Insights · 10 September 2026

Adding AI tools is a
security decision.

SMEs came to our booth with tools chosen and pilots running. One question came up far less often: what does connecting this open up?

We spent 9 September at the SME Centre Conference at Singapore EXPO, on the theme "Vision to Action: AI Adoption for SMEs". The appetite in the room was not in doubt. Owners and operations managers came to the booth with tools already chosen, pilots already running, and a clear sense of what they wanted AI to take off their plate.

One question came up far less often: what does connecting this open up?

That is not an argument against adopting AI. It is an observation that adoption is being treated as a productivity decision when it is also a security one, and the second half is being made by default rather than on purpose.

Greenwich consultants with the Cyber Security Agency of Singapore team at the SME Centre Conference 2026, Singapore EXPO.
SME Centre Conference 2026 Singapore EXPO · 9 September
43%
Of regional cyberattacks target SMEs
40%
Of IT decision-makers did not know if they had been breached
63%
Of surveyed enterprises want a managed provider
1
Question worth asking your leadership this week

The misconception that survives every conference

"We're too small. Why would anyone bother with us?" We heard it again at the booth, and it is the belief that does the most damage, because it is not lazy. It is a reasonable inference from how attacks get reported. The breaches that make the news are large, so smallness reads as cover.

The regional data says the opposite. SPEEDA's Southeast Asia cybersecurity report finds that around 43% of cyberattacks in the region target SMEs, and it is explicit about why: smaller organisations often lack the financial and technical resources to build robust defences. Being small is not what makes you uninteresting. In a supply chain it is frequently what makes you the way in, because the organisation an attacker actually wants has better defences than its suppliers do.

The same report carries a second figure that is harder to sit with. 40% of IT decision-makers did not know whether their systems had already been breached. Not "had not been breached". Did not know.

Those two findings sit together uncomfortably. If two in five organisations cannot answer the question at all, then "we have never had an incident" is, for a large share of them, a statement about visibility rather than about security.

If we were breached this morning,
how would we know?

Put it to your leadership team this week. If nobody has a confident answer, the starting point is not a new software product. It is deciding who owns the question.

What actually changes when you connect an AI tool

The risk is rarely the model. It is the plumbing around it, and it is worth being concrete rather than ominous. Connecting a new AI tool usually means some combination of:

  • A new third party holding your data, often outside Singapore, under terms nobody in the business has read past the pricing page.
  • A new set of credentials, frequently created by whoever ran the pilot, sometimes shared, rarely in the account inventory.
  • A new integration into a system you already rely on (the mailbox, the CRM, the file store), usually granted broad permissions because narrower ones took longer to configure.
  • A new path for data to leave, which is the one that turns a productivity tool into a data protection question.

None of that is an argument for refusing the tool. It is an argument for knowing which of the four you have just taken on, before the tool is embedded in a workflow and removing it becomes a business disruption rather than an IT decision.

Before you procure

Three questions,asked before signing.

Question 01 · The vendor

What do they hold, and where?

What data does the tool receive, where is it stored, how long is it kept, and is it used to train anything? These are answerable from the vendor's own documentation. If they are not, that is itself the answer.

Question 02 · The connection

What did we grant it?

Which systems is it connected to and at what permission level. "Read everything in the mailbox" and "read one folder" are both a tick in a procurement checklist and are not remotely the same exposure.

Question 03 · The record

Who owns it after go-live?

A named person, the tool on the account and asset inventories, and a date to review it. A pilot that nobody formally owns is the most common way an AI tool becomes permanent without ever being assessed.

Where the CSA marks fit

Singapore's position on this moved before most SMEs did. CSA expanded both the Cyber Essentials and Cyber Trust marks to cover cloud security, AI security and operational technology. So the question "how do we secure our AI adoption" now has a documented answer inside a scheme SMEs can actually certify against, rather than only in vendor whitepapers.

Which mark suits you is a separate question, and it is not answered by headcount. We wrote that up in full: Cyber Essentials or Cyber Trust? How to choose, and the two mistakes that cost most.

Worth being plain about what certification does and does not do. It will not stop an attack. What it does is force the inventory, the ownership and the detection question to be answered on a schedule instead of after an incident. Certification is not the goal. Being able to answer for yourself is the goal, and certification is the mechanism that makes someone do it.

If you take one thing from this

Adopt the AI. The productivity case is real and the firms that sit it out will not be rewarded for caution.

But make the security half of the decision deliberately: know what each tool holds, know what you connected it to, and give it an owner. Then answer the question at the top of this page, and if the answer is uncomfortable, start there rather than with a purchase.

One disclosure

Greenwich holds the Cyber Trust mark itself, at Promoter tier, with the AI Security pillar in scope alongside Cloud Security and the classical one. We were assessed against the AI requirements as the client rather than the consultant, which is where most of the above comes from.

Want the structured version?

We built an AI Readiness Check for the conference: eight questions, a few minutes, and an indicative read on where you stand. It is not an assessment, and it says so. The three questions above work retrospectively too, if tools are already connected.

More where this came from.
Regulatory watch, without the noise.