top of page

Dr Edwin Lee | DrCyberPastor

Cybersecurity · Leadership · Stewardship

Insights for Leaders Navigating a Complex World

Practical thinking on cybersecurity, leadership, and the challenge of building organisations with integrity — from nearly 30 years in the field.

All posts
Cybersecurity
Leadership
Stewardship
AI & Technology
FEATURED

01

5 min read · Cybersecurity
CYBERSECURITY

The Hidden Cyber Risks SMBs Bring to Your Supply Chain

Dr Edwin Lee · April 2025 · 5 min read

In today's interconnected world, global supply chains are both an operational necessity and a major cybersecurity vulnerability. While large enterprises invest heavily in security, their supply chains rely on SMBs that lack the same maturity. Here's what you need to know.

Read the article →
02
Why Cybersecurity Is a Leadership Problem — Not an IT Problem
LEADERSHIP
Dr Edwin Lee · April 2025 · 4 min read

Every week, boards ask their IT teams whether the organisation is secure. They're asking the wrong people. Here's why cybersecurity belongs in the boardroom.

Read the article
03
Why Cybersecurity Is a Leadership Problem — Not an IT Problem
CYBERSECURITY · LEADERSHHIP

Most CEOs think about cyber incidents in the abstract — something that happens to other companies. Then it happens to them. Here's what I wish every CEO knew before that call comes.

Dr Edwin Lee · April 2025 · 5 min read
Read the article

Get insights delivered to your inbox

Monthly cybersecurity and leadership thinking from DrCyberPastor. No spam. Unsubscribe anytime.

CYBERSECURITY 

The Hidden Cyber Risks SMBs Bring to Your Supply Chain

Dr Edwin Lee | DrCyberPastor  ·  April 2025  ·  5 min read

In today's interconnected world, global supply chains are both an operational necessity and a major cybersecurity vulnerability.

While large enterprises often invest heavily in securing their digital infrastructure, their supply chains rely on a vast network of small and mid-sized businesses (SMBs) that lack the same cybersecurity maturity. Cybercriminals increasingly exploit these vulnerable SMBs to access larger, more lucrative targets.

As geopolitical tensions rise and cyberattacks grow more sophisticated, the risks to global supply chains are more pressing than ever. This article explores why SMBs in global supply chains are the primary weak link, the potential fallout for enterprise buyers, and the measures organisations must take to secure their extended ecosystems.

The growing threat landscape

Geopolitical cyber threats. State-sponsored cyberattacks are on the rise, targeting critical industries and their supply chains to disrupt economies and extract sensitive information.

Ransomware attacks. SMBs are frequent targets for ransomware gangs, who exploit their weaker defences to penetrate larger enterprise networks.

Regulatory pressures. Governments worldwide are enacting stricter regulations to hold companies accountable for securing their supply chains — including the EU's NIS2 Directive and the U.S. Cyber Incident Reporting for Critical Infrastructure Act.

Third-party breaches. High-profile incidents like the SolarWinds attack reveal how a single compromised vendor can create cascading impacts across the global digital ecosystem.

Why SMBs are the weakest link

Limited resources. SMBs often lack the financial and human resources to invest in advanced cybersecurity tools and practices.

 

Inconsistent security practices. Many SMBs lack standardised cybersecurity frameworks, leading to inconsistent protection across the supply chain.

Lack of threat visibility.Without sophisticated monitoring and detection systems, SMBs are often unaware when they have been breached.

Outdated systems. Legacy software and unpatched vulnerabilities provide easy entry points for cybercriminals.

The business risk for enterprise buyers

A weak link in the supply chain can have severe consequences: operational disruption, data breaches exposing sensitive intellectual property, reputational damage, and regulatory penalties under evolving global cybersecurity laws.

Relying solely on vendor questionnaires and periodic audits is no longer sufficient. Cyber threats are dynamic, and static assessments fail to capture real-time risks.

Proactive measures for enterprise buyers

In today's interconnected world, global supply chains are both an operational necessity and a major cybersecurity vulnerability.

While large enterprises often invest heavily in securing their digital infrastructure, their supply chains rely on a vast network of small and mid-sized businesses (SMBs) that lack the same cybersecurity maturity. Cybercriminals increasingly exploit these vulnerable SMBs to access larger, more lucrative targets.

As geopolitical tensions rise and cyberattacks grow more sophisticated, the risks to global supply chains are more pressing than ever. This article explores why SMBs in global supply chains are the primary weak link, the potential fallout for enterprise buyers, and the measures organisations must take to secure their extended ecosystems.

Conclusion

As cyber threats escalate worldwide, enterprises cannot afford to overlook the vulnerabilities in their supply chains. Enterprise buyers must shift from a compliance-based mindset to a proactive, continuous risk management approach — not just to protect themselves, but to contribute to the broader security and stability of the global digital economy.

