Software Vendor Lock-In: Can a Singapore SME Get Its Own Data Out?
You own your business data in law, but in practice you only own the part you can export and read without your vendor's help. Here is a 90-minute test to find out which systems would hold your records hostage, and what to fix in the contract before you commit to a 2027 stack.
How to Get Your Suppliers Onto InvoiceNow Before the GST Mandate: A 90-Day Campaign
You can be fully InvoiceNow-ready and still receive 90% of your purchase invoices as PDF attachments, because being ready is about your system and your suppliers are not in it. Moving counterparties onto the network is a procurement campaign, not an IT project. Here is how to run it in waves over 90 days, which suppliers to contact first, what the email should say, and what to do with the ones who refuse or genuinely cannot comply before the GST InvoiceNow phases reach you.
Shared Admin Logins: Who Can Lock a Singapore SME Out of Its Own Business?
Most Singapore SMEs cannot name who controls their domain, Meta Business account or accounting software super-admin. That gap is not a security abstraction; it is a shutdown risk. Here is a practical ownership audit any 10-person firm can finish in an afternoon.
One ERP or Five Best-of-Breed Tools? Choosing a 2027 Stack
Most Singapore SMEs rebuilding their systems for 2027 are asking the wrong question first. The choice between one ERP and five connected best-of-breed tools is not about features — it is about how many times a day data has to cross a gap between two systems, and who is responsible when it does not. Here is a five-question test you can run in an afternoon.
MFA and Passkey Rollout for a Small Team: A 30-Day Plan for Google Workspace and Microsoft 365
A sub-20-person company can finish an MFA and passkey rollout in about a month, but only in the right order: admins first, passkeys as the primary factor, SMS retired, then the quiet backdoors closed. Here is the sequence, what breaks, and what it costs.
PDPA Data Protection Officer: What Singapore SMEs Must Fix Before 2027
The PDPA has no headcount exemption: if your company handles personal data in Singapore, you need a named data protection officer with published contact details. Most SMEs have nobody appointed, no registered contact, and no written answer to who owns customer data. Here is the minimum defensible setup, and how to close it before 2027.
Business Email Compromise: Protecting Singapore SME Year-End Payments
Scammers do not break into your systems at year-end; they wait for a busy approver covering for someone on leave. This post sets out the three payment controls, the email account settings and the first-hour response plan that stop a fake supplier invoice from being paid between now and January.
Is the Cyber Essentials Mark Worth It for Singapore SMEs Bidding on Tenders?
Government and enterprise buyers are starting to ask for CSA's Cyber Essentials mark in procurement documents, which turns a security question into a commercial one. Here is what the mark actually requires, how long a sub-20-person company needs to get ready, and when it is cheaper to adopt the checklist without certifying.
Backup Restore Testing for Singapore SMEs: The 3-2-1 Rule and the Restore Nobody Has Tried
Your backup job says "completed" every night. That tells you a file was written somewhere — not that your data is recoverable. This is the 90-minute restore test a 15-person Singapore company can run twice a year, the five reasons healthy-looking backups fail at the moment of truth, and the one-page record that answers both PDPA accountability questions and enterprise tender security questionnaires.
Employee Offboarding Checklist for Singapore SMEs: Revoking Access on the Last Day, Not the Last Quarter
Most small companies suspend the email account and consider offboarding done. Meanwhile the ex-staff member is still in the customer WhatsApp group, still owns a Drive folder of invoices, and still holds the phone number receiving your 2FA codes. Here is the revocation sequence to run on the last working day, and the record that proves you ran it.
InvoiceNow for Non-GST Registered Businesses: What to Do Before 2027
The InvoiceNow mandate only covers newly GST-registered businesses, so most small Singapore firms have filed it under 'not my problem'. That is a mistake of sequence, not of fact. The requirement will arrive through your largest customers' accounts payable teams long before it arrives from IRAS, and the firms that can receive a structured e-invoice in 2027 will be paid faster than the ones still attaching PDFs to email. This post sets out what non-GST and voluntary adopters should do in the next 90 days, what it costs, and the three ways SMEs usually get it wrong.
How to Choose an InvoiceNow Access Point in Singapore Before the GST Mandate Reaches You
Choosing an InvoiceNow access point takes an afternoon. Cleaning your customer master data, mapping your UEN-based Peppol ID and getting suppliers off PDF invoices takes three months. Here is the order of work for a Singapore SME that wants to be connected and tested well before the GST InvoiceNow requirement reaches its segment.