In its latest global survey of SMBs, Kaspersky has highlighted the motives of threat actors, warned about the damaging consequences of cyberattacks, and underscored the growing need for advanced and purpose-built protection.

According to a poll of IT and IT security professionals in the SMB sector, an overwhelming 86% of respondents globally – and 78% in South Africa – stated they had experienced at least one cyber incident in the last year. Among them, the top threats cited as the most damaging were phishing attacks, software and Web application exploits, mass malware, ransomware, external remote access, and attacks targeting AI vulnerabilities.

Financial loss emerged as one of the leading consequences of the most harmful incident, cited by 22% of respondents globally and 16% in South Africa. Other major impacts affecting companies included: theft of customer data, temporary disruption to client-facing services like websites and online stores, loss of control over IT infrastructure, and general business process disruption.

Respondents indicated that, beyond the immediate financial impact, attackers focused heavily on data theft.

The most frequently targeted information included clients’ data (32% globally and 35% in South Africa), sensitive internal information such as financial credentials, legal documents, etc. (28% globally and 23% in South Africa), employees’ credentials (25% globally and 29% in South Africa), and the organisation’s business strategy (23% globally). This pattern reflects a strategic shift toward extracting valuable data that can be monetised or leveraged for further attacks.

The data shows that cybercriminals concentrate their efforts on IT and IT‑security teams, with 50% globally (48% in South Africa) of the most harmful attacks directed at IT and 46% globally (32% in South Africa) at IT‑security departments. Accounting and finance departments were the third most targeted area (24% globally and 26% in South Africa).

On average, globally, three departments were compromised simultaneously during the most severe incidents. Notably, SMBs experience a higher incidence of attacks through customer‑service channels (21%) compared with mid‑market (15%) and large enterprises (17%).

Recent breaches have compelled companies to implement additional cybersecurity measures across processes, people, and technologies.

The top priority globally is deploying IT security monitoring solutions (24%), followed by hardening third-party compliance requirements (23%), and upgrading credential management practices (23%). An almost equal share of organisations focused on deploying security software across all employee devices and investing in specialised training to boost IT staff expertise (22%). In South Africa, the top priority is the implementation/update of IT security compliance requirements for partners and contractors (32%), followed by the installation/update of IT security solutions on all employees’ corporate/personal devices (29%), and the introduction of multi-factor authentication (29%).

“Cyber incidents often inflict far more devastating consequences on small and medium-sized companies than high-profile breaches do on large corporations,” says Ilya Markelov, head of Unified Platform Product Line at Kaspersky. “Sometimes, it can threaten the very survival of these resource-constrained businesses. Faced with diverse and intense threats, operational constraints, and specific growth objectives, SMBs urgently need scalable, purpose-built protection.

“Kaspersky Next Optimum, our flagship offering for this segment, is engineered to bring expert and flexible security within reach for growing businesses,” Markelov says. “With the new suite of customisable, add-on Security Modules, users can further extend capabilities of its core products and strengthen defences as new needs or challenges evolve.”