA Cyber Essentials gap assessment and full evidence pack
  • Answering the security questionnaires your enterprise clients send you
  • Vendor risk review — your suppliers are your exposure too

We are consultants, not a certification body and not your lawyers. We prepare you for assessment; the certification decision sits with the appointed certification body, and legal advice sits with a qualified practitioner.

At a glance

Length
2–5 weeks including remediation support
Your effort
About an hour each with whoever handles IT, HR and operations
You receive
Gap report, prioritised roadmap, ready-to-use policy templates, and a certification-ready evidence pack
Upkeep
Maintained continuously for Support + Secure clients, rather than rebuilt each renewal
From
S$4,500
Get compliance-ready
Your people

Phishing simulation & staff training

Your firewall has never once approved a fraudulent invoice. A person did that.

We run realistic campaigns using the lures that actually circulate in Singapore — parcel delivery SMS, government-lookalike notices, and the classic message to finance asking for an urgent transfer before a deadline. Increasingly these are AI-written, with none of the spelling mistakes staff were taught to look for.

  • Baseline campaign so you're measuring rather than guessing
  • Singapore-specific lures across email, SMS and messaging apps
  • Short training for anyone who clicks, without naming and shaming
  • A 60-minute all-staff session in plain English
  • A targeted briefing for finance and HR on invoice and payroll fraud
  • Management reporting on click rate, report rate, and movement over time

Always run with management authorisation. We report aggregate trends; individual results are for coaching, not discipline.

At a glance

Length
2 weeks for a one-off; quarterly on the Support + Secure plan
You provide
A staff list, mail allowlisting so simulations land, and management sign-off
You receive
Results, trend reporting, training materials you keep, and a repeatable programme
From
S$1,200 per campaign
Run a simulation
When it goes wrong

Incident response

The first hour decides how bad it gets. That's a bad time to be searching for someone to call.

  • Containment guidance immediately — the part that limits the damage
  • Triage: what was accessed, when, and by whom
  • Recovery from backup, with verification that you're clean before reconnecting
  • PDPC notification assessment and support with the filing
  • A written post-incident report and a hardening plan so it doesn't recur
  • Response times agreed in writing for managed clients, including out of hours

If something is happening right now

Managed clients: use your direct line. Everyone else: email nick.t@onedegreeai.com with URGENT in the subject — it's monitored, and we'll come straight back with a number to call.

  • Don't delete anything — logs and disk state are evidence
  • Don't pay a ransom before taking advice
  • Disconnect affected machines from the network, but leave them powered on
  • Write down what you noticed and when
  • Don't announce anything publicly until you know what actually happened
Email the incident address
Questions

Security, answered plainly

You need the baseline, and it's included in your managed plan — so the honest answer is that you're probably already covered for what matters most. The project work on this page becomes relevant when a customer starts asking security questions, when you're handling a lot of personal data, or when you're chasing a certification to win bigger contracts.

We test conservatively and agree the rules of engagement with you in writing first — systems that are off-limits, testing windows outside business hours, and a contact who can stop us immediately. Destructive techniques and denial-of-service are excluded unless you specifically ask for them in a controlled environment.

Antivirus is one control out of many, and on its own it wouldn't have stopped most of the incidents we've been called to. The common causes are a stolen password with no MFA behind it, a staff member tricked into transferring money, or a service exposed to the internet that nobody remembered was running. None of those are things antivirus is designed to catch.

Yes, and this is one of the most common reasons small businesses call us. We complete it accurately on your behalf, flag anything we can't honestly answer yet, and tell you which gaps are worth closing to win the contract. Managed clients get this as part of the service.

Yes. Get in touch first and don't start deleting things — preserving evidence matters both for understanding what happened and for your position with the PDPC. We'll help you contain it, work out what was accessed, advise on whether it's notifiable, and get you operating again. Managed clients get agreed response times; we take other emergencies when we have capacity.

We take the minimum evidence needed to prove a finding and stop there — we don't extract bulk data to make a point. Anything we hold is encrypted, kept in Singapore, covered by an NDA, and destroyed on an agreed schedule. Nothing is subcontracted offshore and nothing of yours is used to train anything.

Next step

Find out what's exposed — before someone else does

The free review covers the security basics too. No cost, no obligation, and you keep the report either way.