Home African NewsCyberattacks on African SMBs Rise as 82% of META Corporations Are Hit

Cyberattacks on African SMBs Rise as 82% of META Corporations Are Hit

by The Connecting Newspaper
0 comments


Cyberattacks on African SMBs rise as Kaspersky reports growing threats across Africa
Picture credit score: Kaspersky

Cyberattacks on African SMBs have gotten a rising enterprise threat, as new Kaspersky analysis reveals that 82% of small and mid-sized companies throughout the Center East, Türkiye and Africa encountered not less than one cybersecurity incident over the previous 12 months.

The findings, launched alongside GITEX Nigeria 2026, counsel that smaller corporations can now not assume they’re much less engaging targets than massive enterprises.

Based on Kaspersky, solely 18% of small and medium-sized companies (SMBs) surveyed within the Center East, Türkiye and Africa (META) area prevented a cybersecurity incident in the course of the previous 12 months. Globally, the equal determine amongst companies with 100 to 499 staff was 14%.

The analysis comes as African companies deepen their reliance on cloud platforms, distant entry, digital funds, synthetic intelligence and different related applied sciences, increasing their potential publicity to cybercrime on the identical time.

Cyberattacks on African SMBs have gotten extra subtle

A number of the most important will increase reported by Kaspersky contain malware designed to realize entry to company methods, credentials and delicate data.

Throughout Africa, detections of password-stealing malware elevated by 51% over the interval lined by Kaspersky’s newest statistics, whereas backdoor detections rose by 23% and spy ware detections elevated by 16%.

Password stealers are significantly vital for companies as a result of compromised credentials can present attackers with an entry level into electronic mail accounts, cloud providers, monetary methods and different company platforms.

Backdoors, in the meantime, can permit attackers to take care of persistent entry to an contaminated setting, whereas spy ware could also be used to gather confidential enterprise data.

The rise in cyberattacks on African SMBs is especially vital as smaller corporations speed up their use of digital providers whereas typically working with fewer cybersecurity sources than bigger enterprises.

Nigeria information thousands and thousands of tried assaults

Nigeria offers a very clear instance of the dimensions of the cybersecurity problem going through African companies.

Kaspersky stated its safety applied sciences blocked greater than 1.6 million on-line assault makes an attempt focusing on customers in Nigeria in the course of the first half of 2026.

These included threats involving password stealers, spy ware, exploits and different types of malicious exercise.

An extra 2.5 million on-device threats have been blocked in Nigeria throughout the identical interval, based on Kaspersky.

Such threats can embrace malware delivered by means of contaminated USB drives and different recordsdata reaching gadgets exterior standard web-based assault channels.

The figures underline the dimensions of the problem going through companies as Nigeria’s financial system turns into more and more depending on digital platforms, related enterprise methods and on-line providers.

Phishing stays one of many greatest SMB dangers

Kaspersky’s newest survey lined 1,800 IT safety specialists throughout SMBs and bigger enterprises in 18 nations.

On common, organisations skilled three several types of safety incidents in the course of the earlier 12 months.

Amongst SMBs globally, phishing was probably the most generally reported class, affecting 20% of organisations surveyed.

Exploitation of software program vulnerabilities adopted at 17%, whereas incidents involving exterior distant entry affected 16%.

Throughout the META area, phishing and software program vulnerability exploitation have been every reported by 19% of SMBs.

The usage of weak or stolen credentials affected 18%, whereas 16% reported incidents related to exterior distant entry.

Though zero-day exploits and trusted relationship assaults ranked decrease, Kaspersky stated every class was nonetheless skilled by 8% of organisations surveyed.

This means that companies face a broad vary of dangers somewhat than a single dominant type of cyberattack.

Folks and safety insurance policies stay main vulnerabilities

The analysis additionally highlights cybersecurity challenges that can not be addressed just by buying further safety software program.

Amongst META SMBs, 25% of respondents recognized inadequate cybersecurity experience amongst IT workers as one of many components rising the probability of profitable assaults.

An equal 25% pointed to insufficient IT safety insurance policies.

Excessive workloads inside IT safety departments have been recognized by 24%, whereas 23% cited inadequate centralised management over IT infrastructure and shadow IT.

