VHVendra Holdings

Security

IT security for firms that cannot absorb an incident.

Most Singapore SMEs have no one whose job is security. We take that job: a fixed-price review, the fixes that matter most, and monitoring that calls a named person when something looks wrong.

Review to written findings
4 days
Incident response target
< 4 hrs
Compliance scope
PDPA
Monitoring, managed tier
24/7

Where it breaks

Most SME breaches are not sophisticated.

  • 01

    Nobody owns it

    IT is whoever is least busy, or a vendor who set things up in 2019 and has not been back. When something goes wrong at 6pm on a Friday there is no one to call and no plan to follow.

  • 02

    Shared logins and stale accounts

    One password in a group chat. Three ex-staff who can still open the shared drive. This is how most SME incidents start, and it costs almost nothing to fix.

  • 03

    Email is the front door

    Supplier impersonation and redirected invoices are the most common loss we see. A single altered bank account line can cost more than a year of security spend, and the money is rarely recovered.

  • 04

    Backups nobody has tested

    Having backups and being able to recover are different things. A restore that has never been rehearsed is a guess, and ransomware is when you find out.

  • 05

    Client security questionnaires

    Larger clients and government tenders now ask 40 to 80 questions about your controls before they sign. Answering well wins work. Answering vaguely loses it quietly.

  • 06

    No visibility

    Without monitoring, an intruder in an SME network goes unnoticed for weeks. The clean-up is measured in days of downtime, not hours.

What we do

Six services. Take one or all of them.

Security assessment

A structured review of accounts, devices, email and external exposure. You receive a prioritised findings list with a fixed price against each fix, within five working days.

  • Accounts, devices and access review
  • External exposure and domain check
  • Prioritised findings, fixed-price remediation

Identity and access

Multi-factor authentication on email and core systems, one account per person, and a documented process for when staff join, move or leave. The highest-return work we do, and usually the cheapest.

  • MFA across email and core systems
  • Per-person accounts, no shared logins
  • Documented joiner and leaver process

Endpoint hardening

Laptops, phones and shared site tablets get managed protection, disk encryption and enforced updates. Personal devices are covered by policy where they cannot be covered by software.

  • Managed endpoint protection
  • Disk encryption and screen-lock policy
  • Patch and update enforcement

Email and phishing defence

Domain authentication so nobody can send as you, inbound rules that catch impersonation and payment-detail changes, and short staff simulations that change behaviour without a training day.

  • SPF, DKIM and DMARC configured
  • Impersonation and payment-change rules
  • Quarterly phishing simulations

Backup and recovery

Offsite, versioned backups with a scheduled test restore. We commit a recovery time in writing and prove it every quarter, not once at setup.

  • Offsite, versioned backups
  • Scheduled test restores
  • Written recovery runbook

Monitoring and response

Identity and endpoint events watched around the clock, a named escalation contact, and a four-hour response target for confirmed incidents. Every incident closes with a written report.

  • Alerting on identity and endpoint events
  • Named escalation contact
  • Four-hour response target, written report after

How we work

Assess, fix, then keep it fixed.

  1. 01

    Review

    A half-day on site and remote checks against your domain and accounts. You get a written, prioritised findings list. Fixed price, no obligation to continue.

    Week 1
  2. 02

    Remediate

    Fixed scope, fixed price. Highest risk and lowest effort first, so the biggest exposures close in the first week. Work is scheduled around your team, not through them.

    Weeks 2 to 4
  3. 03

    Monitor

    The managed tier: monthly coverage, alerts watched, a person to call. Month to month, cancel with 30 days' notice.

    Ongoing
  4. 04

    Report

    A short report an owner can hand to a client, insurer or bank. What is covered, what changed, what is next.

    Quarterly

Engagement

What this looks like in practice.

LogisticsA 45-person logistics operator, Singapore

The firm ran one shared email password across its operations desk, had no multi-factor authentication anywhere, and owned a backup drive nobody had checked since it was installed. A supplier-impersonation attempt had already reached the finance inbox. We ran a four-day review, closed the eleven highest-risk findings over three weeks, and moved them onto the monitoring tier.

We had assumed someone was handling it. Now someone is, and I can show a client exactly what that looks like.

Operations Director
31 → 0
Accounts without MFA
27% → 4%
Phishing simulation click rate, 90 days
38 min
Full restore, tested quarterly

Client named on request. Figures from the engagement close-out report.

Start with a review.

A fixed-price review takes four working days and ends with a written findings list you keep whether or not we do the fixes.