Italian SMEs Overestimate Cybersecurity Resilience Amid Rising Threats, Survey Finds
A new ESET SMB Cyber Readiness Index surveyed 4,400 small and medium‑size enterprises in 13 countries, including Italy. Overall, 45 % of SMEs reported at least one security incident in the past twelve months, while 75 % said they were confident in their ability to withstand an attack and 61 % feared a breach in the coming year. In Italy, 65 % said they had not experienced an incident, 27 % reported one and 8 % more than one; only 17 % felt very confident, compared with 59 % who felt moderately confident.
The survey highlights a gap between perceived and actual resilience. Phishing (26 %), unpatched vulnerabilities (23 %), lack of monitoring (22 %) and weak passwords (20 %) remain the main causes of incidents, even as 31 % of SMEs view AI‑powered malware as the top emerging threat. While 73 % of global SMEs have adopted AI tools, only 60 % in Italy do so, and fewer have formal AI‑use policies. Cyber‑insurance coverage exists for 71 % of firms worldwide, yet only a third trust it as a sole safeguard.
Separately, ALS Group, an Italian risk‑management consultancy, stresses the need for a stronger cyber‑culture in companies. It notes that Italy was the most malware‑hit country in Europe in 2023 and that compliance with the EU NIS‑2 directive and AI governance standards is essential for SME protection.