{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,29]],"date-time":"2026-07-29T14:10:45Z","timestamp":1785334245732,"version":"3.55.0"},"posted":{"date-parts":[[2026]]},"group-title":"SSRN","reference-count":0,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"unspecified","delay-in-days":0,"URL":"https:\/\/www.uspto.gov\/ip-policy\/copyright-policy\/copyright-basics"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"abstract":"<jats:p>Singapore's data-breach enforcement is anchored by two instruments: the Personal Data Protection Act, enforced through published Commission's Decisions and Voluntary Undertakings, and the Cyber Security Agency's Cyber Essentials mark, a baseline certification for resourceconstrained organisations. This note asks how completely the Cyber Essentials baseline maps onto the security failures that the Personal Data Protection Commission actually identifies when it takes enforcement action. I code 34 published enforcement actions from 2019 to 2026-26 Commission's Decisions and 8 Voluntary Undertakings, kept as separate strata-against the five Cyber Essentials categories, using only the failures the Commission expressly stated. Cyber Essentials controls address at least one stated failure in 28 of 34 actions (82%) but address every stated failure in only 13 (38%). A residual failure that no Cyber Essentials clause enumeratesprocess governance, vendor oversight, accountability, or wrongful disclosure-appears in 21 of 34 (62%), and in the formally adjudicated Commission's Decisions specifically, in 17 of 26 (65%). The pattern is consistent with a baseline that covers the technical-hygiene layer of enforced breaches well while leaving a governance residual that the Accountability Obligation, not certification, addresses. Access-control and process-governance failures are the two most frequently cited; backup is never cited, including across eleven ransomware cases.<\/jats:p>","DOI":"10.2139\/ssrn.6841562","type":"posted-content","created":{"date-parts":[[2026,7,29]],"date-time":"2026-07-29T13:40:09Z","timestamp":1785332409000},"source":"Crossref","is-referenced-by-count":0,"title":["Technical Baseline, Governance Gap: Singapore Data-Breach Enforcement and the Cyber Essentials Mark"],"prefix":"10.2139","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-8477-9393","authenticated-orcid":true,"given":"Boon Chuan","family":"Lim","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","container-title":[],"original-title":[],"deposited":{"date-parts":[[2026,7,29]],"date-time":"2026-07-29T13:40:10Z","timestamp":1785332410000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.ssrn.com\/abstract=6841562"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":0,"URL":"https:\/\/doi.org\/10.2139\/ssrn.6841562","relation":{},"subject":[],"published":{"date-parts":[[2026]]},"subtype":"preprint"}}