A cybersecurity and digital privacy company, Kaspersky, has warned that cyber attackers are currently deploying the same methods against small businesses as they do against large enterprises.
It reported that 82 per cent of small and mid-sized businesses (SMBs) in the Middle East, Turkiye and Africa (META) region encountered cybersecurity incidents over the past year.
Further, through its Internal Research Centre, Kaspersky found that just 14 per cent of businesses with 100 to 499 employees avoided cyber incidents in the past year. This figure is slightly higher in the Middle East, Turkiye and Africa (META) region at 18 per cent.
Cyberthreats aimed at businesses vary greatly from malware to trusted relationship attacks. Malware categories that saw the sharpest yearly increase over the past year, according to Kaspersky statistics, are spyware (detections rose by 16 per cent in Africa), password stealer attacks (increased by 51 per cent in Africa), and backdoor detections (rose by 23 per cent in Africa).
These types of malware are commonly used to infiltrate corporate environments, steal confidential information, establish persistent access, and facilitate subsequent stages of targeted attacks. Exploits also remain a major issue for businesses.
Overall, Kaspersky security tools blocked more than 1.6 million online attack attempts on users in Nigeria in the first half of 2026, including malware attacks by password stealers, exploits, spyware, etc. Another 2.5 million on-device threats were blocked in Nigeria, including malware delivered via infected USB drives.
It observed that the illusion that small and mid-sized businesses (SMBs) can fly under the radar of cybercriminals and from such attacks is becoming obsolete. It stressed that as smaller organisations digitalise, and the cost of launching cyberattacks plummets, threat actors are increasingly shifting their focus toward growth-stage companies, weaponising emerging technologies and exploiting all possible cybersecurity gaps.
The study revealed that, on average, organisations experienced three different types of security incidents over the past year. Globally for SMBs, phishing (20 per cent), software vulnerability exploitation (17 per cent) and external remote access (16 per cent) top the list of the most frequently encountered breaches.
In the META region, insufficient expertise among IT staff and insufficient IT security policies were ranked top by SMBs (25 per cent named both categories), followed by high workload on IT security departments (24 per cent). Other categories that were often mentioned are a lack of centralised control over IT infrastructure and shadow IT (23 per cent) and a lack of IT security awareness among employees as well as business decisions made without taking IT security into account – 22 per cent.
To address rising threats and internal challenges, most SMB companies plan to enhance their IT security function (70 per cent globally, 69 per cent in the META region), and 75 per cent globally (70 per cent in META) have already increased their cybersecurity budgets this year. 41 per cent globally (36 per cent in META) allocated additional funds to expand their IT and IT security teams, 32 per cent globally (32 per cent in META) allocated budget to introduce new IT security trainings for employees, and 30 per cent globally (24 per cent in META) did so to migrate to advanced IT security solutions such as XDR, NDR, and SIEM.
Follow Us on Google News
Follow Us on Google Discover
