top of page
Search

Cyber Essentials Is Not a Badge It Is Business Continuity

Writer: MZT
MZT
Sep 4
9 min read

A finance staff member gets an email that looks like it came from a regular supplier.


Same name. Same tone. Same kind of invoice. The amount is not crazy. The timing makes sense because month-end is already messy. The email says the supplier has changed bank account details and asks for the next payment to go there.


Nobody is trying to be careless.


The staff member forwards it to the approver. The approver is rushing between calls. The payment goes out.


By the time someone from the real supplier calls to ask why payment is late, the money is gone.


I have heard some version of this story too many times in Singapore.


Sometimes it is not a fake invoice. Sometimes it is a laptop infected after someone clicks a delivery notice. Sometimes it is a former employee account that still works. Sometimes a shared admin password has been passed around for years. Sometimes the backup was “there”, but nobody had tested whether it could actually restore anything.


Then the room gets very quiet.


Not because people finally understand cybersecurity. They understand something simpler.


The business has stopped.


Close-up view of a laptop beside an untouched kopi cup on a kopitiam table.
Small mistakes usually start in very normal places.

The badge is the least interesting part


Cyber Essentials, under Singapore’s national cyber certification approach, gives companies a way to show that they have put basic cyber hygiene in place.


Yes, some customers may ask for it. Larger enterprises, government-linked organisations, or procurement teams may want evidence that suppliers are not taking wild risks with systems and data. That is understandable.


But if the conversation stops at “Can we get the badge?”, something has gone wrong.


The better question is:


If one ordinary thing fails tomorrow, can the company still operate?

One ordinary thing. Not a movie-style hacker in a hoodie.


A compromised laptop.


A forgotten user account.


A phishing email.


An unpatched system.


A backup that fails when you need it.


That is where real business pain starts. Not in theory. In payroll. In customer orders. In delivery schedules. In payment approvals. In WhatsApp groups full of panic. In the COO asking IT, “How long more?” and IT not having a clean answer.


For many SMEs, cyber risk does not arrive as a dramatic crisis at first. It enters through boring gaps that everyone has got used to.


The shared folder that “only a few people know about”.


The old accounting system that cannot be patched because “the vendor no longer supports it, but it still works”.


The admin account used by three people because it is easier.


The staff member who left six months ago but still has access to email, cloud storage, or a SaaS tool.


The backup drive sitting there with a nice green light, quietly useless.


Cyber Essentials matters because it forces the business to look at these habits before they become a very expensive lesson.


Most incidents are not clever


Business owners often imagine cyber attacks as highly technical. Some are. But many cases that hurt SMEs are not clever at all.


They are opportunistic.


They rely on speed, trust, and messy operations.


A finance team is busy near GST filing season. A project manager is chasing a delivery for a client in Jurong. HR is onboarding part-timers. Ops is sharing files with a subcontractor. The managing director is overseas and approving things from a phone.


That is normal business.


Attackers do not need to break everything. They only need one weak point that the company has not cleaned up.


In Singapore, this is especially uncomfortable because many SMEs sit inside larger supply chains. A small vendor may serve an MNC, a logistics player, a healthcare provider, a school, a construction group, or a public-sector customer. The SME may think, “We are small. Who wants to target us?”


Often, the answer is simple.


Someone wants to use you as a door.


Or they want money quickly.


Or they do not care who you are because their phishing emails go out in bulk and your staff happened to click.


That is the annoying truth. You do not need to be famous to be hit. You only need to be open.


Wide-angle view of a quiet HDB void deck notice board with torn paper notices and a single lost access card hanging from a clip.
Access problems are often ordinary and easily missed.

The painful part is usually the downtime


When people talk about cyber incidents, they often focus on data loss, ransom, or reputation.


Those matter.


But when you sit with a company right after something has gone wrong, the first pain is usually more basic.


Can staff log in?


Can finance pay suppliers?


Can the warehouse release goods?


Can the clinic, tuition centre, importer, contractor, insurer, or retailer serve customers today?


Can the company trust its own files?


One infected machine is bad. One infected machine that spreads into shared drives is worse. One infected machine that reaches the accounting system during payroll week is a different kind of stress.


This is where management teams start asking very practical questions.


“Can we restore from backup?”


“When was the last clean backup?”


