HomeInsights › Threat Landscape
Threat Landscape

Ransomware in Singapore: The Real Cost to SMEs and the Governance Gap That Lets It In

Drawing on CSA's Singapore Cyber Landscape 2024/2025 and recent PDPC enforcement decisions, this article shows how ransomware incidents actually unfold for Singapore SMEs and why a structured GRC programme and Cyber Trust Mark certification close the governance gaps attackers exploit.

By Infracom Team20 August 20267 min read
Watch the short explainer, then read on. More on our YouTube channel.

Ransomware is no longer a large-enterprise problem in Singapore. CSA's own reporting shows cases rising sharply year on year, and PDPC's enforcement decisions confirm that small and mid-sized service providers are being fined, directed to remediate, and in at least one case ordered to obtain certification after an attack. The pattern across these cases is consistent: the technical failure that let the attacker in was almost always a governance failure first.

What the numbers show

Ransomware cases reported to the authorities rose by more than 20% in 2024 (159 cases) compared to 132 cases in 2023, while infected infrastructure rose by 67% to 117,300 systems in 2024 from 70,200 cases in 2023. This is not an isolated spike. Ransomware attacks saw a 21% increase in reported cases, with MNCs and listed firms in manufacturing prime targets, while SMEs in professional services (consulting, legal, accounting) were disproportionately targeted, and data encryption remained a preferred tactic in this sector due to its operational impact.

Perhaps more revealing than the attack count is why the infections succeeded. CSA's analysis revealed that most of these infections involved old malware strains with readily available remediation measures which were not adopted, underscoring that even as ransomware and other cyber threats grew, users were still failing to update and patch vulnerable software. These findings come from CSA's Singapore Cyber Landscape 2024/2025 report, the national reference point for how the threat picture is actually moving.

What happens after the attack: PDPC's decisions

CSA's report describes the threat. PDPC's enforcement decisions describe the consequence, and they are more instructive for SME leaders than any threat statistic, because they name the exact control gaps that regulators found after the fact.

Ezynetic: a SaaS provider fined and directed to certify

In one decision, a Singapore SaaS provider serving licensed moneylenders was found to have breached its Protection Obligation after a ransomware attack. The Organisation's servers were infected by ransomware on or about 24 June 2024, and consequently, 190,589 individuals' personal data was exfiltrated and posted for sale. The underlying causes were unremarkable and entirely preventable: a threat actor had exploited a vulnerable web service to gain access to the system administrator account, which was protected by weak passwords such as "p@ssword1" or "Password@1," and the organisation had not conducted any periodic vulnerability assessments or penetration testing of its infrastructure.

PDPC did not stop at a fine. The breach resulted in the exfiltration of personal data belonging to 190,589 individuals, which were posted for sale on the dark web, and the PDPC directed the Organisation to obtain the Cyber Security Agency's Cyber Trustmark Certification for its new IT network within nine months of the decision. A regulator explicitly ordering certification as a remedial condition is a strong signal of how PDPC now views structured certification: not a nice-to-have, but evidence of reasonable security arrangements under the Personal Data Protection Act.

PDPC also rejected the argument that post-breach spending should soften the penalty. The PDPC indicated that incurring significant financial expenses in implementing remedial measures post-data breach is not necessarily a mitigating factor for any financial penalty imposed, as such measures are a necessary part of an organisation's ordinary compliance with the PDPA's Protection Obligation. In other words, prevention and remediation are both expected as ordinary cost of doing business — not as goodwill after the fact.

SESAMi and Abecha: the same failures, a shared network

A more recent decision, announced in early 2026, involved a B2B e-commerce service provider and its subsidiary. On 26 February 2026, the PDPC announced that it had issued a financial penalty and directions against an organisation and its subsidiary for contravening the PDPA's Protection Obligation, in a decision involving a ransomware incident affecting a shared network managed by a B2B e-commerce service provider, where investigations revealed security lapses including unpatched systems, weak access controls, and failure to enforce multi-factor authentication.

The specific gaps were laid out in detail: password and access control management were insufficient — in particular, password rotation was not implemented, and access control policies, which included the requirement for multi-factor authentication for administrator accounts, were not strictly enforced, and files containing personal data were not encrypted at the file level. The subsidiary was not spared simply because it relied on group-level arrangements. The PDPC acknowledged that the subsidiary did not have the autonomy to depart from centrally managed group-level security arrangements, but stated that subsidiaries are still required to comply with a minimum standard of conduct in such situations.

PDPC also accepted voluntary undertakings from three other companies over separate incidents in the same period. The PDPC announced its acceptance of voluntary undertakings from three companies, each incident likewise concerning separate ransomware and system compromises, arising from weaknesses including lack of multi-factor authentication, outdated systems, and inadequate monitoring. Four separate organisations, four separate incidents, the same three or four root causes each time.

What these cases have in common

← Swipe to compare →

Governance gapEzynetic (2025 decision)SESAMi / Abecha (2026 decision)
Access controlWeak, unrotated system administrator passwords; no minimum complexity enforcedPassword rotation not implemented; MFA required by policy but not enforced
Vulnerability managementNo periodic vulnerability assessment or penetration testing conductedUnpatched systems identified during investigation
Data protection at restPersonal data exfiltrated and posted for saleFiles containing personal data not encrypted at file level
Regulatory outcomeFinancial penalty plus direction to obtain Cyber Trust Mark certification within nine monthsFinancial penalty and directions; three related parties accepted voluntary undertakings

None of these gaps required a novel exploit or a sophisticated adversary. Each is the kind of control weakness that a structured governance, risk and compliance (GRC) programme is specifically designed to surface and close before a regulator does.