An extra 22% pointed to insufficient cybersecurity consciousness amongst staff.

The identical proportion recognized enterprise selections made with out ample consideration of IT safety as one other essential threat.

The figures underline the rising significance of cybersecurity as a administration problem somewhat than solely an IT perform.

For smaller African companies particularly, speedy digitalisation can create new vulnerabilities when know-how adoption strikes sooner than safety governance, worker coaching and entry controls.

Cybersecurity budgets are rising

Companies look like responding to those pressures by allocating extra sources to cybersecurity.

Globally, 75% of SMBs surveyed stated they’d elevated their cybersecurity budgets this 12 months.

Within the META area, the proportion was 70%.

In the meantime, 69% of SMBs in META stated they deliberate to strengthen their IT safety perform.

Some 36% allotted further funding to broaden their IT and cybersecurity groups, whereas 32% invested further finances in IT safety coaching for workers.

One other 24% allotted further sources to superior safety applied sciences similar to prolonged detection and response (XDR), community detection and response (NDR) and safety data and occasion administration (SIEM).

The spending patterns counsel that cybersecurity is transferring larger on the funding agenda of growth-stage companies throughout the area.

Expertise shortages add to the problem

Ilya Markelov, Head of Unified Platform Product Line at Kaspersky, stated corporations of all sizes can now be focused utilizing subtle assault strategies.

“The present actuality when corporations of all sizes will be focused with all doable strategies urges enterprise to rethink their safety posture.”

Markelov stated rising corporations are steadily constrained by restricted budgets and the worldwide scarcity of information-security specialists.

This creates a selected problem for SMBs, which have to strengthen safety with out essentially with the ability to construct the massive inner cybersecurity groups accessible to main firms.

The problem due to this fact extends past buying safety know-how. Firms additionally want applicable inner insurance policies, worker consciousness, entry controls and processes for managing incidents once they happen.

AI and digitalisation broaden the assault floor

Synthetic intelligence and different rising applied sciences are including one other dimension to the cybersecurity problem.

As companies experiment with generative AI, cloud functions and new digital productiveness platforms, staff could undertake providers earlier than they’ve been formally assessed or authorized by company IT groups.

This may contribute to shadow IT — one of many threat components recognized by respondents in Kaspersky’s META analysis.

For smaller companies, the problem is to learn from sooner digital adoption with out permitting uncontrolled functions, weak credentials or poorly managed entry rights to undermine safety.

Cybersecurity due to this fact must develop alongside digital transformation somewhat than being launched solely after new applied sciences have already been deployed.

Cybersecurity turns into a enterprise problem

The implications prolong past IT departments.

A cyber incident can have an effect on fee methods, buyer data, provider relationships, communications and enterprise continuity.

For SMEs working with restricted monetary and operational reserves, even a comparatively quick disruption can have vital business penalties.

On the identical time, compromised buyer or company information can harm belief and doubtlessly expose corporations to regulatory and authorized dangers.

Addressing cyberattacks on African SMBs will due to this fact more and more require corporations to mix know-how funding with stronger inner insurance policies, workers coaching and tighter management over digital entry.

GITEX Nigeria places cybersecurity in focus

The findings have been launched in reference to GITEX Nigeria 2026, happening from 31 August to three September.

The occasion brings collectively know-how corporations, startups, buyers, policymakers and enterprise leaders as Nigeria seeks to strengthen its place in Africa’s quickly increasing digital financial system.

Cybersecurity is turning into more and more essential inside that wider transformation as companies undertake synthetic intelligence, cloud computing, digital funds and different related applied sciences.

For African companies, the Kaspersky findings level to a broader consequence of digitalisation: the extra deeply organisations depend upon digital infrastructure, the much less real looking it turns into to deal with cybersecurity as an elective expense.

For SMBs particularly, the difficulty is more and more tied not solely to defending information but in addition to sustaining enterprise continuity, safeguarding monetary methods and retaining buyer belief.

Sources and Data

Extra survey, Africa and Nigeria-specific statistics have been supplied by Kaspersky in materials equipped to AfricaBusiness.com on 31 August 2026.

You may also like