[REVISION HISTORY]
Cybersecurity threats and resilience for SMEs
Updated 1 time since CLSTR started tracking revisions of this situation.
What changed
2026-09-01 11:32 UTC → 2026-09-03 06:24 UTC ·
added
removed
Cybersecurity threats to small and medium businesses resilience for SMEs
Small and medium-sized enterprises (SMEs) are facing escalating cybersecurity threats, particularly through the targeting of payroll software and business communication tools. Criminals exploit these systems to steal sensitive banking and personal data for fraud or identity theft. Reports from 2025 suggest that four out of five small businesses were victims of a breach, experiencing 350% more social engineering or impersonation attacks than large enterprises. As the threat landscape evolves, cybercriminals are employing sophisticated methods typically used against large corporations, such as phishing and software vulnerability exploitation. Research indicates that only 14% of global businesses with 100 to 499 employees avoided a cyber incident in the past year. Regional authorities have begun issuing warnings regarding the financial impact of these attacks. In the United Kingdom, officials noted that a significant attack can cost a single business nearly £195,000. In South Africa, high rates of social engineering, phishing, and business email compromise have been observed as smaller organizations continue to digitalize. By late 2026, the cybersecurity focus has shifted toward resilience and the ability to maintain operations and recover quickly during incidents. Experts suggest SMEs can reduce risk by implementing fundamental controls, such as multi-factor authentication (MFA) and consistent patch management, rather than relying on expensive, complex tooling. In the insurance sector, cyber insurance is becoming a key metric for preparedness, though a lack of basic security controls may restrict coverage options. In New Zealand, concerns have been raised regarding a “forgotten middle” of medium-sized businesses facing growing regulatory responsibilities without adequate resources, especially as potential legal changes could hold directors personally liable for critical breaches.
Versions
- 2026-09-03 06:24 UTC Cybersecurity threats and resilience for SMEs
- 2026-09-01 11:32 UTC Cybersecurity threats to small and medium businesses
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.