The essential tools that block 2023’s top cyber risks
To boost reach and revenue, digitalisation is a must for companies. But cyberattacks are becoming more sophisticated, threatening business continuity. Learn the layers of security measures you should adopt to safeguard your company.
Businesses of all sizes need protection from cyberattacks.
Global companies are beefing up online security measures to achieve business growth
Singtel offers a range of cybersecurity products and services to protect your business as you expand in the digital age.
Digital transformation has become a top priority for many Asia-Pacific companies. Despite economic uncertainties, over 70% of these businesses aim to ramp up digitalisation by 2025.1
Cybersecurity is essential to this process, especially with online threats becoming bolder and more innovative. According to a recent threat report,2 even run-of-the-mill script kiddies can now easily access advanced ransomware on the dark web, such as the one that pushed a Japanese conglomerate to halt some of its global operations in 2021.3
Cyberattacks in Singapore
Almost 2 million attacks in Q2 2022 alone.4
Ransomware and data theft were the most common attacks.5
Nearly half of the reported crimes in SG were cybercrimes.6
How can you protect your organisation from these increasing risks? Use a multi-layered approach to cybersecurity to defend different sections of your network. With this extensive coverage, you safeguard your network, while empowering it to identify and repel cyber threats.
Build a cybersecurity playbook that evolves with you.
1. The human layer
Attackers can infiltrate your network by making contact through spam email, a phishing message, or a simple phone call. Criminals may also impersonate superiors and colleagues, tricking victims into disclosing private details.
2. Perimeter layer
This is your network’s outermost layer, the boundary that separates your organisation’s internal systems and connections from the internet. It focuses on controlling and keeping track of the traffic that enters and exits the internal network.
3. Network layer
This layer involves a wider scope of monitoring, aiming to safeguard your entire network infrastructure. It secures data transfers between hardware systems and networks to ensure safe and confidential communication.
4. Endpoint layer
It’s a must to supervise all individual devices connected to your network. The end point layer does this to prevent endpoints, including mobile access, from becoming entry points for cyber risks.
5. Application layer
Daily operations today involve using applications like Zoom and Google Workspace to enhance collaboration and productivity. The application layer ensures that all apps and software used by your company are secure and regularly updated.
6. Data layer
Cybercriminals are always targeting your data, which may include client details, payment processes and more. If attackers access this information, they can tamper with your systems, causing you to lose revenue, customers, and your reputation.
7. Mission-critical assets
These are the assets that power your business, such as IT infrastructure, financial systems, and communication networks. This layer is at the core of your operations and must be protected at all times, at all costs.
Top 5 cybersecurity attacks and tools you can use to block them
Businesses are well aware of cybersecurity threats, so they’ve been investing in cybersecurity products and services, a market that has tripled since 2015. This is predicted to grow further by over 13 per cent until 2027.7
Here are some of the most common security attacks and how to prevent them.
1. Phishing
Phishing happens through emails and messages that require immediate response. These trick you into clicking on harmful links, downloading malware, or divulging sensitive information. Attackers mimic valid websites and organisations like banks and your service providers.
How to avoid it:
Conduct security awareness training The human layer Train everyone in the company to spot and report phishing messages. Attackers may also impersonate managers,8 so staff members must always verify emails through a different platform.
Set up firewalls Perimeter and network security layers Superior firewalls can protect you and your device from outside threats. Strengthen your buffer with two firewalls—one for your desktop and one for your network. The dual protection significantly lowers the chance of attackers penetrating your hardware and network.9
Enable multi-factor authentication (MFA) Endpoint security layer MFA requires users to authenticate via additional verification factors, such as a PIN sent through email and a fingerprint scan on a mobile phone. After nearly 500 customers of a Singapore financial institution lost over SGD 8 million to SMS-phishing incidents in 2021,10 the Monetary Authority of Singapore and the Association of Banks in Singapore included notifying bank clients through email or mobile whenever there is a request to change such information as part of the measures to boost digital banking security.11
2. Malware attacks
Malware, such as viruses, worms, and Trojans, infiltrate your computer systems—spreading across individual devices and causing crashes and data breaches. Ransomware, wherein the attackers demand payment in exchange for access restoration, remains rampant in Singapore and worldwide, with global incidents rising by 13 per cent in 2022.12
How to avoid them:
Update software Application security layer Software updates optimise your usage and fix security lapses in previous versions, enhancing safety features. This bolsters your buffer against ransomware since attackers typically use older software versions.13
Use a protective domain name server (pDNS) Network security layer This DNS service gives you an extra layer of security by blocking access to malicious sites. Because it’s rolled out at the network level, you can better manage and implement security measures across the company. Singapore’s Counter-Ransomware Task Force mentions pDNS as a practical step to prevent ransomware attackers.14
Back up data Data security layer Set regular backups of all your data on the cloud or an external storage device. Doing this doesn’t strictly thwart ransomware perpetrators, but it does let you retrieve files without paying the ransom. A complete Disaster Recovery Plan helps your business move forward from an attack.
