Kaspersky Warns: Cybercriminals Target SMBs with Enterprise-Grade Attack Tactics
Global cybersecurity leader Kaspersky has warned that cybercriminals are increasingly employing the same sophisticated attack methods against Small and Medium-sized Businesses (SMBs) as they do against large corporations. A recent global survey by the company revealed that only 14% of businesses with 100 to 499 employees successfully avoided cyber incidents over the past year. This figure stands slightly higher at 18% in the Middle East, Turkiye, and Africa (META) region.
Leading Threats and Security Incidents
Survey results indicate that organizations faced an average of three different security incidents last year. The threat landscape in the META region closely mirrored global trends:
Phishing and Vulnerability Exploitation: Encountered by 19% of organizations.
Credential Compromise: 18% of SMBs suffered breaches due to weak or stolen login credentials.
External Remote Access: Targeted 16% of businesses.
Zero-Day Exploits: While traditionally aimed at enterprises, 8% of global SMBs faced these severe, highly targeted attacks.
Internal Factors Enabling Attacks
Respondents from the META region attributed the increasing success rate of cyberattacks to human and administrative vulnerabilities:
Lack of Expertise and Inadequate Policies: Ranked as the top contributing factors, cited by 25% of respondents each.
High Workloads: 24% highlighted excessive pressure on IT departments.
Shadow IT: 23% struggled with a lack of centralized control over IT infrastructure.
Weak Security Awareness: 22% pointed to a lack of cybersecurity awareness among non-technical staff and business decisions being made without security considerations.
Future Investments and Mitigation Strategies
To combat these escalating threats, the vast majority of SMBs are taking proactive steps this year:
Budget Increases: 75% of global SMBs (70% in META) plan to increase their cybersecurity budgets.
Team Expansion: 36% of META companies have allocated additional funds to hire more IT and security professionals.
Staff Training: 32% of regional businesses are investing in comprehensive security training programs for their employees.
Advanced Technologies: 24% of META organizations plan to transition to sophisticated security solutions, including Extended Detection and Response (XDR), Security Information and Event Management (SIEM), and Network Detection and Response (NDR).
Would you like to emphasize a specific region or add any executive quotes to this press release?












