Follow us on LinkedInfor the latest from Zavior
Zavior
For Business

Ransomware Is a Data Protection Issue: What Singapore DPOs Should Fix Before the Next Incident

When ransomware strikes, the damage is not limited to systems and downtime. Recent PDPC actions show that personal data exposure, access weakness and poor security review can quickly become a data protection issue.

By Glenn Tan · CEO at Zavior.ai

5 min readInsight
Ransomware Is a Data Protection Issue: What Singapore DPOs Should Fix Before the Next Incident

Many organisations still talk about ransomware as an IT disruption problem.

Systems go down. Files become unavailable. Operations slow. Recovery starts. The technical team takes the lead.

But recent cases in Singapore make something else clear: ransomware is also a data protection problem, especially when the attack exposes, exfiltrates, deletes or puts personal data at risk. That matters directly to Data Protection Officers, because the consequences are not only operational. They are regulatory, contractual and reputational.

Recent PDPC decisions and undertakings underline that point. In one announcement published in February 2026, PDPC said that approximately 39,000 individuals' personal data, including bank and credit card details, had been rendered inaccessible due to a ransomware attack. In the People Central case, the personal data of 95,000 employees and another 24,765 emergency contacts and children were put at risk of unauthorised access after an incident involving weak controls and insufficient security review.

The lesson for DPOs in Singapore is straightforward: you do not need to own cybersecurity operations to be accountable for data protection readiness. You do need to know where personal data sits, how it can be affected by a cyber incident, and whether the organisation's controls are proportionate to the data it holds.

Why ransomware belongs on the DPO agenda

A ransomware incident is rarely just encryption.

Modern attacks often involve a mix of unauthorised access, privilege escalation, exfiltration, extortion and disclosure threats. In practice, that means the DPO has to think beyond "can we restore systems?" and ask "what personal data was exposed, how quickly can we determine impact, and what evidence do we have of reasonable protection?"

This is particularly important for HR, finance, healthcare, education and SaaS environments where the data involved may include national identifiers, salary records, bank details, contact information and sensitive personal data.

That is why the recent Singapore cases matter. They show that even where organisations recover systems, regulators still look closely at whether the organisation had reasonable arrangements before the attack, not just how fast it responded after.

What recent cases are telling us

The People Central case is one of the clearest reminders for DPOs. The organisation was a cloud-based HR solutions provider. The affected data reportedly included NRIC numbers, salaries, bank account information, marital status, religion, addresses and more. The PDPC's findings pointed to weak access controls, lack of two-factor authentication for remote access, open exposure to the internet, and security testing that was far too infrequent for the risk profile involved.

This matters because HR data is exactly the kind of dataset that can create real harm if exposed. For a DPO, the issue is not only whether the system was breached. It is whether the organisation had elevated its controls in line with the sensitivity and volume of the personal data entrusted to it.

The same principle applies more broadly. If a business holds payroll data, patient information, customer statements or student records, it cannot rely on basic controls and occasional review. The bar rises with the data.

What DPOs should be asking now

Start with three questions.

First, if ransomware hit a critical system tomorrow, could the organisation quickly identify what personal data is in scope, by business unit, system and vendor?

Second, does the organisation have evidence that its controls are proportionate to the type of data involved? That includes MFA, access restrictions, logging, backup separation, vulnerability management, patching, and remote access safeguards.

Third, has the organisation already defined who leads the data protection side of a cyber incident? Many teams have incident runbooks, but not all of them clearly spell out when the DPO is engaged, how legal and communications are aligned, or how notification decisions are escalated.

The DPO's role before the breach

The most effective DPOs do not wait for the incident response call.

They work upstream with security, IT, operations and vendors to classify systems, map sensitive datasets, tighten retention, and reduce unnecessary exposure. They push for evidence rather than assumptions. They ask whether the backup strategy protects availability without creating new uncontrolled copies of personal data. They ask whether remote administration is restricted. They ask whether reviews happen after major system changes, not only once a year.

Just as important, they make sure the organisation can explain its reasoning. Why was a system exposed? Why was a certain control not implemented? Why was a vulnerability scan cadence considered acceptable? In enforcement, those questions matter.

A practical DPO checklist for ransomware readiness

  1. Review the highest-risk systems that contain payroll, finance, identity, health, student or customer account data.
  2. Confirm which systems and vendors hold personal data and whether the data map is current.
  3. Require evidence of MFA, remote access restrictions, logging, periodic vulnerability assessments, and restoration testing.
  4. Ensure backup and recovery arrangements are documented, tested, and aligned with personal data governance.
  5. Update incident response workflows so the DPO is engaged early in impact assessment, containment, notification and communications.

The real urgency

Ransomware is no longer a scenario that sits neatly in the technical corner of the business. It now sits at the intersection of cyber resilience, customer trust and regulatory accountability.

For Singapore DPOs, the practical implication is simple: if you oversee personal data governance, you also need visibility into the cyber controls that keep that data secure and recoverable. The next ransomware incident will not wait for a better time to test that readiness.

Key takeaways

  • Ransomware incidents often become data protection incidents when personal data is exposed, exfiltrated or rendered inaccessible.
  • PDPC expects controls to be proportionate to the volume and sensitivity of the data involved.
  • HR, payroll, finance and customer datasets deserve higher scrutiny and stronger evidence of protection.
  • DPOs should be part of cyber incident preparation, not only post-incident reporting.
  • The best time to define ownership, evidence and escalation paths is before the next breach.
Glenn Tan

Written by

Glenn Tan

CEO at Zavior.ai

Build Trust Through Certifications | Cyber Security | AI Governance | Data Protection

Share

Let us be your Zavior.

Zavior helps Singapore organizations build cyber resilience aligned to SG Cyber Safe, the PDPA, and ISO 27001.

Continue reading