Menu

6% of Respondents Experienced Cyber Incident last year

6% of Respondents Experienced Cyber Incident last year

A global survey by cybersecurity company Kaspersky has revealed that 86 percent of small and medium-sized business (SMB) respondents experienced at least one cyber incident over the past year, highlighting the growing cybersecurity risks facing businesses worldwide.

According to the survey findings, phishing attacks, software and web application exploits, mass malware, ransomware, external remote-access attacks and threats targeting artificial intelligence vulnerabilities were among the most damaging cyber incidents reported by businesses.

Financial losses were one of the leading consequences, cited by 22 percent of respondents. Other major impacts included the theft of customer data, temporary disruption of client-facing services such as websites and online stores, loss of control over IT infrastructure and wider disruption to business operations.

Data theft also emerged as a major concern, with attackers frequently targeting valuable business information. Customer data was targeted in 32 percent of reported incidents, while sensitive internal information such as financial credentials and legal documents was targeted in 28 percent. Employee credentials accounted for 25 percent, while business strategies were targeted in 23 percent of cases.

IT and cybersecurity departments remained the primary targets, accounting for 50 percent and 46 percent of the most harmful attacks, respectively. Accounting and finance departments were the third most targeted, with 24 percent of incidents affecting these areas. On average, three departments were compromised simultaneously during the most serious cyber incidents.

The survey also found that SMBs were more likely to experience attacks through customer service channels, with 21 percent reporting such incidents compared with 15 percent among mid-sized businesses and 17 percent among large enterprises.

Cyber governance expert Asad Ur Rehman said cybersecurity is no longer an issue limited to large corporations. He noted that Pakistani SMBs are increasingly vulnerable because they often handle valuable customer and financial data while operating with limited security resources. He stressed that investment in cybersecurity should be viewed not merely as an IT expense but as an essential business-resilience measure to protect customer trust, maintain operational continuity and support long-term growth.