Cyberthreats aimed at businesses vary greatly from malware to trusted relationship attacks. Malware categories that saw the sharpest annual increase over the past year, according to Kaspersky statistics, are spyware (detections rose by 16% in Africa), password stealer attacks (increased by 51% in Africa), and backdoor detections (rose by 23% in Africa). These types of malware are commonly used to infiltrate corporate environments, steal confidential information, establish persistent access, and facilitate subsequent stages of targeted attacks. Exploits also remain a major issue for businesses.
Overall, Kaspersky security tools blocked more than 1.6 million online attack attempts on users in Nigeria in the first half of 2026, including malware attacks by password stealers, exploits, spyware, etc. Another 2.5 million on-device threats were blocked in Nigeria, including malware delivered via infected USB drives.
The illusion that small and mid-sized businesses (SMBs) can fly under the radar of cybercriminals and from such attacks is becoming obsolete. As smaller organisations digitalise, and the cost of launching cyberattacks plummets, threat actors are increasingly shifting their focus toward growth-stage companies, weaponising emerging technologies (https://apo-opa.co/4qIj3Qg) and exploiting all possible cybersecurity gaps.
Kaspersky, a global cybersecurity and digital privacy company, surveyed IT security specialists across SMBs and enterprises in 18 countries* to provide insights into the most critical risks facing businesses today.
The study reveals that, on average, organisations experienced three different types of security incidents over the past year. Globally for SMBs, phishing (20%), software vulnerability exploitation (17%) and external remote access (16%) top the list of the most frequently encountered breaches. Even though zero-day exploits and trusted relationship attacks ranked lowest, each of these extremely dangerous attacks was still encountered by 8% of organisations. While incident distribution was similar across all business sizes, threats like mass malware, ransomware, BEC (Business email compromise), and AI vulnerability exploits were more prevalent in large enterprises.
In the META region, the top categories of incidents in SMBs were similar to global statistics: phishing and software vulnerability exploits were encountered by 19% of organisations, followed by the use of weak or stolen credentials (18%) and external remote access (16%).
Respondents were also asked to select the top five factors that elevate the risk of successful cyberattacks in organisations. Globally, the two most frequently chosen factors by SMBs were people-related: lack of expertise among IT security staff (24%) and a lack of security awareness among non-IT employees (23%). Additionally, more than one-fifth of respondents selected insufficient IT security policies (21%), outdated software and hardware (21%) and high workload of IT security departments (20%) as key issues.
In the META region, insufficient expertise among IT staff and insufficient IT security policies were ranked top by SMBs (25% named both categories), followed by high workload on IT security departments (24%). Other categories that were often mentioned are a lack of centralised control over IT infrastructure and shadow IT (23%) and a lack of IT security awareness among employees as well as business decisions made without taking IT security into account – 22%.
To address rising threats and internal challenges, most SMB companies plan to enhance their IT security function (70% globally, 69% in the META region), and 75% globally (70% in META) have already increased their cybersecurity budgets this year. 41% globally (36% in META) allocated additional funds to expand their IT and IT security teams, 32% globally (32% in META) allocated budget to introduce new IT security trainings for employees, and 30% globally (24% in META) did so to migrate to advanced IT security solutions such as XDR, NDR, and SIEM.
“The current reality when companies of all sizes can be targeted with all possible methods urges business to reconsider their security posture. Sophisticated attacks easily bypass fragmented defences, requiring advanced tools and a skilled team to counter them. However, growing companies are often held back by budget constraints and the global InfoSec talent shortage,” says Ilya Markelov, Head of Unified Platform Product Line at Kaspersky. “That is why modern cybersecurity solutions must deliver more with less. Instead of introducing complex new tools that demand hard-to-find, expensive expertise, vendors should focus on cutting complexity. When designing our products for SMBs, our goal is to provide advanced protection that is easy to adopt, simple to manage, and able to grow alongside the business, helping organisations strengthen their security without adding unnecessary complexity or stretching their budget”.
To protect against emerging threats, Kaspersky provides the following recommendations for small and medium businesses:
Visit Kaspersky on the expo days of GITEX Nigeria on 2-3 September at the Convention Center in Lagos, at stand B10 in Hall 2.
Distributed by APO Group on behalf of Kaspersky.
About Kaspersky:
Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date. Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support. Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.Kaspersky.co.za.
This website uses cookies.