Skip to main content

78% of South African SMBs encountered cybersecurity incidents over the past year, Kaspersky research shows

31 August 2026

Kaspersky warns that attackers are currently deploying the same methods against smaller businesses as they do against large enterprises. To help strengthen corporate defences, Kaspersky is releasing new recommendations alongside findings from a global survey by its Internal Research Center, which found that just 14% of businesses globally with 100 to 499 employees avoided a cyber incident in the past year. The figure is 23% in South Africa.

The illusion that small and mid-sized businesses (SMBs) can fly under the radar of cybercriminals is becoming obsolete. As smaller organisations digitalise, and the cost of launching cyberattacks plummets, threat actors are increasingly shifting their focus toward growth-stage companies, weaponising emerging technologies and exploiting all possible cybersecurity gaps.

Kaspersky, a global cybersecurity and digital privacy company, surveyed IT security specialists across SMBs and enterprises in 18 countries* to provide insights into the most critical risks facing businesses today.

The study reveals that, on average, organisations experienced three different types of security incidents over the past year. Globally for SMBs, phishing (20%), software vulnerability exploitation (17%) and external remote access (16%) top the list of the most frequently encountered breaches. Even though zero-day exploits and trusted relationship attacks ranked lowest, each of these extremely dangerous attacks was still encountered by 8% of organisations. While incident distribution was similar across all business sizes, threats like mass malware, ransomware, BEC (Business email compromise), and AI vulnerability exploits were more prevalent in large enterprises.

In South Africa, the top categories of incidents in SMBs were: Social engineering, encountered by 23% of organisations, followed by phishing, the use of weak or stolen credentials and business email compromise (BEC), all encountered by 18% of organisations, and software vulnerability exploitation experienced by 15% of organisations.

Respondents were also asked to select the top five factors that elevate the risk of successful cyberattacks in organisations. The two most frequently chosen factors by SMBs globally were people-related: lack of expertise among IT security staff (24%) and a lack of security awareness among non-IT employees (23%). Additionally, more than one-fifth of respondents selected insufficient IT security policies (21%), outdated software and hardware (21%) and high workload of IT security departments (20%) as key issues. 

In South Africa, outdated software or hardware and Shadow IT (unauthorised software, apps and services usage) were ranked top by SMBs (30% named both categories), followed by a lack of IT security awareness among employees (28%). Other categories that were often mentioned included a high workload on the IT/IT security department (25%), insufficient IT security policies such as rare password changes, back-ups, etc (25%) and a lack of regular risk assessments (25%).

 

To address rising threats and internal challenges, most SMB companies plan to enhance their IT security function (70% globally, 85% in South Africa), and 75% globally (85% in South Africa) have already increased their cybersecurity budgets this year. 41% globally (32% in South Africa) allocated additional funds to expand their IT and IT security teams, 32% globally (35% in South Africa) allocated budget to introduce new IT security trainings for employees, and 30% globally (24% in South Africa) did so to migrate to advanced IT security solutions such as XDR, NDR, and SIEM.

“The current reality when companies of all sizes can be targeted with all possible methods urges business to reconsider their security posture. Sophisticated attacks easily bypass fragmented defences, requiring advanced tools and a skilled team to counter them. However, growing companies are often held back by budget constraints and the global InfoSec talent shortage,” says Ilya Markelov, Head of Unified Platform Product Line at Kaspersky. “That is why modern cybersecurity solutions must deliver more with less. Instead of introducing complex new tools that demand hard-to-find, expensive expertise, vendors should focus on cutting complexity. When designing our products for SMBs, our goal is to provide advanced protection that is easy to adopt, simple to manage, and able to grow alongside the business, helping organisations strengthen their security without adding unnecessary complexity or stretching their budget”.

To protect against emerging threats, Kaspersky provides the following recommendations for small and medium businesses:

  1. Establish internal processes: Implement strict access rules for all corporate resources and cloud services, ensuring IT promptly revokes permissions during employee offboarding. Integrate automated data backups into daily operations to secure critical information against emergencies and ransomware. Back these technical controls with continuous human risk management: simplify cybersecurity guidelines for safe browsing and password hygiene and require IT approval for all new software. These actions will allow to minimise related cyber incidents such as insider threats, use of weak or stolen credentials and exploitation of lost or stolen IT assets.
  2. Protect your people: Conduct dedicated training to teach staff how to detect and address potential threats, including deepfakes and vishing and track their educational progress. Organisations can achieve this with the Kaspersky Automated Security Awareness Platform through interactive online modules and simulated phishing campaigns that build sustainable cyber hygiene habits across all teams.
  3. Choose the right technology defences: Implement specialised cybersecurity solutions that fit your budget, size, and industry requirements, with an emphasis on efficiency, versatility, convenience of use and scalability.

·        Kaspersky Small Office Security Premium is a great choice for micro-businesses below 50 employees. It is an easy-to-use solution that protects against advanced threats, including malware and ransomware, provides digital hygiene tools such as password management and data backup and even includes security awareness training for employees.

·        Companies with more mature IT expertise should consider Kaspersky Next Optimum, which provides robust real-time prevention, threat visibility, as well as advanced detection and response capabilities with Next EDR and XDR Optimum. Organisations that need additional expertise without expanding their in-house security team can choose Kaspersky Next MXDR Optimum, combining XDR capabilities with continuous monitoring, expert threat analysis and incident response guidance delivered by Kaspersky analysts.

·        Protect your business against email-borne threats, such as phishing, business email compromise, invoice payment fraud, etc. Kaspersky Security for Mail Server, a comprehensive email security platform that offers robust, multi-layered protection at mailbox and gateway levels, can help with this. Powered by machine learning and leading global threat intelligence, it effectively addresses all mail security challenges. 

 

*1800 interviews were conducted globally with representation across 18 countries: Brazil, Mexico, Colombia, France, Germany, Italy, Spain, Russia, India, Indonesia, Malaysia, China, Thailand, Vietnam, Egypt, South Africa, Saudi Arabia, Turkey.

78% of South African SMBs encountered cybersecurity incidents over the past year, Kaspersky research shows

Kaspersky warns that attackers are currently deploying the same methods against smaller businesses as they do against large enterprises. To help strengthen corporate defences, Kaspersky is releasing new recommendations alongside findings from a global survey by its Internal Research Center, which found that just 14% of businesses globally with 100 to 499 employees avoided a cyber incident in the past year. The figure is 23% in South Africa.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases