Why Is Cyber Security Hard for a Small Clinic?

Not because nobody takes it seriously any more. At a HealthTechX Asia 2026 panel moderated by StrongKeep CEO Gaurav Keerthi, hospital technology leaders told Hospital Management Asia that the constraint has moved. Boards now ask whether enough has been done. What is short is people to do it.

Gaurav Keerthi moderating the HealthTechX Asia 2026 panel Designing Cyber-Resilient Healthcare, with panellists Bruce Leong of Mount Alvernia Hospital and Aslyn Koh of Thomson Medical
Read on Hospital Management Asia: "Designing cyber-resilient healthcare"

Is the Barrier Awareness or Staffing?

Staffing, on the panel's account. Bruce Leong, Director of Technology and Strategy at Mount Alvernia Hospital, told the session that management now asks IT whether enough has been done on cyber protection, rather than needing to be convinced to invest at all. The harder problem is finding and keeping the people.

"The challenge is no longer perception," he said, as reported by Hospital Management Asia. "The challenge is resources and manpower."

Aslyn Koh, Chief Information Officer at Thomson Medical, described building the other half: governance, staff awareness programmes and phishing simulations, with training kept short enough to fit a clinician's day. The panel also discussed Singapore's Health Information Act, which Leong described as a useful framework for prioritising effort rather than a compliance burden.

What Does a Hospital's Risk Have to Do With a Small Clinic?

The report puts them in the same picture. It describes hospitals as depending on an ecosystem of vendors, device suppliers, specialist clinics and independent clinicians, and notes that many healthcare breaches now begin with a third party. Hospitals are responding with vendor assessments, access reviews and policies for clinicians who need occasional access to clinical systems.

Our own observation, not the panel's: if a hospital with a CISO finds staffing the binding constraint, a six-person clinic in that same ecosystem has nobody in the role at all. That is the gap StrongKeep was built for, and it is why we work with healthcare clinics specifically.

Read the Full Report on Hospital Management Asia

Cindy Peh's report covers more than we have here, including how one hospital spent years removing uncontrolled vendor access to connected medical devices, and why the panel argued cyber resilience cannot sit with the technology team alone.

Read it on Hospital Management Asia: Designing cyber-resilient healthcare, regulation as a catalyst for sector-wide change

Related Reading

Frequently Asked Questions

Who was on the HealthTechX Asia 2026 panel on cyber-resilient healthcare?

It was moderated by Gaurav Keerthi, CEO of StrongKeep and former Deputy Commissioner of Cybersecurity for Singapore. The panellists were Bruce Leong, Director of Technology and Strategy at Mount Alvernia Hospital, and Aslyn Koh, Chief Information Officer at Thomson Medical. Hospital Management Asia reported the session on 6 July 2026.

Is the main barrier to healthcare cyber security awareness or staffing?

Staffing, according to the hospital leaders on this panel. They described a shift in which boards and management now ask whether enough has been done, rather than needing persuading to spend. The reported difficulty is an ongoing shortage of cyber security talent, and the pressure of keeping up with a threat landscape that changes faster than a team can be hired.

How does a hospital's cyber risk reach the clinics and suppliers around it?

Through access. The report describes hospitals as dependent on vendors, medical device suppliers, specialist clinics and independent clinicians, with many healthcare breaches now beginning at a third party. Hospitals are responding by assessing suppliers, reviewing who can reach which systems, and writing policies for clinicians who need only occasional access. For a smaller practice, that means a hospital partner is increasingly likely to ask what protection is in place.

What Does StrongKeep Do?

StrongKeep is a self-serve cybersecurity platform for small and medium businesses. It bundles endpoint protection, phishing and malicious-link filtering, credential management, staff awareness training and phishing simulations, all run by the business itself from one dashboard. Compliance tooling is available on higher plans. StrongKeep holds the CSA Cyber Essentials Mark. Built for teams without an IT department. Plans are on the pricing page.

StrongKeep on LinkedIn Follow StrongKeep for cybersecurity insights and updates
→

Cyber security your clinic can actually run. Start today.

Get Started from US$39 (S$49)/month

Covers up to 5 devices. No IT team required. Cancel anytime.