Within GITEX Nigeria, taking place from 31 August to 3 September in Lagos, Kaspersky (www.Kaspersky.co.za), global cybersecurity and digital privacy company, warns that cyber attackers are currently deploying the same methods against small businesses as they do against large enterprises. To help strengthen corporate defences, Kaspersky is releasing recommendations alongside findings from a global survey by its Internal Research Center, which found that just 14% of businesses with 100 to 499 employees avoided a cyber incident in the past year. This figure is slightly higher in the Middle East, Turkiye and Africa (META) region at 18%.
Cyberthreats aimed at businesses vary greatly from malware to trusted relationship attacks. Malware categories that saw the sharpest annual increase over the past year, according to Kaspersky statistics, are spyware (detections rose by 16% in Africa), password stealer attacks (increased by 51% in Africa), and backdoor detections (rose by 23% in Africa). These types of malware are commonly used to infiltrate corporate environments, steal confidential information, establish persistent access, and facilitate subsequent stages of targeted attacks. Exploits also remain a major issue for businesses.
Overall, Kaspersky security tools blocked more than 1.6 million online attack attempts on users in Nigeria in the first half of 2026, including malware attacks by password stealers, exploits, spyware, etc. Another 2.5 million on-device threats were blocked in Nigeria, including malware delivered via infected USB drives.
The illusion that small and mid-sized businesses (SMBs) can fly under the radar of cybercriminals and from such attacks is becoming obsolete. As smaller organisations digitalise, and the cost of launching cyberattacks plummets, threat actors are increasingly shifting their focus toward growth-stage companies, weaponising emerging technologies (https://apo-opa.co/4qIj3Qg) and exploiting all possible cybersecurity gaps.
Kaspersky, a global cybersecurity and digital privacy company, surveyed IT security specialists across SMBs and enterprises in 18 countries* to provide insights into the most critical risks facing businesses today.
The study reveals that, on average, organisations experienced three different types of security incidents over the past year. Globally for SMBs, phishing (20%), software vulnerability exploitation (17%) and external remote access (16%) top the list of the most frequently encountered breaches. Even though zero-day exploits and trusted relationship attacks ranked lowest, each of these extremely dangerous attacks was still encountered by 8% of organisations. While incident distribution was similar across all business sizes, threats like mass malware, ransomware, BEC (Business email compromise), and AI vulnerability exploits were more prevalent in large enterprises.
In the META region, the top categories of incidents in SMBs were similar to global statistics: phishing and software vulnerability exploits were encountered by 19% of organisations, followed by the use of weak or stolen credentials (18%) and external remote access (16%).
Respondents were also asked to select the top five factors that elevate the risk of successful cyberattacks in organisations. Globally, the two most frequently chosen factors by SMBs were people-related: lack of expertise among IT security staff (24%) and a lack of security awareness among non-IT employees (23%). Additionally, more than one-fifth of respondents selected insufficient IT security policies (21%), outdated software and hardware (21%) and high workload of IT security departments (20%) as key issues.
In the META region, insufficient expertise among IT staff and insufficient IT security policies were ranked top by SMBs (25% named both categories), followed by high workload on IT security departments (24%). Other categories that were often mentioned are a lack of centralised control over IT infrastructure and shadow IT (23%) and a lack of IT security awareness among employees as well as business decisions made without taking IT security into account – 22%.
To address rising threats and internal challenges, most SMB companies plan to enhance their IT security function (70% globally, 69% in the META region), and 75% globally (70% in META) have already increased their cybersecurity budgets this year. 41% globally (36% in META) allocated additional funds to expand their IT and IT security teams, 32% globally (32% in META) allocated budget to introduce new IT security trainings for employees, and 30% globally (24% in META) did so to migrate to advanced IT security solutions such as XDR, NDR, and SIEM.
“The current reality when companies of all sizes can be targeted with all possible methods urges business to reconsider their security posture. Sophisticated attacks easily bypass fragmented defences, requiring advanced tools and a skilled team to counter them. However, growing companies are often held back by budget constraints and the global InfoSec talent shortage,” says Ilya Markelov, Head of Unified Platform Product Line at Kaspersky. “That is why modern cybersecurity solutions must deliver more with less. Instead of introducing complex new tools that demand hard-to-find, expensive expertise, vendors should focus on cutting complexity. When designing our products for SMBs, our goal is to provide advanced protection that is easy to adopt, simple to manage, and able to grow alongside the business, helping organisations strengthen their security without adding unnecessary complexity or stretching their budget”.
To protect against emerging threats, Kaspersky provides the following recommendations for small and medium businesses:
- Establish internal processes: implement strict access rules for all corporate resources and cloud services, ensuring IT promptly revokes permissions during employee offboarding. Integrate automated data backups into daily operations to secure critical information against emergencies and ransomware. Back these technical controls with continuous human risk management: simplify cybersecurity guidelines for safe browsing and password hygiene and require IT approval for all new software. These actions will allow to minimise related cyber incidents such as insider threats, use of weak or stolen credentials and exploitation of lost or stolen IT assets.
- Protect your people: Conduct dedicated training to teach staff how to detect and address potential threats, including deepfakes and vishing and track their educational progress. Organisations can achieve this with the Kaspersky Automated Security Awareness Platform (https://apo-opa.co/4gDrGai) through interactive online modules and simulated phishing campaigns that build sustainable cyber hygiene habits across all teams.
- Choose the right technology defences: Implement specialised cybersecurity solutions that fit your budget, size, and industry requirements, with an emphasis on efficiency, versatility, convenience of use and scalability.
- Kaspersky Small Office Security Premium (https://apo-opa.co/4wXmjJ0) is a great choice for micro-businesses below 50 employees. It is an easy-to-use solution that protects against advanced threats, including malware and ransomware, provides digital hygiene tools such as password management and data backup and even includes security awareness training for employees.
- Companies with more mature IT expertise should consider Kaspersky Next Optimum (https://apo-opa.co/4xpBvje), which provides robust real-time prevention, threat visibility, as well as advanced detection and response capabilities with Next EDR and XDR Optimum. Organisations that need additional expertise without expanding their in-house security team can choose Kaspersky Next MXDR Optimum, combining XDR capabilities with continuous monitoring, expert threat analysis and incident response guidance delivered by Kaspersky analysts.
- Protect your business against email-borne threats, such as phishing, business email compromise, invoice payment fraud, etc. Kaspersky Security for Mail Server (https://apo-opa.co/4cnHQDw), a comprehensive email security platform that offers robust, multi-layered protection at mailbox and gateway levels, can help with this. Powered by machine learning and leading global threat intelligence, it effectively addresses all mail security challenges.
Visit Kaspersky on the expo days of GITEX Nigeria on 2-3 September at the Convention Center in Lagos, at stand B10 in Hall 2.
Distributed by APO Group on behalf of Kaspersky.
About Kaspersky:
Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date. Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support. Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.Kaspersky.co.za.