What regulators and frameworks expect

Singapore SMEs handling personal data sit at the intersection of two expectations. The Personal Data Protection Commission enforces the Protection Obligation under the PDPA: organisations must implement reasonable security arrangements to prevent unauthorised access, use, or disclosure of personal data, and PDPC's published decisions are the clearest guide to what "reasonable" means in practice, because they set out exactly which controls were missing in each real case.

Separately, CSA runs the national certification schemes that let an organisation demonstrate its security posture before, not after, an incident. The Cyber Essentials mark recognises organisations that have put in place cyber hygiene measures, while the Cyber Trust mark is a mark of distinction to recognise organisations with comprehensive cybersecurity measures and practices. Cyber Trust has five cybersecurity preparedness tiers, with 10 to 22 domains under each tier, and organisations use the Cyber Trust mark risk assessment framework to identify which tier is more suitable for their needs.

← Swipe to compare →

AttributeCyber Essentials markCyber Trust mark
PurposeBaseline cyber hygiene for organisations starting their cybersecurity journeyComprehensive, risk-based certification for larger or more digitalised operations
ApproachPrescriptive, fixed set of measuresRisk-based, tiered against the organisation's digital exposure
Best fitMost SMEs, and organisations new to formal certificationSMEs and larger firms with higher digital exposure, or where a regulator has directed certification

Alongside certification, CSA's SingCert function is the national reporting and advisory channel for incidents. The Singapore Cyber Emergency Response Team (SingCERT) responds to cybersecurity incidents for its Singapore constituents and was set up to facilitate the detection, resolution and prevention of cybersecurity related incidents on the internet. An organisation with an incident response plan aligned to SingCERT's guidance, rather than one improvised during an active attack, is in a materially stronger position both operationally and when PDPC later reviews its response.

How to prepare: practical steps for a security lead

The PDPC decisions above point to a short, repeatable list of controls. None require an enterprise budget.

  • Lock down administrator accounts. Enforce strong, unique passwords with a minimum complexity standard, a fixed rotation period, and multi-factor authentication on every privileged account — not just a written policy that isn't checked.
  • Run regular vulnerability assessments and penetration testing. Both PDPC cases cited above involved organisations that had never tested their own infrastructure for exploitable weaknesses.
  • Patch on a schedule, not a backlog. CSA's finding that most 2024 infections involved old, remediable malware strains is a direct argument for a documented patch management cadence.
  • Encrypt personal data at rest, not just in transit. File-level encryption was specifically flagged as missing in one recent PDPC decision.
  • Extend minimum standards to subsidiaries and vendors. Group-level security arrangements do not exempt a subsidiary from its own Protection Obligation compliance.
  • Build and rehearse an incident response plan aligned to SingCERT's guidance, so containment and notification timelines are met without improvisation.
  • Pursue Cyber Essentials or Cyber Trust Mark certification proactively, rather than waiting for it to arrive as a regulatory direction after a breach has already occurred.

Each of these is a governance control before it is a technical one: someone has to own the policy, verify the evidence, and keep it current. That ownership is precisely what a structured GRC programme provides, and its absence is precisely what PDPC's decisions keep finding.

How Infracom helps

Infracom's GRC advisory practice builds the governance layer that closes the gaps found in these PDPC decisions — access control policy, vulnerability management cadence, evidence for the Protection Obligation, and readiness for CSA's Cyber Essentials or Cyber Trust Mark certification — delivered by an all-Singaporean SQEP team at rates built for SME budgets. If your organisation needs to demonstrate reasonable security arrangements before a regulator asks, or is working toward certification following an incident, our GRC advisory service is the practical starting point.

Sources (9)
  1. Singapore Cyber Landscape 2024/2025
  2. A Decade of Strengthening Singapore's Cyber Defence Amid Escalating Threats
  3. CSA's Singapore Cyber Landscape 2024/2025 Report (Clyde & Co)
  4. PDPC All Commissions' Decisions
  5. PDPC Decision: Breach of the Protection Obligation by Ezynetic
  6. Singapore: PDPC issues financial penalty against Ezynetic Pte. Ltd. for ransomware-related data breach (Baker McKenzie)
  7. Singapore: Recent PDPC Decisions Emphasise Ransomware Risks (Baker McKenzie)
  8. SingCert
  9. Cyber Trust

Get Infracom Insights by email

Practical cybersecurity governance and regulatory updates for Singapore and Australia. No more than a few emails a month; unsubscribe any time.

Infracom Consultancy Integration Pte Ltd

Your one-stop IT & cybersecurity partner — Singapore HQ since 2008, expanding to Australia in 2026.

506 Chai Chee Lane

Singapore 469026

Services
IT InfrastructureCloud SolutionsCybersecurityManaged ServicesData Center SolutionsIT Consulting
Consulting
SQEPGRCVAPT
Approach
MethodologyAbout UsInsightsNewsletterPrivacy Policy
Hours

Mon – Fri
9AM – 6PM SGT

Follow us
© Infracom Consultancy Integration Pte Ltd. All rights reserved.Privacy Policy