# Escalating global cybersecurity threats and risks for SMEs

> Live situation record from CLSTR: https://clstr.news/situations/cybersecurity-fundamentals-and-best-practices
> Updated: 2026-09-10T22:00:38.000Z. Sources: 22. Developments: 7.

Cybersecurity threats to small and medium-sized enterprises (SMEs) continue to escalate globally. While a Clusit 2025 report previously noted a 42% increase in attacks, recent data from Kaspersky indicates that 86% of SMEs worldwide faced at least one cybersecurity incident in the past year.

In Italy, 507 serious incidents were recorded in 2025, representing 9.6% of the global total. Phishing and social engineering remain critical vulnerabilities, accounting for 12.4% of serious incidents in Italy—a 66% increase driven by AI-enhanced deepfakes. To help SMEs navigate European regulations like the Cyber Resilience Act (CRA), the APPtake project is providing DevSecOps tools to integrate security into the application lifecycle and manage risks from AI-generated code.

Regional threats vary significantly. In Latin America, the most frequent incidents include phishing (24%), external remote access (15%), and software vulnerability exploitation (13%). In Colombia, ColCERT issued a high-risk alert regarding a global credential theft campaign targeting internet-exposed firewalls and VPN gateways.

New research highlights a gap between technical implementation and operational readiness. A study by FORT Cyber, Data Diggers, and Promocrat found that while over 80% of Romanian companies utilize basic measures like firewalls and multi-factor authentication, 15% of organizations that implemented nearly all analyzed technical measures had never tested their incident response plans.

Global impacts remain severe. According to Kaspersky, 22% of respondents cited financial loss as a primary impact of attacks, 16% reported permanent data loss, and 13% experienced irrecoverable destruction of company assets. Customer data is the most frequent target, cited by 32% of respondents.

## Timeline

### 2026-09-10: Cybersecurity threats impact 86% of SMEs globally

Cybersecurity threats are rising for SMEs, with 86% facing incidents globally. In Colombia, 27 organizations were exposed due to a global credential theft campaign targeting firewalls and VPNs.

4 sources. https://clstr.news/cluster/cybersecurity-threats-impact-86-of-smes-globally

### 2026-09-09: Cybersecurity studies reveal gaps in organizational preparedness and rising attack rates

Studies show Romanian companies often lack tested incident response plans despite having technical tools, while 86% of SMEs globally report experiencing at least one cyberattack annually.

2 sources. https://clstr.news/cluster/cybersecurity-studies-reveal-gaps-in-organizational-preparedness-and-rising-attack-rates

### 2026-09-07: Cybersecurity challenges rise for SMEs amid new EU regulations

Rising cyberattacks and new EU regulations are driving initiatives like the APPtake project to help SMEs integrate DevSecOps, while human error remains a primary vulnerability in digital security.

4 sources. https://clstr.news/cluster/cybersecurity-challenges-rise-for-smes-amid-new-eu-regulations

### 2026-09-07: Kaspersky warns of rising cyber threats against SMEs and parked domains

Kaspersky reports rising cyber threats against SMEs in the META region and warns that scammers are using unused “parked domains” to steal sensitive user data and track devices.

2 sources. https://clstr.news/cluster/kaspersky-warns-of-rising-cyber-threats-against-smes-and-parked-domains

### 2026-09-02: Cybersecurity threats rise for SMBs in META region

Cyberattacks are rising among SMBs in the META region, with 82% of firms reporting incidents. Threats include increased password-stealing malware, phishing, and software vulnerability exploitation.

4 sources. https://clstr.news/cluster/cybersecurity-threats-rise-for-smbs-in-meta-region

### 2026-08-15: SMEs face rising cybersecurity threats and high incident rates

SMEs face rising cyber threats, with 86% reporting incidents last year. Key risks include phishing and software vulnerabilities, necessitating multi-factor authentication and regular backups.

4 sources. https://clstr.news/cluster/cybersecurity-essentials-for-small-businesses

### 2026-08-11: Cybersecurity fundamentals: encryption protocols and employee training

Cybersecurity relies on technical encryption like SSL/TLS certificates to protect data and Security Awareness Training (SAT) to mitigate human error and phishing risks within organizations.

2 sources. https://clstr.news/cluster/cybersecurity-fundamentals-encryption-protocols-and-employee-training

---
Cite as: Escalating global cybersecurity threats and risks for SMEs. CLSTR, https://clstr.news/situations/cybersecurity-fundamentals-and-best-practices