“Who has the password?”


“Why does that old account still exist?”


“Why did nobody approve the bank detail change properly?”


“Which laptops are affected?”


“Do we have a list?”


Sometimes there is no list.


Not a proper one anyway.


There is a spreadsheet somewhere. Last updated by someone who has left. IT knows some things. Finance knows some things. The outsourced vendor knows some things. Nobody has the full picture.


That is the problem Cyber Essentials is trying to fix at the basic level. It is not trying to turn every SME into a bank-grade security operation. It is asking the company to build enough discipline so that a small incident stays small.


That phrase sounds plain because it is.


Keep small incidents small.


That is business continuity.


Basic discipline beats last-minute heroics


After an incident, people work hard. Very hard.


The IT person stays up late. The vendor is called. Someone searches old emails for contracts. Someone calls the bank. Someone updates customers. Someone tells staff not to open attachments. Someone else has already opened three.


There is a lot of motion.


But hard work after the fact is not the same as preparation.


Preparation is boring. It looks like this:


  • Knowing which laptops, servers, cloud tools, and shared systems the business depends on

  • Removing accounts when staff, interns, contractors, and vendors no longer need access

  • Using multi-factor authentication where compromise would hurt

  • Keeping systems and software patched, especially internet-facing ones

  • Making backups that are separated from the systems they protect

  • Testing whether backups can restore real data

  • Teaching staff how payment scams and phishing emails actually look in daily work

  • Setting rules for approvals when supplier bank details change

  • Having a simple incident contact list that people can find under stress


None of this sounds exciting.


Good.


Exciting is what happens when the file server is encrypted at 8.30 am on a Monday.


Cyber Essentials gives structure to these basics. It makes management decide who owns them, how they are checked, and what “done” actually means.


That last part is important.


Many companies assume these things are handled because somebody once said they were. The IT vendor said backups are running. The software prompts for updates. The admin password is “kept safely”. Staff “should know” not to click strange links.


Should know is not a control.


Hope is not a process.


And “we trust our people” is not the same as helping them avoid traps.


Most staff do not want to cause trouble. They are trying to get work done. If the company gives them weak processes, they will use weak processes. If changing supplier bank details only requires an email, someone will eventually accept an email. If everyone shares passwords because access requests take too long, passwords will be shared.


The discipline has to be built into how work happens.


Eye-level view of a small padlock attached to a metal shutter at a closed neighbourhood shop.
Small controls can prevent a much bigger stoppage.

Cyber risk is an operations issue before it is a technical issue


Some management teams put cybersecurity fully under IT. That is convenient. It is also incomplete.


IT can patch systems. IT can manage accounts. IT can set up MFA. IT can run tools.


But the business decides how work is done.


Finance decides payment approval steps.


HR decides how joiners and leavers are handled.


Operations decides which vendors get access to systems or files.


Management decides whether staff can keep using old systems because replacement feels troublesome.


Sales decides how customer documents are shared.


The DPO worries about personal data, but cannot fix everything alone.


Cyber incidents usually cut across all of this.


That is why Cyber Essentials is useful for everyday business. It creates a management conversation, not just a technical checklist.


A CEO does not need to know every firewall setting. A COO does not need to read every vulnerability report. A finance lead does not need to become a security engineer.


But they do need to ask better questions.


For example:


  • Which systems would stop us from operating if they went down for one day?

  • Who has admin access to those systems?

  • Are former staff and vendors removed quickly?

  • Can a payment instruction be changed by email alone?

  • When did we last test restoring from backup?

  • What would we tell customers if our systems were unavailable tomorrow?

  • Who makes decisions during an incident?


These are management questions.


They are also uncomfortable questions because they expose gaps that have been tolerated for years. Not because people are lazy. Usually because the company grew, added tools, hired people, changed vendors, and kept moving.


Singapore SMEs are good at making things work. That is a strength.


But “can make it work” sometimes creates hidden risk. Manual workaround here. Shared login there. Old laptop kept alive because the software licence is tied to it. A NAS box in the corner with everyone’s files inside. A WhatsApp approval because the boss is travelling.


All fine, until not fine.


A certificate can open doors, but discipline keeps them open


There is a practical reason many companies look at Cyber Essentials. Customers ask. Tenders ask. Vendor risk questionnaires ask. Procurement teams want assurance.


