Close Menu
    Facebook X (Twitter) Instagram
    KSA News TodayKSA News Today
    Facebook X (Twitter) Instagram
    • KSA
    • Business
    • Technology
    • Sports
    • Lifestyle
    KSA News TodayKSA News Today
    • KSA
    • Business
    • Technology
    • Sports
    • Lifestyle
    • Contact us
    Technology

    82% of SMBs in the META region encountered cybersecurity incidents over the past year

    Editorial TeamBy Editorial TeamAugust 31, 2026
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Kaspersky warns that attackers are currently deploying the same methods against smaller businesses as they do against large enterprises. To help strengthen corporate defences, Kaspersky is releasing new recommendations alongside findings from a global survey by its Internal Research Center, which found that just 14% of businesses with 100 to 499 employees avoided a cyber incident in the past year. The figure is similar – 18% in the Middle East, Turkiye and Africa region.

    The illusion that small and mid-sized businesses (SMBs) can fly under the radar of cybercriminals is becoming obsolete. As smaller organisations digitalise, and the cost of launching cyberattacks plummets, threat actors are increasingly shifting their focus toward growth-stage companies, weaponising emerging technologies and exploiting all possible cybersecurity gaps.

    Kaspersky, a global cybersecurity and digital privacy company, surveyed IT security specialists across SMBs and enterprises in 18 countries* to provide insights into the most critical risks facing businesses today.

    The study reveals that, on average, organisations experienced three different types of security incidents over the past year. Globally for SMBs, phishing (20%), software vulnerability exploitation (17%) and external remote access (16%) top the list of the most frequently encountered breaches. Even though zero-day exploits and trusted relationship attacks ranked lowest, each of these extremely dangerous attacks was still encountered by 8% of organisations. While incident distribution was similar across all business sizes, threats like mass malware, ransomware, BEC (Business email compromise), and AI vulnerability exploits were more prevalent in large enterprises.

    In the Middle East, Turkiye and Africa (META region) the top categories of incidents in SMBs were similar to global statistics: phishing and software vulnerability exploits we encountered by 19% of organizations, followed by the use of weak or stolen credentials (18%) and external remote access (16%).

    Respondents were also asked to select the top five factors that elevate the risk of successful cyberattacks in organisations. The two most frequently chosen factors by SMBs were people-related: lack of expertise among IT security staff (24%) and a lack of security awareness among non-IT employees (23%). Additionally, more than one-fifth of respondents selected insufficient IT security policies (21%), outdated software and hardware (21%) and high workload of IT security departments (20%) as key issues.

    In META, insufficient expertise among IT staff similar to insufficient IT security politics were ranked top by SMBs (25% named both categories), followed by high workload on the IT (24%). Other categories that were often mentioned are lack of centralised control over IT infrastructure and shadow IT (23%) and lack of IT security awareness among employees as well as business decisions made without taking IT security into account – 22%.

    To address rising threats and internal challenges, most SMB companies plan to enhance their IT security function (70% globally, 69% in the META region), and 75% (70% in META) have already increased their cybersecurity budgets this year. 41% globally (36% in META) allocated additional funds to expand their IT and IT security teams, 32% (32% in META) allocated budget to introduce new IT security trainings for employees, and 30% globally (24% in META) did so to migrate to advanced IT security solutions such as XDR, NDR, and SIEM.

    “The current reality when companies of all sizes can be targeted with all possible methods urges business to reconsider their security posture. Sophisticated attacks easily bypass fragmented defences, requiring advanced tools and a skilled team to counter them. However, growing companies are often held back by budget constraints and the global InfoSec talent shortage”, says Ilya Markelov, Head of Unified Platform Product Line at Kaspersky. “That is why modern cybersecurity solutions must deliver more with less. Instead of introducing complex new tools that demand hard-to-find, expensive expertise, vendors should focus on cutting complexity. When designing our products for SMBs, our goal is to provide advanced protection that is easy to adopt, simple to manage, and able to grow alongside the business, helping organizations strengthen their security without adding unnecessary complexity or stretching their budget”.

