Why Don't Smaller Businesses Have Cybersecurity?

Nobody built it for them. StrongKeep CEO Gaurav Keerthi argues in e27 that demand was never the problem. Cyber risk already reaches firms of every size, and regulators, insurers and enterprise customers are all asking harder questions. What has been missing is a supply side. The industry built for large organisations with security teams, and stopped there.

A cutaway of a Victorian brick sewer tunnel running beneath a row of modern small shopfronts, becoming a modern pipe as it goes, illustrating shared infrastructure rather than fixing each building one at a time
Read on e27: "The demand for SMB cybersecurity is inevitable, the supply was never built correctly"

Why Doesn't Fixing Cybersecurity One Tool at a Time Work?

Because the gap is structural, not a list of separate faults. Gaurav makes that case with 1858 London, where the Thames stank of sewage and the response to the cholera outbreak was to fix contaminated water pumps one at a time. What ended the outbreak was building an urban sewer system. He argues cybersecurity is stuck at the same stage.

He puts it in one sentence. "Today, we are still dealing with cybersecurity as a point source problem, when the solution requires an infrastructure change."

Why Did the Security Industry Design for Specialists?

Contract size. "The industry's priorities were set by contract size, and small businesses never made the shortlist," Gaurav writes. A CISO with a multi-million dollar budget is a more attractive customer than a clinic with no IT staff, so the industry designed for complexity and sold that complexity as sophistication.

He spent two decades on the other side of that line, at the Republic of Singapore Air Force and then at CSA, where the answer to a hard problem was to hire more specialists and buy more advanced tools.

"The cyber industry is full of high-skilled professionals, but there is no IKEA for the masses."

Gaurav Keerthi, CEO of StrongKeep, writing in e27

Read the Full Article on e27

The article was published on e27 under Gaurav's byline, through e27's contributor programme. The views in it are his own, and e27 carries its standard note to that effect. Not summarised above: what he argues AI has done to the cost of building security a non-specialist can operate, and what he thinks security designed for a small business should actually look like.

Read it on e27: The demand for SMB cybersecurity is inevitable, the supply was never built correctly

Related Reading

Frequently Asked Questions

What is the argument in Gaurav Keerthi's e27 article?

That demand for small-business cybersecurity is already settled and the failure is on the supply side. The security industry set its priorities by contract size, designed for organisations with security teams, and never redesigned for anyone else. His argument is that AI has now lowered the cost of building security a non-specialist can operate, which removes the reason the industry gave for not building it.

What does "cyber inequity" mean?

It is the World Economic Forum's term for the widening gap in cyber capability between larger and smaller organisations. In its Global Cybersecurity Outlook 2026 the WEF reports that small organisations by revenue are twice as likely as large ones to experience insufficient resilience levels, and that 46% of small organisations report a lack of cybersecurity skills and expertise against 29% of large organisations.

Why are smaller professional services firms in Singapore so exposed to ransomware?

Because of the data they hold. CSA's Singapore Cyber Landscape 2024/2025 records 159 ransomware cases in 2024, up 21 per cent on 2023, and professional services accounted for 28 of them, with the majority of those attacks targeting SMEs. The report points to the vulnerability of smaller professional service providers, particularly consulting and legal firms, which manage vast amounts of sensitive client data. It was the first time professional services ranked in the top three affected industries since CSA began tracking.

Does a cheaper version of enterprise security solve the problem?

The article says no, and the reason is staffing rather than price. A stripped-down enterprise tool still has to be configured, tuned and watched by someone who knows what they are looking at. Most small businesses have nobody in that role, so a lower price does not make the product usable. The fix has to change what the product asks of the owner, not just what it costs.

What Does StrongKeep Do?

StrongKeep is a self-serve cybersecurity platform for small and medium businesses. It bundles endpoint protection, phishing and malicious-link filtering, credential management, staff awareness training and phishing simulations, all run by the business itself from one dashboard. Compliance tooling is available on higher plans. StrongKeep holds the CSA Cyber Essentials Mark. Built for teams without an IT department. Plans are on the pricing page.

StrongKeep on LinkedIn Follow StrongKeep for cybersecurity insights and updates
→

Cybersecurity your business can actually run. Start today.

Get Started from US$39 (S$49)/month

Covers up to 5 devices. No IT team required. Cancel anytime.