Governance / CSA CISO-as-a-Service

CSAListed CISO-as-a-Service consultant

Up to 70% co-funding
for your cyber health plan.

Under CSA’s SG Cyber Safe Programme, eligible SMEs can engage Insyghts as their CISO-as-a-Service consultant to assess cyber health, build a plan and prepare for certification.

In healthcare?

See how this applies to Health Information Act readiness.

SG Cyber Safe Programme

CSA’s roadmap for every business, at every maturity stage.

The Cyber Security Agency of Singapore’s SG Cyber Safe Programme gives enterprises tools and certification marks to lift their cybersecurity, and to show customers they can be trusted.

  • Toolkits & health checks Self-help guides, health check assessments and the Cyber Essentials in Action tabletop game.
  • Cyber Essentials mark Foundational cyber hygiene for organisations starting out.
  • Cyber Trust mark Risk-based certification for organisations with higher risk profiles.

Organisations can add specialised tracks for cloud, operational technology and AI, and use CISO as-a-Service to get there with a pre-approved consultant.

  • + CLOUD TRACK
  • + OT TRACK
  • + AI TRACK
Isometric illustration: Toolkits, Essentials and Trust blocks rising like steps, with Cloud, OT and AI tiles and a shield

Inside the marks

What each mark covers.

Cyber Essentials is the baseline: 5 pillars and 9 domains across people, process and technology. Cyber Trust scales from 10 to 22 domains across five Cybersecurity Preparedness tiers, based on your risk profile.

Cyber Essentials

domains · 5 pillars · Cyber Essentials

Pillar 1 · Assets

  • PeoplePeople
  • ProcessHardware and software
  • ProcessData

Pillar 2 · Secure / Protect

  • TechnologyVirus and malware protection
  • TechnologyAccess control
  • TechnologySecure configuration

Pillar 3 · Update

  • TechnologySoftware updates

Pillar 4 · Backup

  • ProcessBack up essential data

Pillar 5 · Respond

  • ProcessIncident response

Cyber Trust

of 22 domains · Tier {tier}

  • 1 · Supporter
  • 2 · Practitioner
  • 3 · Promoter
  • 4 · Performer
  • 5 · Advocate
  • In scope
  • Not required at this tier

Cyber governance and oversight

  • T3+Governance
  • T3+Policies and procedures
  • T1+Risk management
  • T5+Cyber strategy
  • T1+Compliance
  • T4+Audit

Cyber education

  • T1+Training and awareness*

Information asset protection

  • T1+Asset management*
  • T1+Data protection and privacy*
  • T1+Backups*
  • T3+Bring your own device (BYOD)
  • T1+System security*
  • T1+Anti-virus / anti-malware*
  • T3+Secure SDLC

Secure access and environment

  • T1+Access control*
  • T4+Cyber threat management
  • T3+Third-party risk and oversight
  • T3+Vulnerability assessment
  • T2+Physical / environmental security
  • T2+Network security

Cybersecurity resilience

  • T1+Incident response*
  • T2+Business continuity / disaster recovery

* Cyber Trust domains marked with an asterisk are also measures in the Cyber Essentials mark. Source: CSA SG Cyber Safe Programme.

Isometric illustration: a health plan board with four ticked items, a shield and a heartbeat badge

CISO as-a-Service

A part-time CISO to build your Cybersecurity Health Plan.

Most SMEs can’t justify a full-time CISO. Under CSA’s CISO as-a-Service, a pre-approved consultant plays that role for you, pre-scoped to the Cyber Essentials and Cyber Trust marks.

  • Cyber health checkup Assess your organisation against CSA’s Cyber Essentials and/or Cyber Trust marks.
  • Tailored health plan A prioritised cybersecurity health plan to improve progressively.
  • Close the gaps Guidance to fix identified cyber hygiene gaps.
  • Certification-ready Prepared for Cyber Essentials certification, at minimum.

Why Insyghts

Three services, one consultant.

Insyghts delivers all three. Funding applies where CSA’s programme covers it.

CO-FUNDED

CISO-as-a-Service

Cyber health assessment, a tailored cybersecurity health plan and preparation for Cyber Essentials, then Cyber Trust.

CO-FUNDED

VAPT

Vulnerability assessment and penetration testing, by a CSA-licensed penetration testing provider.

NOT CURRENTLY FUNDED

Incident response

Available from Insyghts. CSA currently offers no funding for incident response services.

The pathway

From health check to certification.

  • Co-funded
  • Co-funded
  • Certification
  • Risk-based mark

Assess

Cyber health assessment to find hygiene gaps.

Plan

A cybersecurity health plan tailored to your organisation.

Cyber Essentials

Close gaps and prepare for Cyber Essentials certification.

Cyber Trust

Progress to the risk-based Cyber Trust mark.

