82% of META SMBs Faced a Cybersecurity Incident in the Past Year, Kaspersky Finds

A new Kaspersky survey finds that 82% of small and mid-sized businesses in the Middle East, Turkiye and Africa region experienced a cybersecurity incident in the past year, with phishing and software vulnerability exploitation the most common entry points.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region3 min read
A small business office laptop displaying a cybersecurity alert, representing rising incident rates among SMBs in the META region

A small business office laptop displaying a cybersecurity alert, representing rising incident rates among SMBs in the META region

Small and mid-sized businesses across the Middle East, Turkiye and Africa region are no longer a soft target that flies beneath attackers' radar. A new global survey from Kaspersky's Internal Research Center found that just 18% of META businesses with fewer than 500 employees avoided a cybersecurity incident in the past year, meaning 82% experienced at least one. The regional figure sits close to the global rate, where only 14% of businesses in the same size band avoided an incident.

Kaspersky surveyed IT security specialists across SMBs and enterprises in 18 countries for the study, and found that organisations experienced, on average, three different types of security incidents over the past year. In the META region specifically, phishing and software vulnerability exploitation each affected 19% of SMBs, followed by the use of weak or stolen credentials (18%) and external remote access (16%). Zero-day exploits and trusted relationship attacks ranked lowest but were still encountered by 8% of organisations globally, underlining that even the least common attack types remain a live risk.

The survey also asked respondents to identify the factors that most elevate an organisation's risk of a successful attack. Among META SMBs, insufficient expertise among IT staff and insufficient IT security policies ranked jointly at the top, each cited by 25% of respondents, followed by a high workload on IT security teams (24%). Lack of centralised control over IT infrastructure and shadow IT followed at 23%, with a lack of security awareness among employees and business decisions made without IT security input each cited by 22%. The pattern points to a resourcing and governance gap as much as a technical one.

Budgets are responding, if unevenly. Seventy percent of META SMBs said they have already increased their cybersecurity budget this year, against 75% globally, and 69% plan to expand their IT security function. Of those increases, 36% of META respondents allocated funds to expand IT and IT security teams (41% globally), 32% put budget toward new security training for employees (matching the global figure), and 24% used the additional spend to migrate to advanced tools such as XDR, NDR and SIEM (30% globally). "Growing companies are often held back by budget constraints and the global InfoSec talent shortage," said Ilya Markelov, Head of Unified Platform Product Line at Kaspersky. "Modern cybersecurity solutions must deliver more with less."

These findings sit alongside other regional benchmarks tracked on this site. ESET's 2026 SMB Cyber Readiness Index put the regional attack rate for small and mid-sized businesses at 45%, a lower figure than Kaspersky's, a reminder that survey design, sample composition and how "incident" is defined all shift the headline number. What's consistent across independent surveys is the direction of travel: SMB exposure in the region is rising, not stabilising, and the entry points remain overwhelmingly human rather than exotic. That tracks with the wider pattern already documented on this site, where phishing is now confirmed as the entry point for the majority of GCC breaches.

For enterprises and IT decision-makers evaluating where to direct limited security budget, Kaspersky's own recommendations are unremarkable but consistently under-implemented: enforce access controls and prompt offboarding, automate backups against ransomware, run structured phishing and deepfake awareness training, and choose tools scaled to the size of the business rather than importing enterprise-grade complexity that a small IT team cannot sustain.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

sme cybersecuritygcc enterprise security spend