.
Cybersecurity threats are increasingly reaching smaller businesses, with 82% of small and medium-sized businesses (SMBs) across the Middle East, Türkiye and Africa (META) reporting at least one cybersecurity incident in the past year.
The findings, released by cybersecurity and digital privacy company Kaspersky, challenge the long-held assumption that smaller companies are less attractive targets for cybercriminals than large enterprises.
According to the research, only 14% of businesses with between 100 and 499 employees globally avoided cyber incidents during the period under review. The figure was slightly better in the META region, where 18% of businesses in that employee category reported avoiding such incidents.
Nigeria Records Millions of Blocked Attacks
The threat picture is particularly significant for Nigeria, where Kaspersky security systems blocked more than 1.6 million online attack attempts during the first half of 2026.
The blocked threats included malware associated with password stealers, spyware and software exploits.
Kaspersky also reported that its security tools stopped another 2.5 million on-device threats in Nigeria, including malicious software delivered through infected USB devices.
The figures highlight the scale of cyber risks facing organisations as businesses increasingly depend on digital tools for everyday operations.
Password Stealers, Spyware Become Bigger Threats
Kaspersky’s data showed significant year-on-year increases in several categories of malware targeting businesses in Africa.
Password-stealer detections increased by 51%, while backdoor detections rose by 23%. Spyware detections also increased by 16%.
These forms of malware can be used to gain access to corporate systems, steal sensitive information and maintain unauthorised access that can enable further attacks.
Software vulnerabilities also remain an important entry point for attackers.
Kaspersky said the methods being deployed against smaller companies increasingly resemble those traditionally associated with attacks on larger enterprises.
Phishing Remains Major Entry Point
Globally, SMBs reported an average of three different types of security incidents over the past year.
Phishing was identified as the most frequently encountered breach, accounting for 20% of reported incidents. Software vulnerability exploitation followed at 17%, while attacks involving external remote access accounted for 16%.
The findings suggest that cybercriminals do not necessarily need highly sophisticated methods to compromise a business, particularly where employees, outdated systems or weak security processes provide openings.
Lack of Expertise Adds to Business Risk
Beyond external attacks, businesses in the META region identified internal cybersecurity weaknesses as major concerns.
Insufficient IT expertise and inadequate IT security policies were each cited by 25% of SMBs as major challenges.
Another 24% pointed to excessive workloads within IT security departments.
Other commonly reported weaknesses included a lack of centralised control over IT infrastructure and the use of unauthorised or unapproved technology, known as shadow IT. Both were cited by 23% of respondents.
A lack of employee cybersecurity awareness and business decisions being made without sufficient consideration of IT security were each identified by 22% of businesses.
Businesses Increase Cybersecurity Spending
With threats becoming more widespread, businesses are responding by increasing investment in cybersecurity.
Globally, 70% of SMBs said they planned to strengthen their IT security functions, compared with 69% in the META region.
Meanwhile, 75% of SMBs globally had already increased their cybersecurity budgets during the year. In the META region, 70% reported doing the same.
Some businesses are also putting additional money into expanding their IT and security teams, employee training and advanced security technologies.
About 36% of META-region SMBs allocated additional funding to expand their IT and IT security teams, while 32% invested in new employee security training.
Another 24% allocated funds to advanced security solutions such as extended detection and response, network detection and response, and security information and event management systems.
Digital Growth Creates New Attack Surface
The findings point to a growing challenge for businesses across Africa.
As smaller companies adopt cloud services, digital payments, remote access tools and other technologies, they create more potential entry points for cybercriminals.
Kaspersky said the traditional belief that SMBs can remain below the radar of attackers is increasingly outdated. The declining cost of launching cyberattacks and the growing value of digital business information are making smaller, fast-growing companies increasingly attractive targets.
For Nigerian businesses in particular, the millions of attacks already blocked this year underscore the importance of treating cybersecurity as part of core business operations rather than an issue reserved for large corporations.
The emerging picture is clear: digital expansion is creating new opportunities for African businesses, but it is also expanding the battlefield for cybercriminals.