    To protect against emerging threats, Kaspersky provides the following recommendations for small and medium businesses:

    1. Establish internal processes: implement strict access rules for all corporate resources and cloud services, ensuring IT promptly revokes permissions during employee offboarding. Integrate automated data backups into daily operations to secure critical information against emergencies and ransomware. Back these technical controls with continuous human risk management: simplify cybersecurity guidelines for safe browsing and password hygiene and require IT approval for all new software. These actions will allow to minimise related cyber incidents such as insider threats, use of weak or stolen credentials and exploitation of lost or stolen IT assets.
    2. Protect your people: Conduct dedicated training to teach staff how to detect and address potential threats, including deepfakes and vishing and track their educational progress. Organizations can achieve this with the Kaspersky Automated Security Awareness Platform through interactive online modules and simulated phishing campaigns that build sustainable cyber hygiene habits across all teams.
    3. Choose the right technology defences: Implement specialised cybersecurity solutions that fit your budget, size, and industry requirements, with an emphasis on efficiency, versatility, convenience of use and scalability.
    • Kaspersky Small Office Security Premium is a great choice for micro-businesses below 50 employees. It is an easy-to-use solution that protects against advanced threats, including malware and ransomware, provides digital hygiene tools such as password management and data backup and even includes security awareness training for employees.
    • Companies with more mature IT expertise should consider Kaspersky Next Optimum, which provides robust real-time prevention, threat visibility, as well as advanced detection and response capabilities with Next EDR and XDR Optimum. Organisations that need additional expertise without expanding their in-house security team can choose Kaspersky Next MXDR Optimum, combining XDR capabilities with continuous monitoring, expert threat analysis and incident response guidance delivered by Kaspersky analysts.
    • Protect your business against email-borne threats, such as phishing, business email compromise, invoice payment fraud, etc. Kaspersky Security for Mail Server, a comprehensive email security platform that offers robust, multi-layered protection at mailbox and gateway levels, can help with this. Powered by machine learning and leading global threat intelligence, it effectively addresses all mail security challenges.

    *1800 interviews were conducted globally with representation across 18 countries: Brazil, Mexico, Colombia, France, Germany, Italy, Spain, Russia, India, Indonesia, Malaysia, China, Thailand, Vietnam, Egypt, South Africa, Saudi Arabia, Türkiye.

    Image Credit: Kaspersky


    Source: Tahawul Tech

    Previous ArticleBeyond the Signal: How Zero-Failure Networks and Real-Time Event Management Are Securing the Future of Saudi Industries
    Next Article Prince Khalid, Asim Munir discuss strengthening Saudi-Pak defense cooperation

    Related Posts

    Building trustworthy agentic AI: How security concerns have changed in 2026

    August 31, 2026

    NetApp platform unveils AI-ready data, unified storage, proactive protection and complete control at LEAP 2026

    August 31, 2026

    Salam named strategic sponsor of LEAP 2026, unveils Connectivity+ solutions

    August 30, 2026
    Latest Posts

    Prince Khalid, Asim Munir discuss strengthening Saudi-Pak defense cooperation

    82% of SMBs in the META region encountered cybersecurity incidents over the past year

    Beyond the Signal: How Zero-Failure Networks and Real-Time Event Management Are Securing the Future of Saudi Industries

    Burj Khalifa or Sky Views Observatory? Two Ways to See Dubai From Above

    Latest News

    Building trustworthy agentic AI: How security concerns have changed in 2026

    August 31, 2026

    NetApp platform unveils AI-ready data, unified storage, proactive protection and complete control at LEAP 2026

    August 31, 2026

    Salam named strategic sponsor of LEAP 2026, unveils Connectivity+ solutions

    August 30, 2026
    Facebook X (Twitter) Instagram Pinterest
    • KSA
    • Business
    • Technology
    • Sports
    • Lifestyle
    • Contact us
    2026. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.