LEADERSHIP 

Why Cybersecurity Is a Leadership Problem — Not an IT Problem

Dr Edwin Lee | DrCyberPastor  ·  April 2025  ·  5 min read

Every week, boards ask their IT teams whether the organisation is secure. They are asking the wrong people.

I have spent nearly 30 years in cybersecurity — at Accenture, HP, DXC Technology, and now as a Fractional CISO to regulated companies across Asia-Pacific. And the single most consistent predictor of a company's cyber resilience is not the size of its security budget. It is not the sophistication of its tools. It is the degree to which the leadership team takes ownership of security as a strategic priority.

Cybersecurity is a leadership problem. And until boards and CEOs accept that, no amount of technology will close the gap.

The myth of the IT department

For decades, organisations have treated cybersecurity as a technical problem — something to be solved by the people who manage the servers. This was always a flawed model, but it was survivable when threats were unsophisticated.

Today's attackers are patient, professional, and strategic. State-sponsored groups conduct multi-year campaigns. Ransomware gangs research their victims before striking. Social engineering attacks bypass technology entirely — targeting the human layer, not the firewall. None of these are solved by the IT department alone.

What boards get wrong

Most boards fall into one of two failure modes. The first is abdication — treating cybersecurity as someone else's problem, asking for a traffic light report once a quarter. This board discovers its exposure only after an incident. The second is anxiety without action — the board that knows it should care, invites the CISO to present once a year, and walks away more confused than when they arrived.

What leadership ownership actually looks like

They ask different questions. Not "are we secure?" but: "What are our three most critical assets? What would it cost if we lost access for 72 hours? What decisions this quarter change our risk profile?"

They include security in business decisions. A new vendor relationship, an acquisition, a cloud migration — all carry cybersecurity implications. Organisations that consider security at the decision point spend far less than those who bolt it on afterwards. cost if we lost access for 72 hours? What decisions this quarter change our risk profile?"

They build a culture of ownership. When the CEO talks about security, the organisation listens. Culture is set at the top.

They know the plan. Not the technical plan — the business continuity plan. Who decides what to say to customers? Who calls the regulator? These decisions must be owned before the incident, not during it.

The bottom line

Cybersecurity is not an IT problem. It is a leadership responsibility. And it starts with the board deciding to own it.

Cybersecurity · Leadership 

What Every CEO Should Know Before Their First Cyber Incident

Dr Edwin Lee | DrCyberPastor  ·  April 2025  ·  5 min read

Most CEOs think about cyber incidents in the abstract — something that happens to other companies, to organisations with weaker defences. Then the call comes.

I have been in the room when organisations discover they have been breached. I have seen the confusion, the panic, the costly mistakes made in the first hours that compound the damage for weeks. In almost every case, what made those moments harder was not a lack of technology. It was a lack of preparation at the leadership level.

The first hour is the most expensive

They try to fix it quietly. The instinct is understandable — contain the problem before it becomes a crisis. But delayed disclosure almost always makes things worse: regulatory penalties are steeper, customer trust is harder to rebuild, and the cover-up becomes part of the story.

They let IT lead the response. The technical team should lead the technical response. But the moment a breach becomes a business event, it needs business leadership. IT cannot answer: who is communicating with customers? Who is talking to the regulator?

They improvise. Without a pre-agreed response plan, every decision is made under pressure, with incomplete information, by people who are frightened and exhausted.

What you need before the incident

A response plan with names, not roles. "The CISO will notify the board" is not a plan. A specific person, calling a specific number, within a specific timeframe — that is a plan.

 

Regulatory obligations understood. In Singapore, the PDPA requires notification of the PDPC within three business days of a data breach affecting 500 or more individuals or likely to cause significant harm. MAS-regulated entities have additional obligations. Do you know yours.

A relationship with an incident response firm.When a breach happens is not the time to start evaluating vendors. A pre-agreed letter of engagement with agreed response times can cut hours off your recovery.

What to expect during the incident

It will take longer than you think. Containment, investigation, remediation, and recovery can take days or weeks. Plan for business continuity through that period.

You will not have complete information. The story keeps changing — first one system, then three, then the scope expands again. Build your communications strategy around what you know to be true, not what you hope to be true.

Customers are more forgiving than you expect — if you are honest. Organisations that communicate quickly, honestly, and with a clear remediation plan retain customer trust far better than those that delay or minimise.

The question to ask today

If your organisation suffered a significant breach at 11pm tonight, what would happen in the next two hours? If you cannot answer that question clearly — with names, numbers, and decisions — you have work to do. And the best time to do that work is before the call comes.

Want Edwin's thinking delivered monthly?

Subscribe to DrCyberPastor Insights — cybersecurity and leadership for business leaders across Asia-Pacific.

bottom of page