Agentic AI attacks are the reason this year’s Singapore International Cyber Week has the theme “Cyber at a Crossroads”. SICW 2026 opens on 12 October at the Sands Expo and Convention Centre, and the GovWare conference running alongside it from 13 to 15 October has gone further with its theme: “Cyber at Agentic Velocity”. The organisers expect more than 15,000 attendees from over 90 countries.
Most SMB owners will not attend. The conversation in those halls will still reach your business within a year, because the attack techniques discussed there are already being used against small companies in Singapore.
What is changing in agentic AI attacks?
For most of the last decade, a cyberattack needed people. Someone had to find a weak server, write a convincing email, try stolen passwords and move through a network one step at a time. That work took hours or days, and it limited how many targets a criminal group could pursue.
Agentic AI removes most of that limit. In its Singapore Cyber Landscape 2025/2026 report, released on 30 June 2026, the Cyber Security Agency of Singapore (CSA) describes threat actors using agentic AI to automate significant parts of the cyber kill chain. The Baker McKenzie summary of the same report notes attackers using “agentic orchestrators to manage the entire attack lifecycle”.
GovWare’s organisers put the problem plainly in their launch announcement: intelligent systems now sense signals, support decisions and trigger actions, and the time between signal and consequence is compressing.
For an SMB, compression is the part that hurts. A gap you would have had a week to close now gets found and tested in an afternoon.
Why do SMBs feel this first?
Large enterprises have security teams watching logs around the clock. A 30-person firm usually has an IT vendor and a shared admin password.
CSA’s numbers show where the pressure lands. Singapore recorded 165 ransomware cases in 2025, up from 159 in 2024, and CSA states that SMEs “continued to be disproportionately affected” because of lower cybersecurity maturity and limited resources. Infected systems in Singapore rose to 284,300 in 2025, a 142% increase on the year before.
Phishing fell. CSA received about 4,800 phishing reports in 2025, down 21% from around 6,100 in 2024. Fewer reports does not mean fewer attempts reaching inboxes. AI-written messages are harder to spot, and a message no one recognises as phishing never gets reported.
Agentic tools make small targets more attractive. When the cost of attacking one more company drops close to zero, attackers stop choosing between a bank and a logistics SME. They try both.
What does an agentic attack on an SMB look like?
Here is a realistic sequence, assembled from patterns CSA and industry researchers describe.
An agent scans thousands of Singapore company domains overnight and flags one with an unpatched VPN appliance. It pulls staff names from the company’s LinkedIn page and writes a payment-change email in the finance manager’s style, using text scraped from a public tender document. While that email waits in an inbox, the same agent tries leaked passwords against the VPN. One works. By morning, the attacker has a foothold and a list of file shares, and ransomware is staged before anyone in the office has had coffee.
None of those steps is new. What is new is that one operator can run that sequence against hundreds of companies at the same time.
Five habits that keep an SMB ahead
The good news from SICW’s own agenda is in the first half of GovWare’s theme: “Anchored in Unchanging Principles”. The defences that work against AI-run attacks are the ones that worked before. What changes is how quickly you need them in place. Five habits cover most of the risk.
1. Phishing-resistant sign-in everywhere
CSA’s report tells organisations to prioritise phishing-resistant authentication. That means passkeys or hardware security keys for email, finance systems, cloud consoles and your VPN. SMS codes and push approvals can be relayed by an attacker in real time. A passkey cannot.
2. Least privilege for people and for agents
Every account should hold only the access its job needs. This now includes the AI agents and service accounts your own business runs. An agent that drafts quotations does not need write access to your accounting system. We covered how to set these boundaries in our piece on IMDA’s agentic AI framework.
3. Patch on a clock
Set a written deadline: critical patches on internet-facing systems within 72 hours, everything else within 30 days. Agentic scanners find exposed VPNs, firewalls and content management plugins within days of a vulnerability going public. Your website counts here too, and AI crawler traffic has already made website upkeep a security question.
4. Backups an attacker cannot reach
Keep at least one copy of critical data offline or in immutable storage, and restore from it once a quarter. A backup that has never been restored is a hope rather than a plan. Ransomware groups look for backup servers first because a working backup takes away their bargaining power.
5. A one-page incident plan with names on it
When an agent moves in minutes, there is no time to work out who to call. Write one page: who decides to disconnect systems, who calls the bank, who contacts your IT vendor and who notifies the PDPC if personal data is involved. Pin it where finance and operations can see it.
What should you ask your IT vendor this month?
Most SMBs outsource IT, which means the five habits above live partly in someone else’s hands. Book 30 minutes with your provider before SICW ends and ask four direct questions:
- Which of our logins still accept SMS codes or push approvals, and when can we move them to passkeys?
- How many days did it take to patch our firewall and VPN after the last critical advisory?
- When did we last restore a full backup, and how long did the restore take?
- If ransomware hit us at 2am on a Saturday, who on your side picks up the phone?
Write the answers down. Vague answers to the second and third questions are the most common gap we find in SMB security reviews, and both can be closed inside a month.
Where can SMBs get help?
Singapore offers more support than most owners realise. CSA’s Cyber Essentials mark gives SMEs a structured baseline, and more than 800 organisations had earned Cyber Essentials or Cyber Trust certification by early 2026. CSA’s CISO-as-a-Service programme offers SMEs up to 70% co-funding for cybersecurity advisory work, which puts an experienced security lead within reach of a 20-person business.
The companies that come through the next year intact will be the ones that treated SICW week as a deadline rather than a news story. Pick one of the five habits above and finish it before GovWare closes on 15 October.
Webpuppies runs security reviews and remediation for Singapore SMBs, from authentication rollouts to patch automation and backup testing. Book a security review with our team and we will tell you which of the five habits your business needs first.
Sources
- CSA: Initiatives to strengthen Singapore’s cyber defences amid an AI-driven threat landscape (30 June 2026)
- Baker McKenzie: CSA Cyber Landscape Report 2025/2026
- PR Newswire: GovWare 2026 to convene global leaders as cyber moves at agentic velocity
- Singapore International Cyber Week
Frequently Asked Questions
What are agentic AI attacks?
Agentic AI attacks use AI agents that plan and carry out steps of an intrusion on their own, such as scanning for weak systems, writing phishing messages and moving through a network, with little human direction.
When is Singapore International Cyber Week 2026?
SICW 2026 runs from 12 to 15 October 2026 at the Sands Expo and Convention Centre. GovWare 2026 runs alongside it from 13 to 15 October.
Are SMEs in Singapore targeted by ransomware?
Yes. CSA recorded 165 ransomware cases in Singapore in 2025, up from 159 in 2024, and reported that SMEs continued to be disproportionately affected.
What is the first thing an SMB should do about agentic AI threats?
Move every staff and admin login to phishing-resistant authentication, such as passkeys or hardware security keys. CSA names this as a priority in its 2025/2026 report.
Is there funding for SME cybersecurity in Singapore?
Yes. CSA’s CISO-as-a-Service programme offers SMEs up to 70% co-funding for cybersecurity advisory services, and the Cyber Essentials mark gives a structured baseline to work towards.