3. Distributed Denial of Service (DDoS) attacks
A DDoS attack uses botnets—networks of malware-infected computers that flood a target system or website to overwhelm it with requests or data packets. This uptick in traffic saturates the victim’s server, causing it to crash and making it accessible to users. A soon-to-be-released survey reveals Singapore’s DDoS protection averages only 56 per cent.15
How to avoid them:
Get DDoS protection Perimeter, network, application security layers Cybersecurity companies offer high-quality DDos protection services that identify and eliminate malicious traffic. This helps ensure that only authenticated users can access your servers.
Ensure a flexible network infrastructure Network security layer Spread your services and load across numerous servers and data centres. A scalable network infrastructure lets your server handle traffic surges.
Employ a content delivery network (CDN) Network security layer Improve the speed and performance of your website with CDNs, which consist of strategically-placed servers in different parts of the world. These ensure balanced loads of user requests while delivering content from the nearest edge server, allowing for faster content loading.
4. Man-in-the-Middle (MitM) attacks
In this attack type, an outsider intercepts communication between two parties who think they are solely interacting with each other. With the attacker positioned between the sender and receiver, they can access or modify sensitive information or insert malicious code into the data stream.
How to avoid them:
Use a virtual private network (VPN) Perimeter, network, application security layers Public Wi-Fi networks often don’t have strong encryption measures, making them susceptible to cyber threats. By using encrypted connections like VPNs, you can protect your private information and transactions.
Be vigilant while surfing Endpoint security layer Like VPNs, HTTPS (Hypertext Transfer Protocol Secure) websites use encryption techniques, preventing attackers from eavesdropping on your conversations. Instead of clicking on links, enter the web address manually. A secure and legitimate web address should begin with “https://”.
Use MFA Endpoint security layer Protect yourself from MItM attacks by preventing criminals from impersonating you and your subordinates. Require multi-factor authentication and strong passwords for all employees to make it challenging for attackers to infiltrate your IT system.
5. Insider threats
Threats can also come from within your organisation via present or past employees. As they have legitimate access to your networks and information, they can use these assets for sabotage, fraud, and other malicious intentions. According to the Ministry of Health, insider threats, particularly equipment theft, remain a common cyber threat in the health industry, especially if the devices contain sensitive information.16
How to avoid them:
Conduct regular risk assessments Mission-critical assets layer Run an inventory of your most crucial assets, weaknesses, and potential risks from within and outside your organisation. Design a network security infrastructure that addresses the vulnerabilities on the list.
Enforce systematic documentation and controls The human layer Create and enforce guidelines for implementation and record-keeping for each security measure. Partner with your HR, to craft thoughtful yet effective policies on incident reporting and response, data protection, user monitoring, and many others.
Keep track of all access types The human layer While monitoring access inside your physical workspace, you should also detect and block unauthorised intrusion from outside devices such as mobile phones. Discontinue remote access for an employee when they leave the company.
Detect, analyse, and contain threats
Your IR team is the first to be alerted and mobilised when a breach is detected. Should a breach affect access to default communication channels such as your email8, have alternative streams of communication ready to enable quick correspondence. Once alerted, technical experts examine breach details and damage severity to determine which workflow to execute.
Time is of the essence during an incident. Singtel bolsters your team’s defenses with decisive and effective managed detection and response services to avoid further data compromise and eradicate the threat at hand.
Communicate with employees, customers, and stakeholders
Cyberbreaches can drastically tarnish an enterprise’s reputation to current customers and the general public. Customers may lose trust in your company when they believe their personal information has been mishandled, and the perceived riskiness may make others deem it unsafe to give numbers and home addresses to you.
Mitigate such adverse effects with a clear, concise communication strategy—first to alert employees, then to inform customers and stakeholders. Produce also a statement for responding to media inquiries. Detail information taken, if any, and steps taken to contain threats. Your communications manager and legal counsel work together at this point to ensure statements fall within legal policies on cyberattacks and do not disrupt investigations.
Regroup and recover
A business continuity plan is part of your cybersecurity playbook that enables your organisation to keep running after a data breach. Hold a post-mortem meeting to identify the breach impact, what weaknesses it has revealed, and action points for recovery.
