Favicon

87% of APAC SMBs Hit by Cyberattacks: Kaspersky

Reported By: ST Report September 23, 2026, 5:32 pm Category: International
87% of APAC SMBs Hit by Cyberattacks: Kaspersky
Photo: Courtesy
87% of APAC SMBs Hit by Cyberattacks: Kaspersky

September 23, 2026: The illusion that small and mid-sized businesses (SMBs) can fly under the radar of cybercriminals is becoming obsolete. As digitalization grows and the cost of launching cyberattacks falls, threat actors are increasingly targeting growth-stage companies and exploiting cybersecurity gaps.

Kaspersky surveyed IT security specialists across SMBs and enterprises in 18 countries. The study found that APAC organizations experienced an average of three types of security incidents over the past year. Among SMBs, software vulnerability exploitation (20%), phishing (19%) and mass malware attacks (18%) were the most frequently encountered breaches, while 6% reported experiencing zero-day exploits.

The leading factors increasing cyberattack risks were lack of security awareness among non-IT employees (26%), lack of expertise among IT security staff (24%), outdated software or hardware (23%), lack of regular risk assessments (22%) and lack of necessary security solutions (22%).

In response, 75% of APAC companies plan to strengthen their IT security functions, while 78% of SMBs increased cybersecurity budgets this year. Nearly half (48%) allocated additional funds to expand IT and security teams, and 32% invested in advanced solutions such as XDR, NDR and SIEM.

“The current reality when companies of all sizes can be targeted with all possible methods urges business to reconsider their security posture. Sophisticated attacks easily bypass fragmented defenses, requiring advanced tools and a skilled team to counter them. However, growing companies are often held back by budget constraints and the global InfoSec talent shortage,” says Ilya Markelov, Head of Unified Platform Product Line at Kaspersky. “That is why modern cybersecurity solutions must deliver more with less. Instead of introducing complex new tools that demand hard-to-find, expensive expertise, vendors should focus on cutting complexity. When designing our products for SMBs, our goal is to provide advanced protection that is easy to adopt, simple to manage, and able to grow alongside the business, helping organizations strengthen their security without adding unnecessary complexity or stretching their budget”.

“SMBs across APAC are no longer the collateral damage or secondary target. Our survey shows that they are prime victims for modern threat actors who use the exact same enterprise-level tactics,” says Adrian Hia, Managing Director for Asia Pacific at Kaspersky. “However, the fact that the majority of SMBs step up their cybersecurity budgets indicates a strong signal that business leaders understand the importance of cybersecurity. The goal ahead is not about burdening teams with overly complex tools, but about securing essential systems, empowering non-IT employees, and deploying managed security solutions that scale smoothly as businesses grow.”

“As a company that helps clients adopt a security maturity model to navigate current digital trends, we see that the cyber challenge is intensifying. Attackers increasingly leverage on artificial intelligence, driving up both the volume and complexity of today's threats. Also, credential protection has become paramount as attackers exploit security gaps to harvest high-value logins for targeted attacks that disrupt business operations or cause data theft. Consequently, raising importance of educating non-technical users who remain one of the weakest links,” comments Maximiliano Allo, Director at Custom IT . “Kaspersky offers a wide range of suites, enabling companies with smaller budgets or limited staff to effectively counter these threats. Their SMB suites feature robust automation and a centralized management console, delivering enterprise-grade security without requiring significant time investments.”

Kaspersky recommends that SMBs strengthen access controls, automate backups, simplify cybersecurity guidelines, train employees to identify threats such as phishing, deepfakes and vishing, and adopt scalable security solutions suited to their size and needs.