The illusion that small and mid-sized businesses (SMBs) can fly under the radar of cybercriminals is becoming obsolete.

Kaspersky warns that attackers are deploying the same methods against smaller businesses as they do against large enterprises.

To help strengthen corporate defences, Kaspersky is releasing new recommendations alongside findings from a global survey by its Internal Research Center, which found that just 14% of businesses globally with 100 to 499 employees avoided a cyber incident in the past year. The figure is 23% in South Africa.

As smaller organisations digitalise, and the cost of launching cyberattacks plummets, threat actors are increasingly shifting their focus toward growth-stage companies, weaponising emerging technologies and exploiting all possible cybersecurity gaps.

The study reveals that, on average, organisations experienced three different types of security incidents over the past year. Globally for SMBs, phishing (20%), software vulnerability exploitation (17%) and external remote access (16%) top the list of the most frequently encountered breaches. Even though zero-day exploits and trusted relationship attacks ranked lowest, each of these extremely dangerous attacks was still encountered by 8% of organisations.

While incident distribution was similar across all business sizes, threats like mass malware, ransomware, BEC (Business email compromise), and AI vulnerability exploits were more prevalent in large enterprises.

In South Africa, the top categories of incidents in SMBs were: Social engineering, encountered by 23% of organisations, followed by phishing, the use of weak or stolen credentials and business email compromise (BEC), all encountered by 18% of organisations, and software vulnerability exploitation experienced by 15% of organisations.

Respondents were also asked to select the top five factors that elevate the risk of successful cyberattacks in organisations. The two most frequently chosen factors by SMBs globally were people-related: lack of expertise among IT security staff (24%) and a lack of security awareness among non-IT employees (23%).

Additionally, more than one-fifth of respondents selected insufficient IT security policies (21%), outdated software and hardware (21%) and high workload of IT security departments (20%) as key issues.

In South Africa, outdated software or hardware and Shadow IT (unauthorised software, apps and services usage) were ranked top by SMBs (30% named both categories), followed by a lack of IT security awareness among employees (28%). Other categories that were often mentioned included a high workload on the IT/IT security department (25%), insufficient IT security policies such as rare password changes, back-ups, etc (25%) and a lack of regular risk assessments (25%).

To address rising threats and internal challenges, most SMB companies plan to enhance their IT security function (70% globally, 85% in South Africa), and 75% globally (85% in South Africa) have already increased their cybersecurity budgets this year. 41% globally (32% in South Africa) allocated additional funds to expand their IT and IT security teams, 32% globally (35% in South Africa) allocated budget to introduce new IT security trainings for employees, and 30% globally (24% in South Africa) did so to migrate to advanced IT security solutions such as XDR, NDR, and SIEM.

“The current reality when companies of all sizes can be targeted with all possible methods urges business to reconsider their security posture. Sophisticated attacks easily bypass fragmented defences, requiring advanced tools and a skilled team to counter them. However, growing companies are often held back by budget constraints and the global InfoSec talent shortage,” says Ilya Markelov, head of unified platform product line at Kaspersky.

“That is why modern cybersecurity solutions must deliver more with less. Instead of introducing complex new tools that demand hard-to-find, expensive expertise, vendors should focus on cutting complexity. When designing our products for SMBs, our goal is to provide advanced protection that is easy to adopt, simple to manage, and able to grow alongside the business, helping organisations strengthen their security without adding unnecessary complexity or stretching their budget.”