Kaspersky warns that attackers are currently deploying the same methods against smaller businesses as they do against large enterprises. To help strengthen corporate defences, Kaspersky is releasing new recommendations alongside findings from a global survey by its Internal Research Center, which found that just 14% of businesses with fewer than 500 employees avoided a cyber incident in the past year.
The illusion that small and mid-sized businesses (SMBs) can fly under the radar of cybercriminals is becoming obsolete. As smaller organizations digitalize, and the cost of launching cyberattacks plummets, threat actors are increasingly shifting their focus toward growth-stage companies, weaponizing emerging technologies and exploiting all possible cybersecurity gaps.
Kaspersky, a global cybersecurity and digital privacy company, surveyed IT security specialists across SMBs and enterprises in 18 countries[1] to provide insights into the most critical risks facing businesses today.
The study reveals that, on average, organizations experienced three different types of security incidents over the past year. For SMBs, phishing (20%), software vulnerability exploitation (17%) and external remote access (16%) top the list of the most frequently encountered breaches. Even though zero-day exploits and trusted relationship attacks ranked lowest, each of these extremely dangerous attacks was still encountered by 8% of organizations.
While incident distribution was similar across all business sizes, threats like mass malware, ransomware, BEC (Business email compromise), and AI vulnerability exploits were slightly more prevalent in companies with over 500 employees.
Global study conducted by
Kaspersky’s Internal Research Center: which incidents did your organization
face over the past year? (Multiple choice)
Respondents were also asked to select the top five factors that elevate the risk of successful cyberattacks in organizations. The two most frequently chosen factors by SMBs were people-related: lack of expertise among IT security staff (24%) and a lack of security awareness among non-IT employees (23%). Additionally, more than one-fifth of respondents selected insufficient IT security policies (21%), outdated software and hardware (21%) and high workload of IT security departments (20%) as key issues.
To address rising threats and internal challenges, most companies plan to enhance their IT security function (70%), and 75% of SMBs have already increased their cybersecurity budgets this year. Almost half (41%) allocated additional funds to expand their IT and IT security teams, while nearly one-third (30%) did so to migrate to advanced IT security solutions such as XDR, NDR, and SIEM.
“The current reality when companies of all sizes can be targeted with all possible methods urges business to reconsider their security posture. Sophisticated attacks easily bypass fragmented defenses, requiring advanced tools and a skilled team to counter them. However, growing companies are often held back by budget constraints and the global InfoSec talent shortage,” says Ilya Markelov, Head of Unified Platform Product Line at Kaspersky. “That is why modern cybersecurity solutions must deliver more with less. Instead of introducing complex new tools that demand hard-to-find, expensive expertise, vendors should focus on cutting complexity. When designing our products for SMBs, our goal is to provide advanced protection that is easy to adopt, simple to manage, and able to grow alongside the business, helping organizations strengthen their security without adding unnecessary complexity or stretching their budget”.
“As a company that helps clients adopt a security maturity model to navigate current digital trends, we see that the cyber challenge is intensifying. Attackers increasingly leverage on artificial intelligence, driving up both the volume and complexity of today's threats. Also, credential protection has become paramount as attackers exploit security gaps to harvest high-value logins for targeted attacks that disrupt business operations or cause data theft. Consequently, raising importance of educating non-technical users who remain one of the weakest links,” comments Maximiliano Allo, Director at Custom IT[2]. “Kaspersky offers a wide range of suites, enabling companies with smaller budgets or limited staff to effectively counter these threats. Their SMB suites feature robust automation and a centralized management console, delivering enterprise-grade security without requiring significant time investments.”
To protect against emerging threats, Kaspersky provides the following recommendations for small and medium businesses:
Establish internal processes: implement strict access rules for all corporate resources and cloud services, ensuring IT promptly revokes permissions during employee offboarding. Second, integrate automated data backups into daily operations to secure critical information against emergencies and ransomware. Finally, back these technical controls with continuous human risk management: simplify cybersecurity guidelines for safe browsing and password hygiene and require IT approval for all new software. These actions will allow to minimize related cyber incidents such as insider threats, use of weak or stolen credentials and exploitation of lost or stolen IT assets.
Protect your people: Conduct dedicated training to teach staff how to detect and address potential threats, including deepfakes and vishing and track their educational progress. Organizations can achieve this with the Kaspersky Automated Security Awareness Platform through interactive online modules and simulated phishing campaigns that build sustainable cyber hygiene habits across all teams.
Choose the right technology defenses: Implement specialized cybersecurity solutions that fit your budget, size, and industry requirements, with an emphasis on efficiency, versatility, convenience of use and scalability.
- Kaspersky Small Office Security Premium is a great choice for micro-businesses below 50 employees. It is an easy-to-use solution that protects against advanced threats, including malware and ransomware, provides digital hygiene tools such as password management and data backup and even includes security awareness training for employees.
- Companies with more mature IT expertise should consider Kaspersky Next Optimum, which provides robust real-time prevention, threat visibility, as well as advanced detection and response capabilities with Next EDR and XDR Optimum. Organizations that need additional expertise without expanding their in-house security team can choose Kaspersky Next MXDR Optimum, combining XDR capabilities with continuous monitoring, expert threat analysis and incident response guidance delivered by Kaspersky analysts.
- Protect your business against email-borne threats, such as phishing, business email compromise, invoice payment fraud, etc. Kaspersky Security for Mail Server, a comprehensive email security platform that offers robust, multi-layered protection at mailbox and gateway levels, can help with this. Powered by machine learning and leading global threat intelligence, it effectively addresses all mail security challenges.
[1] 1800 interviews were conducted globally with representation across 18 countries: Brazil, Mexico, Colombia, France, Germany, Italy, Spain, India, Indonesia, Malaysia, China, Thailand, Vietnam, Egypt, South Africa, Saudi Arabia, Turkey, Russia.
[2] Custom IT S.A. - IT services and cybersecurity consulting firm based in Buenos Aires, Argentina.
·