86% of SMBs Faced Cyber Incidents in Past Year, Kaspersky Survey Finds

Phishing, ransomware and malware emerged among the most damaging threats, while financial losses and data theft remained major concerns for businesses

Cybersecurity risks and cyber incidents affecting small and medium-sized businesses

Kaspersky survey highlights rising cybersecurity risks facing small and medium-sized businesses

ISLAMABAD, September 10, 2026: Around 86% of small and medium-sized businesses (SMBs) globally experienced at least one cyber incident in the past year, according to a new survey released by cybersecurity company Kaspersky.

The survey found that phishing attacks, software and web application exploits, mass malware and ransomware ranked among the most damaging threats.

External remote access attacks and vulnerabilities targeting artificial intelligence systems also emerged as major concerns.

Financial Losses Among Major Consequences

Financial loss was one of the leading consequences of the most damaging cyber incident, with 22% of respondents reporting such an impact.

Businesses also reported theft of customer data and disruption to client-facing services. These disruptions included websites and online stores going offline.

Other consequences included loss of control over IT infrastructure and wider disruption to business operations.

The findings highlight the growing impact of cyberattacks on smaller companies. Such businesses often have fewer resources to recover from major incidents.

Customer Data Remains a Key Target

Data theft emerged as another major concern for SMBs.

Customer information was the most frequently targeted data, cited by 32% of respondents.

Sensitive internal information, including financial credentials and legal documents, followed at 28%.

Employee credentials were targeted in 25% of cases. Business strategy information was targeted in 23%.

The figures suggest that cybercriminals are increasingly seeking data that can generate financial value or support further attacks.

IT Departments Face Heavy Pressure

IT and cybersecurity teams were the main targets during the most damaging incidents.

According to the survey, 50% of attacks targeted IT departments, while 46% targeted IT security teams.

Accounting and finance departments ranked third, with 24% of respondents reporting attacks against these areas.

On average, three departments were compromised during the most serious incidents.

Customer service channels also faced notable risks. SMBs reported attacks through these channels at a rate of 21%, compared with 15% among mid-sized companies and 17% among large enterprises.

Anthropic Safety Researcher Warns AI Could Pose Existential Risk

Businesses Strengthen Cybersecurity Measures

Recent incidents have pushed companies to introduce additional security measures.

IT security monitoring ranked as the top priority, cited by 24% of respondents.

Another 23% focused on strengthening third-party compliance requirements. The same percentage reported upgrading credential management practices.

Meanwhile, 22% of businesses focused on deploying security software across employee devices.

An equal share invested in specialised training to improve the expertise of IT staff.

Experts Warn Pakistani SMBs Face Growing Risks

Ilya Markelov, Head of the Unified Platform Product Line at Kaspersky, said cyber incidents can have a particularly serious impact on smaller businesses.

He said limited resources can make recovery difficult and, in some cases, threaten a company’s survival.

Markelov said SMBs need scalable security solutions that match their size, budgets and operational needs.

Cyber governance expert Asad Ur Rehman also highlighted the growing exposure of Pakistani businesses.

He said cybersecurity is no longer an issue limited to large corporations.

According to Rehman, Pakistani SMBs often handle valuable customer and financial information while operating with limited security resources.

He said businesses should treat cybersecurity as a business-resilience measure rather than simply an IT expense.

Kaspersky Recommends Stronger Protection

Kaspersky recommends that SMBs adopt security solutions suited to their budget, size and industry.

The company said smaller businesses can consider endpoint protection that helps defend against malware and ransomware.

For companies requiring more advanced capabilities, Kaspersky recommends solutions designed to prevent attacks, detect threats, investigate incidents and support rapid response.

The company also highlighted security awareness training for employees.

Interactive courses and simulated phishing exercises can help staff recognise common cyber threats and develop safer online habits.

As cyberattacks continue to target businesses of all sizes, stronger protection, employee training and regular security monitoring are becoming increasingly important for business continuity.

Follow THE AZB

Leave a Reply

Your email address will not be published. Required fields are marked *

Are you human? Please solve:Captcha


Social Media Auto Publish Powered By : XYZScripts.com