A recent study by the Cyber Security Agency of Singapore (CSA) revealed that most companies need more essential cyber-security measures, despite four out of five firms experiencing a cyber-security incident each year.
The survey, released on March 28, involved 2,036 organizations of all sizes across various industry sectors. Disturbingly, many of these firms missed out on basic cyber-security measures recommended by CSA, leaving themselves inadequately protected against cyber threats.
The study indicated that a critical challenge for companies is the lack of knowledge in cyber security and concerns about costs and whether they would be specific targets for cyber threats. Additionally, nearly half of the businesses surveyed faced cyber-security incidents several times a year, with ransomware being the most common, followed by social engineering attacks and exploitation of misconfigured cloud systems.
Another alarming finding was that more than 40% of the companies faced business disruption, reputational damage, or data loss due to cyber-security incidents, with over 30% of respondents reporting financial losses.
The survey also highlighted that companies still need to fully implement essential cyber-security measures recommended by CSA, with only one in three organizations implementing at least three of the five categories of measures.
Communications and Information Minister Josephine Teo emphasized the importance of adopting the complete package of essential measures in all five categories, pointing out that the current partial adoption of critical security measures is inadequate and exposes organizations to unnecessary cyber risks.
Small and medium-sized enterprises (SMEs) needed to strengthen virus protection and access control, with less than 20% fully adopting such measures. Nearly 30% of required SMEs incident responses and updated their software regularly.
The study revealed that many companies cited a need for knowledge and experience as their top challenges in adopting more robust cyber-security protocols, with roughly half expressing skepticism about the likelihood of becoming targets of cyber attacks.
In response to the report, CSA Chief Executive David Koh stressed the need for organizations to prioritize cyber security and take advantage of available funding support and resources. He cautioned against addressing cyber-security only after an incident has occurred, emphasizing the higher cost and risks involved in doing so.
The survey emphasizes the need for companies to prioritize and fully implement essential cyber-security measures to protect themselves against the increasing prevalence of cyber threats.
For more details about the study and its implications for companies, visit CSA’s official website.













