Nearly eight in 10 South African small and medium-sized businesses (SMBs) encountered a cybersecurity incident over the past year, with social engineering emerging as the most common type of attack, according to new research from Kaspersky.
The survey of IT security specialists found that just 23% of South African businesses with between 100 and 499 employees avoided a cyber incident during the past year. Globally, the figure was 14%.
South African SMBs most commonly reported social engineering incidents, affecting 23% of organisations. Phishing, weak or stolen credentials and business email compromise (BEC) each affected 18%, while software vulnerability exploitation was reported by 15%.
Outdated technology poses a risk
The research also examined the factors businesses believe increase their exposure to cyberattacks.
Among South African SMBs, outdated software or hardware and so-called Shadow IT – the use of unauthorised software, applications and services – were the most frequently cited risks, with 30% of respondents identifying each.
A lack of cybersecurity awareness among employees followed at 28%, while 25% of respondents identified the workload of IT and security teams, insufficient security policies and a lack of regular risk assessments as key risk factors.
The findings point to a combination of technology and people-related weaknesses leaving smaller businesses exposed as they become increasingly reliant on digital systems.
Globally, SMBs identified a lack of expertise among IT security staff as their biggest risk factor, cited by 24% of respondents, followed by a lack of security awareness among non-IT employees at 23%.
SMBs increasing security spending
South African businesses are responding by increasing their investment in cybersecurity.
Kaspersky's research found that 85% of South African SMBs had increased their cybersecurity budgets during the year, compared with 75% globally.
A further 85% said they plan to enhance their IT security function, compared with 70% globally.
Among South African SMBs, 35% allocated additional funds to employee IT security training, while 32% allocated funding to expand their IT and security teams. A further 24% invested in advanced security technologies such as extended detection and response (XDR), network detection and response (NDR) and security information and event management (SIEM).
Kaspersky said smaller businesses are increasingly facing many of the same attack methods as larger enterprises, while often operating with more limited budgets and access to cybersecurity expertise.
The research covered 1,800 IT security specialists across 18 countries, including South Africa.