Eligibility

Who can take part.

Isometric illustration: a small office building under a shield

SMEs

Up to 70% co-funding

CO-FUNDED

Isometric illustration: a tall office tower

Any size

Engage directly, without funding

DIRECT

Isometric illustration: a community building under a heart

Social Service Agencies

Data Protection Officer services

NCSS

Is my business an eligible SME?

CSA refers funding applications to IMDA’s SMEs Go Digital. Final eligibility is confirmed by IMDA when you apply. At minimum, your business must be:

  • Registered and operating in Singapore With a valid UEN
  • Group sales turnover of not more than S$100 million OR group employment size of not more than 200 employees

Funding is subject to CSA and IMDA eligibility and approval. Source: CSA — CISO as-a-Service (updated 6 September 2026).

How to apply

Three steps to start.

01

Sign up

Register through IMDA’s SMEs Go Digital platform and select Insyghts.

02

Assessment

We run your cyber health assessment.

03

Your plan

You receive a cybersecurity health plan and next steps toward certification.

Pricing

Pre-scoped, co-funded pricing.

Insyghts’ CSA-listed fees. Up to 70% co-funding for eligible SMEs on the first 200 end-points, for CISO as-a-Service and VAPT.

How many end-points?

What you pay

  • Fee before funding
  • Funding (up to 70%)
  • Out of pocket
  • Optional retainer, per man-hour
  • Optional retainer, per month

CISOaaS · Cyber Essentials

  • Classical
  • For ICT vendors

Add-ons

End-pointsFeeFundingYou payRetainer / hrRetainer / month
1–10S$2,400S$1,680S$720S$100S$400
11–20S$3,200S$2,240S$960S$100S$800
21–50S$4,800S$3,360S$1,440S$100S$1,200
51–100S$8,000S$5,600S$2,400S$100S$1,600
101–200S$12,000S$8,400S$3,600S$100S$2,400
201–500 (per add’l 100)+ S$4,800——S$100S$800
501+ (per add’l 100)+ S$2,400——S$100S$800
Classical cybersecurity
End-pointsFeeFundingYou payRetainer / hrRetainer / month
1–10S$3,600S$2,520S$1,080S$150S$720
11–20S$4,800S$3,360S$1,440S$150S$1,440
21–50S$7,200S$5,040S$2,160S$150S$2,160
51–100S$12,000S$8,400S$3,600S$150S$2,880
101–200S$18,000S$12,586S$5,414S$150S$4,320
201–500 (per add’l 100)+ S$7,200——S$150S$1,440
501+ (per add’l 100)+ S$3,600——S$150S$1,440
Cyber Essentials for ICT vendors
End-pointsFeeFundingYou pay
1–10S$1,680S$998S$682
11–20S$2,240S$1,238S$1,002
21–50S$3,360S$1,612S$1,748
51–100S$5,600S$2,226S$3,374
101–200S$8,400S$3,030S$5,370
201–500 (per add’l 100)+ S$3,360——
501+ (per add’l 100)+ S$1,680——
Cloud security
End-pointsFeeFundingYou pay
1–10S$1,680S$998S$682
11–20S$2,240S$1,238S$1,002
21–50S$3,360S$1,612S$1,748
51–100S$5,600S$2,226S$3,374
101–200S$8,400S$3,030S$5,370
201–500 (per add’l 100)+ S$3,360——
501+ (per add’l 100)+ S$1,680——
OT security
End-pointsFeeFundingYou pay
1–10S$1,920S$998S$922
11–20S$2,560S$1,238S$1,322
21–50S$3,840S$1,612S$2,228
51–100S$6,400S$2,226S$4,174
101–200S$9,600S$3,030S$6,570
201–500 (per add’l 100)+ S$3,840——
501+ (per add’l 100)+ S$1,920——
AI security

SGD. Cyber Essentials comes in two variants: classical, and for ICT vendors. Cloud, OT and AI security are add-ons charged on top, each a separate package on SMEs Go Digital. Retainers shown are for classical cybersecurity; add-on retainers are extra. Funding covers the first 200 end-points only and is subject to CSA and IMDA eligibility and approval. Retainers receive no funding. Above 200 end-points, fees are per additional 100 end-points. Source: CSA CISOaaS (Cyber Essentials) provider listing, 18 August 2026.

