
For many small businesses in Southeast Asia, cybersecurity still sits in an uncomfortable place: too important to ignore, but too costly and specialised to manage properly.
Singapore Polytechnic wants to narrow that gap with a new initiative that turns student training into practical cyber support for enterprises.
Also Read: The demand for SME cybersecurity is inevitable, the supply was never built correctly
The institution has launched the Cybersecurity Assessment and Security Operations Centre Training Lab for Enterprises, or CASTLE, through its School of Computing. The programme is designed to provide small and medium-sized enterprises (SMEs) with cybersecurity services ranging from basic cyber hygiene checks to penetration testing and security operations support, while giving students exposure to real-world threats before they enter the workforce.
With the launch, Singapore Polytechnic has also become the first Institute of Higher Learning in Singapore licensed by the Cybersecurity Services Regulation Office to provide penetration testing services. Penetration testing, often known as ethical hacking, involves simulating attacks on an organisation’s systems to uncover weaknesses before criminals do.
“Cybersecurity was once seen as a concern mainly for large organisations. Today, SMEs are just as much a target, but many simply don’t have the budget or in-house expertise to defend themselves,” said Liew Chin Chuan, Director of the School of Computing at Singapore Polytechnic. “CASTLE was built to close that gap.”
The timing is significant. According to the Singapore Cyber Landscape 2024/2025 report, reported ransomware cases in Singapore rose by 21 per cent in 2024, with manufacturing and professional services among the sectors most affected. Many incidents were linked to long-standing vulnerabilities, the sort that often persist in smaller firms because they lack dedicated security teams or the budget for frequent external audits.
That problem is not unique to Singapore. Across Southeast Asia, SMEs form the backbone of the economy, but many are digitising faster than they are securing their systems. Cloud software, digital payments, remote work and connected devices have helped businesses become more efficient, but they have also widened the attack surface. For attackers, a poorly protected SME can be an easy target in itself, or a gateway into larger customers and supply chains.
A tiered model for cyber maturity
CASTLE is structured around four pillars, each aimed at a different stage of an enterprise’s cybersecurity journey.
The first is a cybersecurity hygiene check service. Conducted by Singapore Polytechnic students and staff, the service helps SMEs identify basic gaps in their digital infrastructure. These could include weak password practices, outdated software, misconfigured systems, poor access controls or insufficient backup processes. The assessments draw on frameworks and best practices from the Cyber Security Agency of Singapore and industry partners, with the aim of giving companies practical steps they can act on quickly.
Also Read: Why cyber resilience is the new standard for SME survival
The second pillar moves into more advanced cybersecurity posture assessments. These include penetration testing, vulnerability assessments and advisory services. Singapore Polytechnic’s licence from the Cybersecurity Services Regulation Office allows it to offer regulated penetration testing services to SMEs, while giving students a learning environment that mirrors industry requirements.
This matters because cybersecurity training can often remain abstract until students encounter messy, real-world systems. CASTLE aims to change that by allowing students to work on genuine business environments under supervision. The programme is also linked to a partnership with Offensive Security, better known as OffSec, giving students a pathway towards the Offensive Security Certified Professional certification, a widely recognised credential for offensive cybersecurity practitioners.
A live security operations centre on campus
The third pillar is a Security Operations Centre as a Service model, developed with ST Engineering’s Cyber business. The new SME Cybersecurity Operations and Training Centre will be located on campus and will combine operational cyber monitoring for SMEs with training for students and educators.
A security operations centre, or SOC, is where analysts monitor systems for suspicious activity, detect threats and respond to incidents. In large companies, such centres often run round the clock. For SMEs, maintaining one internally is usually unrealistic. CASTLE’s model gives smaller businesses access to some of these capabilities while allowing students to train in a live environment.
ST Engineering said its existing facility has helped more than 1,000 SMEs over the past year take steps to improve cyber resilience. The partnership with Singapore Polytechnic is intended to extend that work while developing students who are familiar with operational cybersecurity and digital forensics before graduation.
For students, this could be one of CASTLE’s most important elements. Classroom exercises tend to be controlled and predictable. A live SOC exposes students to alerts, false positives, incident triage and the pressure of making decisions when business systems may be at risk. It also gives lecturers a closer connection to current industry practices, which can change quickly as attackers adopt new tools and techniques.
Awareness, industrial systems and the talent pipeline
The fourth pillar, CyberSAFE@SP, focuses on awareness and training. Delivered by Singapore Polytechnic students and staff, the programme is aimed at helping business owners and employees understand everyday cyber risks and safer digital practices. It also serves as an entry point for companies that may later need deeper assessments or operational support.
This community-facing model resembles the growing cybersecurity clinic movement, where universities and colleges provide supervised support to under-resourced organisations. Singapore Polytechnic is a member of the global Consortium of Cybersecurity Clinics, placing CASTLE within a broader international push to make cybersecurity assistance more accessible.
Beyond SME services, the polytechnic is also updating its curriculum. It has signed a memorandum of understanding with Athena Dynamics to build capabilities in operational technology and industrial control systems. These are the systems that run factories, utilities, transport networks and other physical infrastructure. As industries across Southeast Asia automate and connect more machines to digital networks, the line between cyber incidents and physical disruption becomes thinner.
The focus on operational technology is especially relevant in Singapore, where critical infrastructure protection has become a national priority, and in neighbouring markets where manufacturing, energy and logistics are becoming more digitally connected. Cybersecurity graduates increasingly need to understand not only laptops, servers and cloud environments, but also industrial systems that were not originally designed with internet-era threats in mind.
Also Read: What SMEs must know to secure and scale
CASTLE is expected to benefit more than 180 students annually through projects, internships, industry collaborations and operational training. Up to 50 SMEs are expected to use its cybersecurity services and awareness programmes by mid-2027.
Those numbers are modest against the scale of the cyber talent shortage, but the model could be important. Singapore, like many countries, faces persistent demand for cybersecurity professionals who can do more than pass exams. Employers want people who can investigate alerts, communicate risks to non-technical managers and operate in high-pressure environments. CASTLE gives students a way to build those muscles earlier.
For SMEs, the value is more immediate. A small firm may not need the same level of security infrastructure as a bank, but it still needs to know where it is exposed and how to reduce the odds of a damaging attack. CASTLE’s promise is not that it will solve every cybersecurity problem. Rather, it offers a more accessible starting point: supervised expertise, practical recommendations and a bridge between Singapore’s education system and the security needs of its business community.
If it works, the initiative could become a useful template for the region. Southeast Asia’s digital economy will not be secured only by large vendors and government rules. It will also depend on whether ordinary businesses can get help before an attack forces them to act.
The post Singapore Polytechnic launches CASTLE to help SMEs strengthen cyber defences appeared first on e27.
