Think You're Safe from Cyber Crooks? Here's Why 99% of Companies Are Exposed

StrongKeep CEO Gaurav Keerthi joined Deputy Opinion Editor Bhavan Jaipragas on The Straits Times podcast to discuss why 99% of companies remain vulnerable to cyber threats and why improving cybersecurity does not have to be expensive or technically complex.

The Straits Times 'In Your Opinion' Podcast: Season 1, Episode 76 featuring Gaurav Keerthi
Listen: The Straits Times "In Your Opinion" Podcast, Season 1 Episode 76

The Shift: From IT Problem to Boardroom Issue

Cybersecurity has moved from an IT back-office function to a boardroom governance priority in Singapore. Regulatory bodies, corporate boards, and insurers now treat cyber risk on par with financial and legal risk. Companies that still manage it as a purely technical IT matter are structurally behind, and the 99% exposure rate is the result.

High-profile breaches have accelerated this shift. The businesses best positioned are not necessarily the largest; they are the ones that have built consistent, practical defences. The challenge is that most solutions on the market were built for enterprise budgets and enterprise IT teams, not for a 15-person clinic or a boutique professional services firm.

Why SMEs Are the Most Exposed

99% of companies in Singapore have no one on their team with a cybersecurity title or technical background. Without that expertise, most SMEs have no way of knowing whether they have already been compromised. Gaurav notes that well over half of StrongKeep customers arrive with a dormant virus already running on a device, silently logging keystrokes or stealing data, with no visible disruption to daily operations.

  • No in-house expertise: 99% of Singapore companies have no staff member with a cybersecurity title or technical background
  • Perceived cost barrier: Most SMEs believe proper cybersecurity requires an enterprise budget and dedicated IT staff. It does not.
  • False sense of security: Many SMEs assume they are too small to be a target. Most arrive at StrongKeep already compromised.

SMEs as Supply Chain Entry Points

SMEs are targeted not only for their own data but as entry points into the larger organisations they supply or serve. Gaurav's example: breaking into a large bank directly is hard. Breaking into a law firm, accounting firm, or HR software provider that the bank relies on is far easier, and gives an attacker the same access. Boards are beginning to ask which of their vendors could be used as a route in.

Cybersecurity Risk: AI in the Hands of Attackers

AI has not introduced new categories of cyber threat. It has made existing threats faster, cheaper, and more convincing. Gaurav describes it as a productivity tool for attackers: they are building better viruses and more convincing phishing at greater scale and lower cost. When the mouse gets superpowers, the cats need to worry.

The clearest example is phishing. A decade ago, the standard advice was to look for typos and grammatical errors in suspicious emails. Today, Gaurav notes, a typo is a sign the email came from a human. AI writes perfect, personalised phishing at scale. Deepfake images and videos have made it harder still to verify what is real. CSA's advisory to boards was specifically about this shift: not that AI is a new threat, but that it has given attackers a significant speed and scale advantage.

"Building cyber resilience is not difficult nor does it have to be expensive or overly complex."

Gaurav Keerthi, CEO of StrongKeep, on LinkedIn

What Practical Resilience Looks Like

Gaurav frames the SME cybersecurity problem around four things that can go wrong: downloading something malicious, clicking on a fraudulent link, having credentials stolen, and running unpatched or insecure systems. AI exploits all four more effectively, but addressing these four remains the foundation of a defensible business. Solving all four, Gaurav argues, costs less than a nice lunch for an SME that knows where to start.

  • Protection against malicious downloads across all business devices
  • Staff training to identify phishing links and fraudulent websites
  • Strong, unique credentials across all systems and accounts
  • Keeping all software and systems patched and up to date

StrongKeep bundles all of this into a single, affordable platform built specifically for Singapore SMEs, starting from US$39 (S$49) per month, billed annually, for device protection across up to 5 devices.

Read and Listen to the Full Story

The full podcast episode is available on The Straits Times website and Spotify. The episode is part of Season 1 of "In Your Opinion", the ST opinion desk's podcast series exploring Singapore's most consequential issues.

Read and listen: Think you're safe from cyber crooks? Why 99% of companies are exposed: The Straits Times

Gaurav Keerthi on LinkedIn See the original post and discussion, with 141 reactions
→
StrongKeep on LinkedIn Follow StrongKeep for cybersecurity insights and updates
→

Don't be part of the 99%. Protect your business today.

Get Started from US$39 (S$49)/month

Covers up to 5 devices. No IT team required. Cancel anytime.