CISOaaS · Cyber Trust

  • Supporter
  • Practitioner
  • Promoter
  • Performer
  • Advocate

Add-ons

End-pointsFeeFundingYou payRetainer / hrRetainer / month
1–10S$5,880S$4,116S$1,764S$180S$1,400
11–20S$7,180S$5,026S$2,154S$180S$2,100
21–50S$8,280S$5,796S$2,484S$180S$2,800
51–100S$9,480S$6,636S$2,844S$180S$3,500
101–200S$12,080S$8,456S$3,624S$180S$5,600
201–500 (per add’l 100)+ S$6,480——S$180S$2,800
501+ (per add’l 100)+ S$5,880——S$180S$2,800
Cyber Trust Supporter · Classical cybersecurity
End-pointsFeeFundingYou payRetainer / hrRetainer / month
1–10S$5,880S$4,116S$1,764S$180S$2,100
11–20S$7,180S$5,026S$2,154S$180S$2,800
21–50S$8,280S$5,796S$2,484S$180S$3,500
51–100S$9,480S$6,636S$2,844S$180S$4,200
101–200S$12,080S$8,456S$3,624S$180S$6,300
201–500 (per add’l 100)+ S$6,480——S$180S$3,500
501+ (per add’l 100)+ S$5,880——S$180S$3,500
Cyber Trust Practitioner · Classical cybersecurity
End-pointsFeeFundingYou payRetainer / hrRetainer / month
1–10S$5,860S$4,102S$1,758S$180S$2,800
11–20S$6,180S$4,326S$1,854S$180S$3,500
21–50S$7,680S$5,376S$2,304S$180S$4,200
51–100S$8,680S$6,076S$2,604S$180S$4,900
101–200S$12,680S$8,876S$3,804S$180S$7,000
201–500 (per add’l 100)+ S$6,780——S$180S$4,200
501+ (per add’l 100)+ S$6,860——S$180S$4,200
Cyber Trust Promoter · Classical cybersecurity
End-pointsFeeFundingYou payRetainer / hrRetainer / month
1–10S$5,860S$4,102S$1,758S$180S$3,500
11–20S$6,180S$4,326S$1,854S$180S$4,200
21–50S$7,680S$5,376S$2,304S$180S$4,900
51–100S$8,680S$6,076S$2,604S$180S$5,600
101–200S$12,680S$8,876S$3,804S$180S$7,700
201–500 (per add’l 100)+ S$6,780——S$180S$4,900
501+ (per add’l 100)+ S$6,860——S$180S$4,900
Cyber Trust Performer · Classical cybersecurity
End-pointsFeeFundingYou payRetainer / hrRetainer / month
1–10S$5,860S$4,102S$1,758S$180S$4,200
11–20S$6,180S$4,326S$1,854S$180S$4,900
21–50S$7,680S$5,376S$2,304S$180S$5,600
51–100S$8,680S$6,076S$2,604S$180S$6,300
101–200S$12,680S$8,876S$3,804S$180S$8,400
201–500 (per add’l 100)+ S$6,780——S$180S$5,600
501+ (per add’l 100)+ S$6,860——S$180S$5,600
Cyber Trust Advocate · Classical cybersecurity
End-pointsFeeFundingYou pay
1–10S$1,480S$1,036S$444
11–20S$1,780S$1,246S$534
21–50S$2,080S$1,456S$624
51–100S$2,380S$1,666S$714
101–200S$3,680S$2,576S$1,104
201–500 (per add’l 100)+ S$1,980——
501+ (per add’l 100)+ S$1,780——
Cloud security
End-pointsFeeFundingYou pay
1–10S$1,380S$966S$414
11–20S$2,680S$1,876S$804
21–50S$3,680S$2,576S$1,104
51–100S$5,860S$4,102S$1,758
101–200S$7,860S$5,502S$2,358
201–500 (per add’l 100)+ S$5,680——
501+ (per add’l 100)+ S$5,860——
Cloud security
End-pointsFeeFundingYou pay
1–10S$1,480S$1,036S$444
11–20S$1,780S$1,246S$534
21–50S$2,080S$1,456S$624
51–100S$2,380S$1,666S$714
101–200S$3,680S$2,576S$1,104
201–500 (per add’l 100)+ S$1,980——
501+ (per add’l 100)+ S$1,780——
OT security
End-pointsFeeFundingYou pay
1–10S$1,380S$966S$414
11–20S$2,680S$1,876S$804
21–50S$3,680S$2,576S$1,104
51–100S$5,860S$4,102S$1,758
101–200S$7,860S$5,502S$2,358
201–500 (per add’l 100)+ S$5,680——
501+ (per add’l 100)+ S$5,860——
OT security
End-pointsFeeFundingYou pay
1–10S$1,480S$1,036S$444
11–20S$1,780S$1,246S$534
21–50S$2,080S$1,456S$624
51–100S$2,380S$1,666S$714
101–200S$3,680S$2,576S$1,104
201–500 (per add’l 100)+ S$1,980——
501+ (per add’l 100)+ S$1,780——
AI security
End-pointsFeeFundingYou pay
1–10S$1,380S$966S$414
11–20S$2,680S$1,876S$804
21–50S$3,680S$2,576S$1,104
51–100S$5,860S$4,102S$1,758
101–200S$7,860S$5,502S$2,358
201–500 (per add’l 100)+ S$5,680——
501+ (per add’l 100)+ S$5,860——
AI security

Cyber Trust add-ons are arranged with Insyghts after sign-up.

