The failures in Singapore are mostly unglamorous
Infected systems in Singapore rose 67% in a year to roughly 117,300, and CSA attributes the rise to outdated and unpatched software. Not zero-day exploits. Not state actors. Patches that were never applied, and nobody whose job it was to check.
Ransomware cases rose again in 2025, and CSA states plainly that SMEs are disproportionately affected because of lower cybersecurity maturity and limited resources. Reported phishing attempts have surged past 6,100 cases, with AI-generated content in a meaningful share of them.
Threat actors have also started impersonating IT support staff on the phone. If your team has no documented escalation path with named contacts, they cannot tell a real IT call from a fake one.
Source: Cyber Security Agency of Singapore, Singapore Cyber Landscape 2025/2026.



