With a S$113 billion contribution to the GDP in 2023, Singapore’s digital economy is thriving. Small and medium businesses (SMBs) are central to this growth, having tripled their AI adoption since 2018. The catch? Cybercriminals are finding more inroads into SMB networks, capitalizing on the fact that these companies often lack the resources of larger enterprises.
These attacks are widespread: Arctic Wolf’s 2025 Trends Report found 70% of Singapore businesses surveyed suffered a breach in the past year, while the Cyber Security Agency of Singapore (CSA) said three in five ransomware attacks hit SMEs.
This growing exposure highlights a bigger challenge: too many SMBs still operate under false assumptions about cybersecurity, which restrict their strategies. These misconceptions don’t just limit defenses, they actively open doors for attackers, making it critical for SMB leaders to confront and correct to build resilience. Let’s dispel three of the most common myths today:
Myth 1: “We’re too small to be targeted.”
It is common for SMBs to think that with larger companies around, cyber attackers are unlikely to go after them. This feeds into declining awareness rates among these businesses, with less than half (47%) of Singaporean SME leaders being fully aware of cyber risks.
What’s more, it also creates an overestimation of capabilities as SMBs may not have the complete picture on if their cybersecurity postures are up to the task. This points to a significant disconnect between perceived and actual security.
Reality: Cybercriminals rarely discriminate; they go wherever defense is the weakest. This makes SMBs low-hanging fruit as they often present multiple paths to a quick payday. According to Arctic Wolf’s 2025 Trends Report, ransomware, business email compromise, and intrusions comprise the majority of incident response cases, all of which can cripple SMBs with limited funding and resources.
One breach could potentially disrupt supply chains, drain finances, and shatter customer confidence, creating long-term consequences for victims.
Myth 2: “Ransomware just locks files.”
Ransomware attacks typically meant a tried and tested methodology: encryption to lock files and demanding payment to decrypt. But today, improvements in backup and restoration capabilities have made double extortion the norm.
In 96% of ransomware cases investigated by us at Arctic Wolf, attackers, on top of encrypting data, also exfiltrated it to apply pressure and extort payment. These multi-level schemes, where victims are threatened with reputational threats or legal consequences after their data is stolen, are growing.
Reality: A majority of Singapore SMBs (88%) would pay the ransom if attacked, and 100% of surveyed enterprises targeted by ransomware in Singapore last year paid up. However, paying no longer guarantees that you will regain access to your data. Add this ransom amount to the cost of incident response, disrupted operations, downtime, and post-breach network management, and SMBs have a significant threat to business viability on their hands. What adds to this is how cyber attackers can branch out to coerce victims further. With AI and ransomware-as-a-service (RaaS) lowering the technical barrier, cyberattackers are even resorting to higher forms of extortion, which include triple and quadruple extortion, deepfakes, sextortion, killware, and more.
Myth 3: “Cybersecurity is only for large corporations.”
Historically speaking, cyber attacks on large MNCs, government agencies, and critical infrastructures have been highly publicized. Additionally, SMBs often believe enterprise-grade security solutions are prohibitively expensive or too complex for companies at their scale and for those that have them, they believe the tool alone is sufficient. This perception is reinforced by lean IT teams, where cybersecurity feels like a luxury rather than a necessity, which leads SMBs to think that their smaller data sets or customer bases make them unattractive to attackers.
In some cases, SMBs also underestimate their obligations under Singapore’s PDPA and sector-specific rules (e.g., MAS TRM guidelines for financial services SMEs), assuming compliance is only critical for large organisations.
Reality: As shared earlier, a majority of cyberattacks in Singapore target SMBs. They are not only easier to breach, they are also, often a part of the supply chain of larger companies. This provides attackers a stepping stone to breach large networks, while bleeding the small businesses.
As human error risks climb, this risk increases significantly for businesses with lean security teams, as vulnerable employees are the first line of defence. This makes watertight cybersecurity postures critical, even for SMBs, as they could potentially put not only employees, but also other businesses in their network at risk.
For SMBs in Singapore, cybersecurity can’t be an afterthought. Threat actors are moving fast, using AI, RaaS, and layered extortion to increase the frequency, scale, and impact of attacks. The idea that cyber risk only applies to big corporations no longer holds.
The good news: resilience is in reach. By challenging common myths, investing in the right defences, and leaning on trusted partners, SMBs can shift from easy targets to resilient players. This way they won’t simply stop attacks, but also do their part in protecting trust and keeping Singapore’s digital economy on track.












