Skip to main content

86% of small and medium sized businesses encountered cybersecurity incidents over the past year

13 August 2026

Kaspersky warns that attackers are currently deploying the same methods against smaller businesses as they do against large enterprises. To help strengthen corporate defences, Kaspersky is releasing new recommendations alongside findings from a global survey by its Internal Research Center, which found that just 14% of businesses with fewer than 500 employees avoided a cyber incident in the past year.

The illusion that small and mid-sized businesses (SMBs) can fly under the radar of cybercriminals is becoming obsolete. As smaller organizations digitalize, and the cost of launching cyberattacks plummets, threat actors are increasingly shifting their focus toward growth-stage companies, weaponizing emerging technologies and exploiting all possible cybersecurity gaps.

Kaspersky, a global cybersecurity and digital privacy company, surveyed IT security specialists across SMBs and enterprises in 18 countries[1] to provide insights into the most critical risks facing businesses today.

The study reveals that, on average, organizations experienced three different types of security incidents over the past year. For SMBs, phishing (20%), software vulnerability exploitation (17%) and external remote access (16%) top the list of the most frequently encountered breaches. Even though zero-day exploits and trusted relationship attacks ranked lowest, each of these extremely dangerous attacks was still encountered by 8% of organizations.

While incident distribution was similar across all business sizes, threats like mass malware, ransomware, BEC (Business email compromise), and AI vulnerability exploits were slightly more prevalent in companies with over 500 employees.

image
Respondents were also asked to select the top five factors that elevate the risk of successful cyberattacks in organizations. The two most frequently chosen factors by SMBs were people-related: lack of expertise among IT security staff (24%) and a lack of security awareness among non-IT employees (23%). Additionally, more than one-fifth of respondents selected insufficient IT security policies (21%), outdated software and hardware (21%) and high workload of IT security departments (20%) as key issues.

To address rising threats and internal challenges, most companies plan to enhance their IT security function (70%), and 75% of SMBs have already increased their cybersecurity budgets this year. Almost half (41%) allocated additional funds to expand their IT and IT security teams, while nearly one-third (30%) did so to migrate to advanced IT security solutions such as XDR, NDR, and SIEM.

“Businesses of all sizes can be targeted by increasingly sophisticated attacks, making it essential to continually strengthen their security posture. Sophisticated attacks can bypass fragmented defenses, requiring advanced protection and skilled expertise to counter them. For SMBs, however, budget constraints and the global shortage of cybersecurity talent can make this particularly challenging. This is where MSPs play an important role, providing the expertise and security capabilities SMBs need without requiring them to build large in-house teams,” says Anna Papla, UKI Territory Channel Manager at Kaspersky.

“For both SMBs and the MSPs that support them, security needs to deliver more with less. Rather than adding complex tools that require expensive and hard-to-find expertise, we believe security should be easy to adopt, simple to manage, and able to scale with the business. Our goal is to help MSPs deliver advanced protection to their customers while reducing complexity and making the most of limited resources and budgets.”

SMBs often don’t have the time or in house expertise to manage cybersecurity on their own, yet they face many of the same threats as larger organisations. For us as an MSP, the challenge is to provide strong protection that is easy to deploy and manage, while keeping costs viable for smaller customers,” comments Graham Martin, Technical Lead at Beyond the Cloud Solutions[2].

“Kaspersky gives us the technology and support to deliver enterprise grade cybersecurity at SMB scale, with centralised management, high quality alerts and built in automation that make it easier for our team to monitor and protect customer environments. Using Kaspersky’s solutions, we can also cover 100% of the UK National Cyber Security Centre’s Cyber Essentials recommendations, helping even the smallest organisations achieve compliance at a viable cost and increasingly win more business on that differentiator in today's economy.”

To protect against emerging threats, Kaspersky provides the following recommendations for small and medium businesses:

  1. Establish internal processes: implement strict access rules for all corporate resources and cloud services, ensuring IT promptly revokes permissions during employee offboarding. Second, integrate automated data backups into daily operations to secure critical information against emergencies and ransomware. Finally, back these technical controls with continuous human risk management: simplify cybersecurity guidelines for safe browsing and password hygiene and require IT approval for all new software. These actions will allow to minimize related cyber incidents such as insider threats, use of weak or stolen credentials and exploitation of lost or stolen IT assets.
  2. Protect your people: Conduct dedicated training to teach staff how to detect and address potential threats, including deepfakes and vishing and track their educational progress. Organizations can achieve this with the Kaspersky Automated Security Awareness Platform through interactive online modules and simulated phishing campaigns that build sustainable cyber hygiene habits across all teams.
  3. Choose the right technology defenses: Implement specialized cybersecurity solutions that fit your budget, size, and industry requirements, with an emphasis on efficiency, versatility, convenience of use and scalability.
  4. Kaspersky Small Office Security Premium is a great choice for micro-businesses below 50 employees. It is an easy-to-use solution that protects against advanced threats, including malware and ransomware, provides digital hygiene tools such as password management and data backup and even includes security awareness training for employees.
  5. Companies with more mature IT expertise should consider Kaspersky Next Optimum, which provides robust real-time prevention, threat visibility, as well as advanced detection and response capabilities with Next EDR and XDR Optimum. Organizations that need additional expertise without expanding their in-house security team can choose Kaspersky Next MXDR Optimum, combining XDR capabilities with continuous monitoring, expert threat analysis and incident response guidance delivered by Kaspersky analysts.
  6. Protect your business against email-borne threats, such as phishing, business email compromise, invoice payment fraud, etc. Kaspersky Security for Mail Server, a comprehensive email security platform that offers robust, multi-layered protection at mailbox and gateway levels, can help with this. Powered by machine learning and leading global threat intelligence, it effectively addresses all mail security challenges.

[1] 1800 interviews were conducted globally with representation across 18 countries: Brazil, Mexico, Colombia, France, Germany, Italy, Spain, India, Indonesia, Malaysia, China, Thailand, Vietnam, Egypt, South Africa, Saudi Arabia, Turkey, Russia.

[2] Beyond the Cloud Solutions – a UK based MSP provides managed cyber security services to business from all sectors and all sizes.  These services are designed to offer businesses hands off, professional cover and training to combat cyber incursions and reduce the risk of data and reputational loss at a cost-effective price.

86% of small and medium sized businesses encountered cybersecurity incidents over the past year

Kaspersky warns that attackers are currently deploying the same methods against smaller businesses as they do against large enterprises. To help strengthen corporate defences, Kaspersky is releasing new recommendations alongside findings from a global survey by its Internal Research Center, which found that just 14% of businesses with fewer than 500 employees avoided a cyber incident in the past year.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases