ADVERTISEMENT

Kaspersky survey finds 86% of SMBs hit by cyber incidents

Kaspersky survey finds 86% of SMBs hit by cyber incidents

ISLAMABAD: Eighty-six percent of small and medium-sized businesses (SMBs) surveyed globally said they experienced at least one cyber incident over the past year, according to a new survey released by cybersecurity company Kaspersky.

The findings highlight the growing exposure of smaller businesses to cyber threats, including phishing, software and web application exploits, malware, ransomware, external remote access attacks and attacks targeting artificial intelligence vulnerabilities.

Financial losses and data theft among major impacts

Financial loss was among the leading consequences of the most damaging cyber incidents, cited by 22% of respondents.

Other reported impacts included the theft of customer data, temporary disruption to client-facing services such as websites and online stores, loss of control over IT infrastructure and disruption to business processes.

The survey also found that attackers frequently targeted data that could have financial or operational value. Customer data was identified as the most frequently targeted information, cited by 32% of respondents.

Sensitive internal information, including financial credentials and legal documents, was targeted in 28% of cases, while employee credentials and business strategy were cited by 25% and 23% of respondents respectively.

IT teams remain primary targets

IT and IT security departments were the most frequently affected areas during the most harmful incidents. Half of respondents said attacks targeted IT departments, while 46% reported attacks against IT security teams.

Accounting and finance departments were the third most targeted, with 24% of respondents reporting incidents affecting these functions.

On average, three departments were compromised simultaneously during the most severe incidents, according to the survey.

SMBs also reported a comparatively higher incidence of attacks through customer service channels. The figure stood at 21%, compared with 15% among mid-market organizations and 17% among large enterprises.

Businesses strengthen cybersecurity measures

The reported incidents have prompted organizations to introduce additional security measures across technology, processes and staff training.

IT security monitoring solutions were the leading priority, cited by 24% of respondents. Hardening third-party compliance requirements and improving credential management practices were each identified by 23%.

Meanwhile, 22% of organizations said they were deploying security software across employee devices, while the same proportion reported investing in specialized training to strengthen the expertise of IT staff.

Ilya Markelov, Head of Unified Platform Product Line at Kaspersky, said cyber incidents could have particularly serious consequences for smaller companies because of their limited resources.

He said SMBs need scalable security measures that can address a range of threats while adapting to changing business requirements.

Cyber governance expert Asad Ur Rehman said cybersecurity risks were increasingly relevant to Pakistani SMBs because many handle customer and financial information while operating with limited security resources.

He said businesses should consider cybersecurity as part of broader business resilience, particularly in protecting customer trust and maintaining operational continuity.

Kaspersky recommends that SMBs select security measures based on their size, budget and industry requirements. The company also highlighted endpoint protection, security awareness training and simulated phishing exercises as measures businesses can use to strengthen employee security practices.

For organizations requiring broader security capabilities, Kaspersky also promotes its Kaspersky Next Optimum offering, while its Automated Security Awareness Platform provides online training and simulated phishing campaigns.