Singapore Polytechnic: Cybersecurity for SMEs

Singapore Polytechnic: Cybersecurity for SMEs


Singapore’s small and medium-sized businesses have a new option for cybersecurity support. And it doubles as a real-world training ground for the country’s next generation of defenders.

Singapore Polytechnic (SP) has launched the Cybersecurity Assessment and Security Operations Centre Training Lab for Enterprises (CASTLE). The initiative delivers live cybersecurity services to SMBs while giving students hands-on experience with active business networks and is expected to benefit 400 students and 10 staff through full-time and part-time diplomas.

Crucially, SP is the first Institute of Higher Learning in Singapore licensed by the Cybersecurity Services Regulation Office (CSRO) to provide penetration testing. That license elevates CASTLE beyond standard classroom environments. Instead of hacking synthetic networks with intentionally planted flaws, students work alongside staff on live security operations, threat assessments, and awareness campaigns for real companies.

The timing addresses a growing gap. The Cyber Security Agency of Singapore’s (CSA) latest Singapore Cyber Landscape 2025/2026 report noted 165 reported ransomware cases in 2025 (up from 159 in 2024), with SMBs bearing the brunt due to limited budgets and lower security maturity. CSA also detected 284,300 infected infrastructure systems nationwide in 2025, a 142% surge from 2024 driven by Malware-as-a-Service and unpatched IoT devices.

A four-pillar framework

An Aether SOC in action.

A ST Engineering SOC in action.

Photo: ST Engineering

Rather than offering a one-size-fits-all assessment, SP structured CASTLE around four distinct entry points matching an SMB’s operational maturity:

  • Pillar A: Cybersecurity Hygiene Check as a Service. The baseline tier. Students and staff evaluate an SMB’s digital infrastructure for immediate vulnerabilities based on CSA and industry frameworks, delivering actionable patch and hygiene recommendations.
  • Pillar B: Cybersecurity Posture Assessment as a Service. CASTLE provides regulated penetration testing and vulnerability assessments. Through a partnership with OffSec, SP aligns student tasks with the Offensive Security Certified Professional (OSCP) track, letting students test live corporate networks rather than theoretical setups.
  • Pillar C: On-Campus Security Operations Centre. SP partnered with ST Engineering’s Cyber business to build a live, on-campus SOC—a first for a local polytechnic. Students monitor active threat scenarios, handle incident responses, and take on SOC internships supervised by industry veterans.
  • Pillar D: Cyber Awareness Outreach (CyberSAFE@SP). Run by students and staff, this tier focuses on staff training and basic cyber hygiene for business owners, acting as an entry point for companies that later require advanced technical testing.

This setup complements existing national initiatives like the Cyber Resilience Centre and the CISO-as-a-Service programme (which offers up to 70% co-funding for SMB advisory services) by adding an educational pipeline to the ecosystem.

Real networks, messy realities

A lecture

Students at a lecture.

Photo: Pexels

CASTLE aims to support over 180 students annually through projects, internships, and live operations, while targeting up to 50 SMBs for services by mid-2027.

For students, the value lies in exposure to actual operational friction. “Cybersecurity was once seen as a concern mainly for large organisations. Today, SMBs are just as much a target, but many simply don’t have the budget or in-house expertise to defend themselves,” said Liew Chin Chuan, Director of SP’s School of Computing.

Evidence supports that concern.

CSA says SMBs remained disproportionately affected by ransomware in 2025 because they typically have fewer cybersecurity resources and lower security maturity than larger organisations.

At the same time, Singapore needs people capable of dealing with a threat environment that is becoming more complicated.

CSA says artificial intelligence is allowing threat actors to attack with greater speed, scale, and sophistication. Agentic AI could potentially automate significant parts of an attack and reduce the expertise required to carry it out.

Unlike lab simulations, live business networks feature legacy software, unusual configurations, zero-downtime constraints, and varying levels of employee awareness. Early exposure to these constraints prepares students for an increasingly complex threat environment, particularly as AI tools lower the bar for automated cyberattacks. Industry partners including ST Engineering, OffSec, and Athena Dynamics are providing curriculum support, faculty attachments, and access to emerging security tech.

What makes CASTLE potentially useful is that the two sides of the programme solve related problems.

SMBs need cybersecurity expertise but may struggle to maintain large internal security teams. Students need practical experience, but realistic cybersecurity work is difficult to reproduce entirely inside a classroom.

CASTLE attempts to put the two together.

Industry partners, including ST Engineering, OffSec, and Athena Dynamics, will provide expertise, curriculum support, faculty attachments, internships, and access to emerging cybersecurity technologies.

For an SMB, the result could range from discovering basic cyber hygiene problems to undergoing a penetration test or gaining access to security operations expertise. According to SP, SMBs can benefit by gaining a better understanding of possible weaknesses in their digital security and how CASTLE can help bolster their defences. Under one of the pillars, SP students and staff will conduct basic cyber hygiene training for SMBs to inculcate good digital habits. CASTLE is also designed to be flexible, and SMBs can choose the services that best meet their needs and the duration of support they require. As the only institute of higher learning in Singapore licensed to carry out penetration testing services, CASTLE subjects SMBs’ digital systems to rigorous testing to uncover vulnerabilities, providing valuable insights for SMBs and systemic learning opportunities for SP’s students and staff

For students, the payoff is getting closer to what cybersecurity work actually looks like before graduation.

CASTLE does not solve that imbalance on its own. But putting SMBs, students, lecturers and cybersecurity companies into the same working environment gives Singapore Polytechnic an interesting way to tackle two shortages at once: affordable cybersecurity expertise for smaller businesses and experienced cybersecurity talent for the workforce.

Expanding into Operational Technology

The Minister at the MOU ceremony.

Acting Minister for Manpower and Senior Minister of State, Ministry of Digital Development and Information, Ms Jasmin Lau at the MoU Recognition Ceremony on 19 August.

Photo: MDDI

Alongside CASTLE, SP signed a Memorandum of Understanding with Athena Dynamics to expand its curriculum into Operational Technology (OT) and Industrial Control Systems (ICS), the infrastructure powering manufacturing and physical plant operations.

Athena Dynamics CEO Ken Soh noted that as IT, OT, IoT, and AI systems converge, cybersecurity education must cover physical-cyber security alongside traditional IT defence. The partnership expands on SP’s Diploma in Cybersecurity & Digital Forensics, which already prepares students for industry certifications such as CEH, PCNSA, and CCSA.




Read Full Article At Source

Share. Save. Don't Miss The Buzz: XFacebookRedditLINETelegramWhatsAppGmail

Leave a Reply