Singapore’s small and medium-sized businesses have a new option for cybersecurity support. And it doubles as a real-world training ground for the country’s next generation of defenders.
Singapore Polytechnic (SP) has launched the Cybersecurity Assessment and Security Operations Centre Training Lab for Enterprises (CASTLE). The initiative delivers live cybersecurity services to SMBs while giving students hands-on experience with active business networks and is expected to benefit 400 students and 10 staff through full-time and part-time diplomas.
Crucially, SP is the first Institute of Higher Learning in Singapore licensed by the Cybersecurity Services Regulation Office (CSRO) to provide penetration testing. That license elevates CASTLE beyond standard classroom environments. Instead of hacking synthetic networks with intentionally planted flaws, students work alongside staff on live security operations, threat assessments, and awareness campaigns for real companies.
The timing addresses a growing gap. The Cyber Security Agency of Singapore’s (CSA) latest Singapore Cyber Landscape 2025/2026 report noted 165 reported ransomware cases in 2025 (up from 159 in 2024), with SMBs bearing the brunt due to limited budgets and lower security maturity. CSA also detected 284,300 infected infrastructure systems nationwide in 2025, a 142% surge from 2024 driven by Malware-as-a-Service and unpatched IoT devices.
A four-pillar framework
A ST Engineering SOC in action.
Photo: ST Engineering
Rather than offering a one-size-fits-all assessment, SP structured CASTLE around four distinct entry points matching an SMB’s operational maturity:
- Pillar A: Cybersecurity Hygiene Check as a Service. The baseline tier. Students and staff evaluate an SMB’s digital infrastructure for immediate vulnerabilities based on CSA and industry frameworks, delivering actionable patch and hygiene recommendations.
- Pillar B: Cybersecurity Posture Assessment as a Service. CASTLE provides regulated penetration testing and vulnerability assessments. Through a partnership with OffSec, SP aligns student tasks with the Offensive Security Certified Professional (OSCP) track, letting students test live corporate networks rather than theoretical setups.
- Pillar C: On-Campus Security Operations Centre. SP partnered with ST Engineering’s Cyber business to build a live, on-campus SOC—a first for a local polytechnic. Students monitor active threat scenarios, handle incident responses, and take on SOC internships supervised by industry veterans.
- Pillar D: Cyber Awareness Outreach (CyberSAFE@SP). Run by students and staff, this tier focuses on staff training and basic cyber hygiene for business owners, acting as an entry point for companies that later require advanced technical testing.
This setup complements existing national initiatives like the Cyber Resilience Centre and the CISO-as-a-Service programme (which offers up to 70% co-funding for SMB advisory services) by adding an educational pipeline to the ecosystem.
Real networks, messy realities
Students at a lecture.
Photo: Pexels
Read Full Article At Source

