Ask an Expert: Cybersecurity Readiness for SMEs

This month on Ask an Expert, Trina Choy, Head of Growth & Partnerships, Asia at Northbridge, answers your questions about Cybersecurity Readiness for SMEs.


 

Q: Many SME leaders assume they’re “too small to be a target.” What does the actual threat data show, and why is this assumption dangerous?

A: One of the biggest risks for SMEs is assuming they are too small to attract cybercriminals.


Cybercriminals look for opportunities, not just large organisations. Smaller businesses can be particularly vulnerable due to limited resources and lower cybersecurity maturity.


Singapore’s Cyber Security Agency reported approximately 284,300 infected systems in 2025, a 142% increase from the previous year. While this does not represent the number of businesses breached, it highlights the scale of the threat.


The consequences extend beyond IT, potentially disrupting operations, compromising customer information and damaging business relationships.


My advice is to adopt an “assume breach” mindset. Rather than believing an attack will never happen, prepare your business to detect, respond and recover when it does.

 

 

Q: With limited budgets and no in-house security team, how should an SME leader prioritise their first few cybersecurity investments?

A: Cybersecurity should be built into the way your business operates, not treated as an afterthought.

I would recommend prioritising three areas:

  • Protect access: Implement multi-factor authentication (MFA) across email, financial systems and critical applications.
  • Get the basics right: Keep software updated, protect company devices and maintain reliable backups.
  • Engage the right expertise: If you lack an internal security team, consider a managed security service provider to monitor threats and support incident response.
     

The priority should be investments that reduce the time needed to detect an incident, contain the damage and restore operations.

Cybersecurity is not about buying the most expensive tools. It is about protecting your ability to keep doing business.
 

 

Q: What’s the difference between compliance-driven security (ticking a box) and genuinely effective security, and how can a business tell which one it has?

A: Compliance asks whether you have the right controls in place. Effective security asks whether those controls actually work.

For example, having a documented backup policy is important, but when was the last time your business tested whether its systems could actually be restored? How long did it take?


I encourage leaders to ask their teams for evidence of effectiveness, not simply documentation. This could include recovery tests, access reviews and incident response exercises.


With cyber threats evolving rapidly, annual audits alone are not enough. Security measures need to be continuously monitored and tested.


Compliance demonstrates that you have met a standard. Effective security demonstrates that your business is prepared when something goes wrong.

 

 

Q: AI is now being used on both sides of this fight, by attackers and defenders. Where should SMEs actually be paying attention here?

A: AI offers tremendous productivity benefits, but businesses need to understand how it is being used internally.


Employees may unknowingly expose confidential information by uploading customer data into public AI tools or connecting AI assistants to company systems without appropriate safeguards.


I recommend two priorities.


First, establish clear AI guardrails. Define which tools employees can use and what information can be shared.


Second, gain visibility into AI usage. Technologies such as Netskope’s Security Service Edge (SSE) can help businesses identify AI applications, protect sensitive data and detect risky activities.


The goal is not to restrict innovation, but to enable businesses to adopt AI confidently without introducing unmanaged risks.
 



Q: If you were advising a CEO ahead of Cyber Awareness Month, what three questions should they be asking their own team or vendors this quarter?

A: I would encourage every CEO to ask three simple questions:

  1. To your team: “If we were breached tomorrow, what would happen in the first hour?”

    Understand who is responsible, what actions would be taken and how business operations would be restored.
     
  2. To your security partner: “What have you discovered and addressed in our environment over the past 90 days?”

    Look beyond dashboards and ask for tangible evidence of risks identified and actions taken.
  3. To yourself: “What would one day of downtime cost us, and how long would recovery take?”

    Understanding the financial impact helps turn cybersecurity from a perceived IT expense into an informed business investment.
     

Ultimately, cybersecurity is a leadership responsibility. You don’t need to be a technical expert; you need to ask the right questions and ensure your business is prepared.

 


Ask an Expert is a monthly series in which we call on subject experts within the AustCham Singapore community to answer questions that we may have on a specific topic. The strength of our community is in the diverse expertise within our membership, and we want to use this initiative to tap on the knowledge of our members to enrich the community as a whole.

Our expert for this month is Trina Choy, Head of Growth & Partnerships, Asia at Northbridge, a cybersecurity services provider that delivers managed security solutions

Trina brings more than 15 years of experience in the technology industry. She specialises in building strategic partnerships and helping businesses navigate cybersecurity challenges through practical, scalable solutions. Previously she also worked at Telstra, Salesforce and LinkedIn.

Connect with Trina on LinkedIn.