SGD. Cloud, OT and AI security are add-ons over and above classical cybersecurity. Retainers shown are for classical cybersecurity; add-on retainers are extra. Funding covers the first 200 end-points only and is subject to CSA and IMDA eligibility and approval. Retainers receive no funding. Above 200 end-points, fees are per additional 100 end-points. Source: CSA CISOaaS (Cyber Trust) provider listing, 31 July 2026.

VAPT

Services

End-pointsFeeFundingYou pay
1–10S$1,300S$910S$390
11–20S$1,500S$1,050S$450
21–50S$2,000S$1,400S$600
51–100S$3,000S$2,100S$900
101–200S$5,000S$3,500S$1,500
201–500 (per add’l 100)+ S$3,000——
501+ (per add’l 100)+ S$3,000——
VA · network
End-pointsFeeFundingYou pay
1–10S$1,400S$980S$420
11–20S$1,600S$1,120S$480
21–50S$2,200S$1,540S$660
51–100S$3,200S$2,240S$960
101–200S$5,200S$3,640S$1,560
201–500 (per add’l 100)+ S$3,200——
501+ (per add’l 100)+ S$3,200——
VA · web app
End-pointsFeeFundingYou pay
1–10S$1,400S$980S$420
11–20S$1,600S$1,120S$480
21–50S$2,200S$1,540S$660
51–100S$3,200S$2,240S$960
101–200S$5,200S$3,640S$1,560
201–500 (per add’l 100)+ S$3,200——
501+ (per add’l 100)+ S$3,200——
VA · mobile app
End-pointsFeeFundingYou pay
1–10S$1,600S$1,120S$480
11–20S$2,800S$1,960S$840
21–50S$6,000S$2,624S$3,376
51–100S$8,000S$3,677S$4,323
101–200S$10,000S$5,015S$4,985
201–500 (per add’l 100)+ S$2,800——
501+ (per add’l 100)+ S$2,800——
PT · network
End-pointsFeeFundingYou pay
1–10S$1,600S$1,120S$480
11–20S$3,200S$1,980S$1,220
21–50S$7,000S$2,624S$4,376
51–100S$9,600S$3,677S$5,923
101–200S$12,000S$5,015S$6,985
201–500 (per add’l 100)+ S$3,200——
501+ (per add’l 100)+ S$3,200——
PT · web app
End-pointsFeeFundingYou pay
1–10S$1,600S$1,120S$480
11–20S$3,200S$1,980S$1,220
21–50S$7,000S$2,624S$4,376
51–100S$9,600S$3,677S$5,923
101–200S$12,000S$5,015S$6,985
201–500 (per add’l 100)+ S$3,200——
501+ (per add’l 100)+ S$3,200——
PT · mobile app

Select at least one service.

SGD. VA and PT are priced per network, per 10 dynamic pages per web app, and per mobile app. Delivered by a CSA-licensed penetration testing provider. Funding covers the first 200 end-points only and is subject to CSA and IMDA eligibility and approval. Above 200 end-points, fees are per additional 100 end-points. Source: CSA CISOaaS (VAPT Service) provider listing, 31 July 2026.

Incident response

NOT CURRENTLY FUNDED

Incident response retainer

Standby support when a cybersecurity incident hits. Same rates for 1 to 200 end-points.

From

S$160 / month

  • Per man-hour, activated within 8×5 S$130
  • Per man-hour, activated outside 8×5 S$180
  • Monthly retainer, 8×5 S$160
  • Monthly retainer, 24×7 S$240
  • Above 200 end-points, per add’l 100 (8×5 / 24×7) S$260 / S$340

SGD. CSA currently offers no funding for incident response services. Source: CSA CISOaaS (IR Service) provider listing, 31 July 2026.

Find Insyghts on SMEs Go Digital ↗

Resources

Tools to check where you stand.

Start with a quick look at your exposure or readiness.

Isometric illustration: blocks on a platform under a magnifier

Stage 01 · Just starting

Domain scan

Understand your exposure.

Coming soon

Isometric illustration: a checklist with three ticked items under a shield

Stage 02 · Getting compliant

Cyber Essentials readiness assessment

See how close you are to certification.

Coming soon

Isometric illustration: buildings on a platform scanned by a radar

Stage 04 · Mature, want to improve

Attack surface assessment

Find and close gaps.

Coming soon

Flowing cyan and blue ribbon artwork

Where does your governance need to go next?

Tell us your target framework or challenge, and we’ll suggest a starting point.

Enquiry