Category: Cybersecurity

  • Cyber Essentials First or ISO 27001 First? The Pathway Most Singapore SMEs Get Wrong

    A conversation I have almost weekly: a company wants “the ISO 27001” because a customer asked about their cybersecurity. Halfway through scoping, it turns out what the customer actually asked for was evidence of good cyber hygiene — and there was a faster, cheaper way to give it. Here is how to think about the pathway.

    Two different questions

    Cyber Essentials (CSA’s national mark) answers the question: “has this company done the cybersecurity basics?” Asset inventory, anti-malware, access control, secure configuration, software updates, backups, incident response. It is designed for SMEs and is assessed on declared evidence — practical, fast, affordable.

    ISO 27001 answers a bigger question: “does this company run a management system that continuously governs its information security?” It is an international certification with a risk-based ISMS, internal audits, management reviews, and a certification body audit cycle. It is what MNCs, regulated industries and overseas customers recognise.

    The mistake in both directions

    Overshooting: a 15-person local firm signs up for ISO 27001 because “it sounds more powerful”, spends months and five figures, and discovers their customers would have accepted Cyber Essentials. The ISMS then becomes shelf-ware they dread maintaining.

    Undershooting: a growing tech firm gets Cyber Essentials, then six months later a large client’s vendor assessment demands ISO 27001 anyway — and they start again from scratch, paying twice for overlapping work.

    The honest decision test

    • Who is asking? Local SME customers, government SME programmes → Cyber Essentials usually satisfies. MNCs, financial institutions, overseas clients, formal vendor-assessment questionnaires → ISO 27001 is usually the named requirement. Read the actual contract clause before deciding.
    • What do you hold? If you process sensitive personal data, run client systems, or sit in a critical supply chain, the risk-based depth of 27001 (or Cyber Trust Mark) fits. If your exposure is ordinary office IT, Essentials-level hygiene is genuinely proportionate.
    • Where are you going? If enterprise clients are 12–18 months away in your plan, sequencing matters more than choosing.

    The sequencing secret: the work overlaps heavily

    This is the part most companies never get told: the two are not separate projects. The asset inventories, access-control policies, patching discipline, backup regime and incident-response plan you build for Cyber Essentials map directly onto ISO 27001’s Annex A controls. Done deliberately, Cyber Essentials becomes phase one of a future ISMS — the certificate you can show customers this quarter, while the 27001 foundation quietly accumulates underneath.

    The same logic applies to the Cyber Trust Mark, CSA’s risk-based mark for more digitally mature organisations: its domains overlap substantially with 27001 controls, so a company holding one should never pay full price to build the other from zero.

    Bottom line

    Start from the contract in front of you, not the certificate with the bigger name. If nobody has named a standard yet, Cyber Essentials first is the right default for most Singapore SMEs — provided whoever builds it does so with the 27001 mapping in mind, so nothing is thrown away when you level up.

    Thong Kian Leong is the founder and principal consultant of Sage Shield Safety Consultants, a bizSAFE STAR and CSA Cyber Security Essentials-certified firm that has served 1,300+ organisations, delivering ISO 27001, Cyber Essentials and Cyber Trust Mark end to end. Talk to us about the right pathway.

  • Cyber Trust Mark Tiers Explained: Which One Your Company Actually Needs

    Every week I meet business owners who ask the same question: “Which Cyber Trust Mark tier do we actually need?” It is usually asked with a quotation from some consultant on the table, and almost always the tier on that quotation is wrong — in one direction or the other. Here is the plain-English version I give them over coffee.

    First, what the Cyber Trust Mark actually is

    The Cyber Trust Mark (CTM) is the Cyber Security Agency of Singapore’s certification for organisations with a more mature digital footprint — the bigger sibling of the Cyber Essentials Mark, which covers baseline cyber hygiene for smaller companies. Where Cyber Essentials asks “have you done the basics?”, Cyber Trust asks “does your cybersecurity match your actual risk?”

    That distinction drives everything. CTM is a risk-based certification: you first assess your organisation’s cybersecurity risk profile, and that assessment points you to one of five preparedness tiers. You then implement the domains required for that tier and are audited against them by an appointed certification body.

    The five tiers, in plain English

    Each tier adds domains on top of the previous one — from 10 domains at the entry tier to 22 at the top:

    • Tier 1 — Supporter (10 domains): for organisations with a limited digital footprint and low cyber-risk exposure. Covers the foundations: risk management, asset management, access control, anti-malware, system security, backups, incident response.
    • Tier 2 — Practitioner (12 domains): for companies moderately dependent on digital systems. Adds structure around training and awareness and data protection.
    • Tier 3 — Promoter (16 domains): the first tier where governance enters the picture — documented policies and procedures, leadership oversight, BYOD controls, secure software development where relevant.
    • Tier 4 — Performer (19 domains): for organisations where digital systems are business-critical. Expect scrutiny of your cyber strategy, third-party risk, and exercising — not just having — your incident response.
    • Tier 5 — Advocate (22 domains): the full framework, for organisations with extensive digital reliance and the highest risk exposure — typically larger enterprises and those in sensitive supply chains.

    How to choose — and the two classic mistakes

    Mistake #1: choosing a higher tier for prestige. I have seen SMEs ask for Advocate “because it looks better”. Every extra domain is real work — policies you must live by and evidence you must produce at audit, year after year. If your risk assessment points to Practitioner, certifying at Practitioner is the credible outcome; auditors and enterprise customers know exactly how the tiers work.

    Mistake #2: choosing a lower tier to save cost when a contract demands otherwise. Increasingly, government and enterprise tenders specify a minimum tier. If the contracts you want require Tier 3, certifying at Tier 1 saves you money and wins you nothing. Start from the question: what do my customers and regulators expect of a company holding my kind of data?

    The honest answer usually comes out of the risk assessment itself. When we run one, the tier tends to select itself: your digital dependence, the sensitivity of the data you hold, and who is in your supply chain do the deciding.

    What the journey looks like

    1. Risk assessment — establish your risk profile and confirm the target tier.
    2. Gap analysis — map what you already have against the tier’s domains. Most companies are further along than they think in some areas, and blind in others (backup testing and incident-response exercising are the usual blind spots).
    3. Implementation — close the gaps: policies, technical controls, training, evidence trails.
    4. Certification audit — by a CSA-appointed certification body.

    For a typical SME at the lower tiers this is a matter of weeks to a few months. At the upper tiers — we are currently delivering a Tier 4 implementation for an SGX-listed group, spanning VAPT coordination and awareness training for several hundred staff — it is a structured programme across a quarter or more.

    What it costs, roughly

    Consultancy fees scale with tier and organisation size — from around the price of a bizSAFE package at the entry tier to five figures for Advocate-level engagements. Certification-body audit fees are separate. Two pieces of good news: CSA runs support schemes with co-funding for eligible SMEs, and if you already hold ISO 27001, a large share of your existing controls maps directly onto the CTM domains — you should not be paying to build the same thing twice. The reverse is also true: CTM work done properly becomes a head start on ISO 27001 later.

    The bottom line

    Pick the tier your risk profile and your customers demand — not the one that flatters, and not the one that merely saves. If you are unsure, a one-hour conversation about your data, systems and contracts usually settles it definitively.

    Thong Kian Leong is the founder and principal consultant of Sage Shield Safety Consultants, a bizSAFE STAR and CSA Cyber Security Essentials-certified firm that has served 1,300+ organisations across 30+ compliance schemes, including Cyber Trust Mark, Cyber Essentials and ISO 27001. Talk to us about the Cyber Trust Mark.