Unveiled at GITEX Nigeria, new findings reveal that small and mid-sized businesses are facing enterprise-grade attacks, prompting a surge in cybersecurity investments.
A staggering 82% of small and mid-sized businesses (SMBs) in the Middle East, Turkiye, and Africa (META) region encountered cybersecurity incidents over the past year, according to new research from Kaspersky. Released during GITEX Nigeria in Lagos, the study underscores that cybercriminals are increasingly deploying the same aggressive tactics against smaller enterprises that were once reserved for large corporations.
Data from Kaspersky’s Internal Research Center reveals that only 18% of META SMBs avoided a security breach entirely over the last year. On average, organizations experienced three distinct types of security incidents. Across the region, the most frequently reported breaches mirror global trends:
- Phishing: 19% of SMBs
- Software vulnerability exploits: 19% of SMBs
- Weak or stolen credentials: 18% of SMBs
- External remote access: 16% of SMBs
The threat landscape is also shifting as malware families surge. In Africa, password stealer attacks spiked by 51%, backdoors rose by 23%, and spyware detections grew by 16%. In Nigeria alone, Kaspersky security tools blocked more than 1.6 million online attack attempts and 2.5 million on-device threats (including malware via USB drives) in the first half of 2026 alone.
The illusion that SMBs can fly under the radar is fading as digitalization accelerates and attack costs plummet. According to the study, internal challenges significantly amplify cyber risk for growing businesses in the META region:
- Insufficient IT expertise and security policies: Named as top risk factors by 25% of respondents.
- High workload on IT security departments: Cited by 24% of businesses.
- Lack of centralized control and shadow IT: Highlighted by 23% of organizations.
- Employee awareness gaps and non-IT business decisions: At 22%.
In response to rising threat levels, 70% of META SMBs plan to enhance their IT security functions, and 70% have already increased their cybersecurity budgets this year. Companies are channeling funds into expanding security teams, introducing employee training, and migrating to advanced detection solutions like XDR, NDR, and SIEM.
To combat the talent and budget constraints facing growing businesses, Kaspersky recommends establishing strict internal access controls, enforcing continuous human risk management, and deploying right-sized technology defenses, ranging from Kaspersky Small Office Security for micro-businesses to Kaspersky Next MXDR Optimum for more mature operations.





