Since human error still accounts for an overwhelming majority of breaches, enterprises must not overlook the value of cybersecurity education. Singtel helps enterprises address this need with an extensive cybersecurity training program that hones employees’ cyber skills.
A strong cybersecurity playbook involves both experts and regular employees working together to form a solid defence system that evolves with you and stays on par with advancing technology.
Contact us to learn more about Singtel’s cybersecurity services.
References:
BCW Global, Digital Transformation in Asia-Pacific Communications, 2023
Blackberry, 2022 Threat Report, 2022
TechCrunch, Fujifilm becomes the latest victim of a network-crippling ransomware attack, 2021
International Trade Administration, Singapore Cybersecurity Market, 2023
International Trade Administration, Singapore Cybersecurity Market, 2023
Singtel, Nearly 40% of cyberattacks in Singapore target SMBs, 2022
International Trade Administration, Singapore Cybersecurity Market, 2023
CSO Online, 9 tips to prevent phishing, 2022
BDO Singapore, Protecting from Phishing Scams in Singapore, 2022
The Straits Times, Young couple lost $120k in fake text message scam targeting OCBC Bank customers, 2022
Ken Chia, Andy Leck, Lim Ren Jun, Stephanie Magnus, Daryl Seetoh, and Alex Toh, Singapore: Authorities introduce measures to combat SMS-phishing scams, 2022
Cyber Security Agency of Singapore, Phishing and Ransomware Continue to Pose Significant Risks to Organisations and Individuals Drop Seen in Number of Infected Infrastructure, 2023
U.S. Chamber of Commerce, 11 Things You Can Do Right Now to Protect Your Business from a Ransomware Attack, 2023
Cyber Security Agency of Singapore, Counter Ransomware Task Force Report, 2022
Internet Society Pulse, How Hygienic is Your Website and Email Service?, 2023
Ministry of Health, Common Cyber Threats in the Healthcare Sector, 2023
Featured solutions
Related products
Broadband Security — A cloud-based solution for office network protection. Anti-virus and web content filtering to guard against advanced threats and malicious websites. Easily customisable security settings to control website user access through URL filtering./business/products-services/cybersecurity/network-security/broadband-security
Network-level caller verification: Defending against voice phishing — The phone remains one of the most trusted channels enterprises use to reach their customers, which is exactly why generative AI voice is being weaponised against it. Effective defence depends on verifying caller identity at the network layer, before the call ever reaches a handset. As deepfake fraud scales across Southeast Asia, the maturity of carrier-level verification and risk-signal capabilities will shape how well the voice channel can be defended./business/insights/network-level-caller-verification-defending-against-voice-phishing
Singtel named Frost & Sullivan’s 2026 Singapore Cybersecurity Services Company of the Year — Singtel has been recognised for its leadership in cyber security services in Singapore. The award highlights Singtel’s integrated approach to cyber security, combining connectivity, network intelligence and managed security capabilities to help enterprises strengthen resilience across cloud, users, applications and digital infrastructure. Read the full story to discover how Singtel is helping enterprises secure their digital operations with end-to-end cyber security services./business/insights/singtel-named-frost-and-sullivans-2026-singapore-cybersecurity-services-company-of-the-year
Autonomous defence in BFSI: why the network matters — Banking is moving toward more autonomous cyber defence as agentic AI takes on a growing role in assessing risk and guiding responses. Its impact depends on the ability to enforce decisions consistently across complex, hybrid environments, making the network a critical execution layer. As adoption expands, the maturity of data, cloud, and connectivity foundations will shape how effectively these capabilities operate at scale./business/insights/autonomous-defence-in-bfsi-why-the-network-matters
Network guardrails for the agentic era — As AI moves from answering questions to orchestrating workflows, enterprises must ensure appropriate governance. One emerging consideration is agentic drift, where autonomous agents act beyond their intended scope. Explore how Singtel’s Unified SASE Convergence platform applies Zero Trust principles at the network layer, treating AI agents as non-human identities with clearly defined access controls./business/insights/network-guardrails-for-the-agentic-era
Why the future of security is written in your data’s DNA — Security is moving beyond the perimeter towards the core cryptographic layer that defines trust across every transaction, device, and data flow. As quantum computing reshapes the threat environment, the durability of this data “DNA” becomes a true measure of resilience./business/insights/why-the-future-of-security-is-written-in-your-datas-dna
IDC MarketScape: APAC Managed SD-WAN/SASE Services 2025–2026 — We’re honoured to be named a leader in the IDC MarketScape: APAC Managed SD-WAN/SASE Services 2025–2026. This report offers clarity on where the market is heading, and what a trusted managed SASE partner should deliver./business/insights/idc-marketscape-apac-managed-sd-wan-sase-services-2025-2026