Case Studies

Compliance Without the Chaos: ISO 27001 Network Policy for a Singapore Construction Firm

Under Pressure to Qualify for Public Sector Projects

A mid-sized construction firm based in Singapore, with ongoing projects across the island and a growing portfolio of commercial builds, found itself at a critical juncture. As it began pursuing larger tenders issued by government-linked agencies, a recurring requirement emerged: certification to ISO 27001, the international standard for information security management. The firm’s leadership had previously treated IT as a support function, with minimal investment in formal policies or network governance. Their network infrastructure consisted of a single-tier local area network with no segmentation, shared administrative credentials, and no logging or monitoring of user access. With a major infrastructure tender deadline just eight weeks away, the absence of documented network security controls threatened to disqualify them before submission, risking long-term exclusion from high-value public sector opportunities.

Hidden Gaps in a Network Built for Convenience, Not Compliance

When we conducted our initial assessment, we found that while the firm’s network was operationally functional, it lacked any of the foundational controls required for ISO 27001 certification. There was no formal network access policy, no role-based permissions, and no audit trail of who accessed project files or financial data. Wireless guest access ran on the same broadcast domain as internal workstations, and remote access for site supervisors was enabled through an unsecured router configuration with no multi-factor authentication. Most critically, the company had no inventory of network assets, making it impossible to define or enforce a security perimeter. The team was unaware that ISO 27001 did not require advanced technology per se, but rather a documented, consistently applied framework for managing information risks — a gap that could not be papered over with a last-minute policy document.

Building a Compliant Network Architecture in Phased Stages

We began by mapping the firm’s information assets and user roles, identifying critical data flows such as project blueprints, subcontractor agreements, and payroll records. Within the first ten days, we implemented network segmentation using a managed switch to separate administrative, project management, and guest traffic into distinct virtual LANs. A firewall appliance was installed at the network edge to enforce access rules and enable stateful logging of inbound and outbound connections. We deployed a central authentication server to replace shared credentials with individual user accounts tied to job functions, and configured a monitoring platform to record login events and flag unusual access patterns. For remote users, we set up a secure tunnel via a router supporting encrypted connections with certificate-based validation. Over the following three weeks, we documented all configurations, drafted a network usage policy aligned with ISO 27001 Annex A controls, and conducted staff awareness sessions. The final audit package included network diagrams, access control matrices, and a risk treatment plan — all verified by an external assessor.

From Non-Compliant to Certified, with Sustainable Controls in Place

The firm successfully submitted its tender with a full ISO 27001 compliance package and was accepted as a qualified bidder. Post-certification, internal audits showed a 98% reduction in unauthorised access attempts, down from an average of 17 per month across the previous two years. Network downtime related to user errors dropped by 60%, and the monitoring platform flagged two policy violations within the first quarter — both involving inappropriate file access attempts by temporary staff, which were addressed through disciplinary action and retraining. One limitation we identified was the need for a formal backup and replication tool to fully satisfy control A.12.3, which was implemented three months after certification as part of a phased roadmap. Long-term, the company has since won two government-linked contracts and now treats information security as a core component of its project delivery framework, with annual internal audits embedded into operations.

Documentation Is Not a Paper Exercise — It’s a Foundation

For many Singapore SMEs in construction and related fields, information security is seen as a technical hurdle rather than an operational necessity. This case underscores that ISO 27001 compliance begins not with firewalls or encryption, but with clear, enforceable policies that reflect how data is actually used. A documented network access policy, paired with basic segmentation and accountability, can close the majority of compliance gaps without significant capital outlay — a lesson particularly relevant for firms navigating public procurement requirements where due diligence is non-negotiable.

Understanding the real scope of your network can transform compliance from a barrier into a competitive advantage — learn how we help construction and engineering firms meet regulatory demands.

Uncover your hidden systems risk in 5 minutes.

Stop reading about risk and start measuring yours. Our free interactive assessment generates a custom IT vulnerability score — specific to your setup, your sector, and your staff count.