That is fair. Trust needs evidence.


A certificate can help show that the company has taken basic steps. It may make conversations with larger customers smoother. It may reduce repeated back-and-forth when someone asks, “What do you have in place?”


But the certificate should be the by-product.


The real value is what changes inside the company while preparing for it.


A proper review often reveals simple things:


  • Too many people have admin rights

  • Nobody owns the asset list

  • Backups run, but restore testing is missing

  • Staff use personal devices for work without clear rules

  • Some systems are patched quickly, others are forgotten

  • Vendor access is granted but not reviewed

  • Incident response exists only in someone’s head


These are not exotic findings. They are normal.


That is why fixing them is powerful.


The goal is not perfection. Perfection is expensive and usually fake. The goal is to reduce the chance that one mistake becomes a full business stoppage.


If a laptop is compromised, you can isolate it.


If a staff member clicks a phishing link, MFA can reduce the damage.


If an employee leaves, access gets removed before it becomes a problem.


If a system fails, tested backups give you options.


If a supplier email is spoofed, payment checks catch it before funds move.


That is the difference between disruption and disaster.


Top-down view of a paper checklist held down by a chilli sauce bottle at a hawker centre table.
Useful security is usually a checklist people actually follow.

The lesson is simple and slightly boring


Every company has a few things that cannot fail for long.


For one company, it is the order system.


For another, it is email.


For another, it is the accounting platform.


For another, it is the customer database, warehouse scanner, booking system, design files, or project folder.


Cyber Essentials helps a company identify the basic protections around those things. Not all protections. The basic ones.


That matters because many businesses do not collapse from one huge technical failure. They stumble because several small weaknesses line up.


One person clicks.


One password is reused.


One account is still active.


One server is unpatched.


One backup cannot restore.


One approval step is skipped.


Then everyone is stuck.


This is why business leaders should treat Cyber Essentials as part of continuity planning. Not as decoration for the website. Not as a procurement exercise to rush through at the last minute. Not as something to throw to IT and forget.


The badge may be useful. The habits are more useful.


Start with the things that would hurt tomorrow


If the company wants to take action, start small but be honest.


Do not begin with a 60-page policy nobody will read.


Begin with the next bad Tuesday.


Ask what would hurt if it happened tomorrow morning.


Then work backwards.


Find the systems that keep the business moving.

List the tools, devices, accounts, and vendors that matter. If nobody has a clear list, that is the first job.


Clean up access.

Remove old accounts. Reduce admin rights. Stop sharing passwords. Turn on MFA for important systems. This is not glamorous work, but it prevents a lot of pain.


Fix the money process.

Supplier bank detail changes should not rely on email alone. Add a call-back step using a known number, not the number in the email. Make it normal, not personal.


Patch what faces the internet.

Old VPNs, remote access tools, servers, websites, and network devices should not be left alone until something breaks. Attackers love neglected systems.


Test backups properly.

A backup is only useful if it restores. Test real files. Test the system people actually need. Keep at least one backup protected from the same attack that could hit the main system.


Teach staff using real examples.

Do not just say, “Beware of phishing.” Show them fake invoice emails, parcel scams, payroll changes, QR code tricks, and supplier impersonation. Use examples that look like their work.


Write down the first hour plan.

If something strange happens, who gets called? Who can disconnect a machine? Who talks to customers? Who decides whether to shut down a system? Keep it short enough to use.


That is often enough to change the risk picture.


Not solve everything. Nothing does.


But it gives the company a fighting chance.


And that is the point.


Cyber Essentials is useful because it turns common sense into business routine. It makes the company less dependent on luck, memory, and that one IT person who knows where everything is.


A badge can help others trust you.


The discipline helps you keep your business going when something goes wrong. Enquire more: hello@mzt.one


 
 
 

Comments


Momentum Z

31 Harrison Road, #05-02, CMM Global Building Singapore 369649

PAGES

​Mon-Fri: 930AM-530PM SGT

SERVICES

vCISO + GRC

MDR/EDR/IR

VAPT + Testing

AI Security

Cloud Security

Space Specialisation

QUICK LINKS

Privacy Policy

Terms & Conditions

© 2026 MOMENTUM  Z. ALL RIGHTS RESERVED

bottom of page