The Growing Threat Landscape for Small and Medium-Sized Businesses

0
12

Why cyber resilience, not bigger IT budgets, will determine which businesses thrive in the age of AI-powered attacks

Kenya’s digital economy is one of Africa’s greatest success stories. Mobile money and social media have put East Africa’s largest economy on the global digital map and the uptake of digital sectors such as electric mobility, e-commerce, artificial intelligence (AI) and e-government services is high.

A majority of Kenyans access public services online through the eCitizen platform encouraging several businesses to digitize their platforms, transforming how businesses operate, compete and grow. However, the same technologies fueling innovation are open to vulnerabilities and manipulation by cybercriminals and increasingly, cyber attackers are eyeing small and medium-sized businesses (SMBs) as gateways into larger, interconnected digital ecosystems connected to government agencies and multinational corporations as SMBs generally don’t have the cybersecurity budgets of larger corporates. And  for cyber attackers, access is access, regardless of the route taken.

With API access and interconnectedness into partner platforms, an attack on a SMB is a threat to a government agency or a multinational corporation. Therefore, resilience and speed, and not a bigger IT budget alone, will determine which businesses thrive in the age of AI-powered attacks.

The reality is that automation and AI has lowered the barrier of entry for cybercriminals and is helping cybercriminals build sophisticated tools, making any amateur hacker a skilled one and cyberattacks are evolving into a sophisticated global industry powered by cybercrime-as-a-service platforms. An amateur  hacker in Kenya doesn’t need sophisticated tools as today ransomware kits, phishing campaigns and malicious software can be bought or rented online complete with 24-hour support.

This has made the cyber threat landscape even more challenging for SMBs, as they are expected to secure increasingly complex digital environments, including their partner access points, despite their lean IT teams, low cybersecurity expertise and limited budgets. SMBs are expected to be more alert than they were ten or five years ago as they serve banks, telecommunications companies, manufacturers, retailers, healthcare providers and government agencies. Their growth as lean and preferred suppliers of services in the digital marketplace makes them attractive targets for cyber-attacks.

Kenya recorded more than 4.5 billion cyber threat events between April and June 2025, representing an 83.4% increase compared to the previous quarter, according to the Communications Authority of Kenya’s National Kenya Computer Incident Response Team, Coordination Centre report. In the same period, the national cyber incident response team issued more than 17 million cyber threat advisories, not only highlighting the growing volume and sophistication of attacks targeting businesses, government institutions and critical infrastructure but calling for cyber security preparedness, resilience and the need for early mitigation.

Earlier, the country also experienced the impact of high-profile cyber incidents especially on its national carrier and a number of healthcare facilities, banks and government agencies. These attacks put personal and financial information at risk, and no amount of ransomware payments is enough to deter cyber attackers from coming again. 

According to Kaspersky telemetry, in 2025, Kaspersky security tools blocked more than 11,3 million online attack attempts on users in Kenya. Another 18,4 million on-device threats were blocked, including malware delivered via infected USB drives. Password stealers, designed to secretly gather users’ account information, grew in the number of attacks by 83% compared with the previous year. Spyware attacks also increased in the number of attacks by 83%. The number of backdoor attacks in the country grew by 25% year-over-year, where growth in detections of this type of malware was sharp in the corporate segment. 

For business leaders, the big question right now is not how sophisticated cyber threats are becoming but how resilient they are to withstand them.

The urgency is particularly pronounced in Kenya, where SMBs account for more than 98% of all businesses and form the backbone of the country’s economy. As Kenyan SMBs embrace cloud services, digital payments, AI-powered tools and remote work, they are opening themselves up to more players both good and bad. Their platforms have to be open and interconnected to others to increase their services, reach more users and new markets and improve efficiency but these come at a cost. The increased digital footprint means they are open to heavier cyber- attacks, requiring dedicated cybersecurity teams and budgets to fend off sophisticated cybercriminals.

Small Businesses Have Become Strategic Targets

In 2026, no business owners should assume that cybercriminals are primarily interested in organizations with billions of dollars in revenue. Cyber attackers view and use smaller businesses as efficient entry points into much larger ecosystems and sometimes stay as long as they can in the SMBs systems before they lay an attack on the larger corporations. The attacks dwell in the SMBs systems for months or even years studying its clientele as most of these SMBs are suppliers, software vendors, consultants, logistics providers and managed service providers of major corporate firms, government agencies and multinational corporations. Every client is potentially at risk as instead of attacking a well-defended multinational directly, cybercriminals often choose the smaller partner with fewer security controls, using that foothold to move laterally through connected systems of its larger clients.

This trend has transformed cybersecurity from a purely technical issue into a boardroom concern. Protecting customer information, ensuring operational continuity and maintaining trusted business relationships is fundamental to long-term business success. For many SMBs, demonstrating strong cybersecurity practices is increasingly essential for winning contracts, securing investment and participating in regional and global value chains.

The Business of Ransomware

In 2026, no cybercriminal needs to spend hours developing their own malware due to white-label cybercrime organizations running Ransomware-as-a-Service (RaaS) businesses. Therefore, instead of developing malware themselves, attackers just need to pay a few dollars to subscribe to ransomware platforms with ready-made malicious software and an anonymous cryptocurrency wallet for payments, all untraceable to their local or amateur cybercriminal. This has drastically changed the criminal business model, making it easier for attackers and harder for victims.

As a media business, and to any other business out there, ransomware is no longer simply an IT incident but a business continuity crisis. Speaking from experience, downtime halted our productivity, delayed our customer deliveries, and lost us a number of clients. Whether to pay or not is not the only concern. A cyber-attack  is a business interruption no organization wants to deal with. Downtime  ruins financial transactions, impacts your online reputation and rankings, and damages carefully built standings. And even though you get your systems back, there’s that trauma of it happening again, there’s that fear of not wanting to take on more business and there’s a constant need to survey your systems instead of focusing on your primary tasks.

As an SMB, our greatest cost was not the ransom itself but the interruption to business operations, lost revenue, and ruined customer trust. To another SMB, there could be regulatory obligations, legal costs, customer attrition and the expense of rebuilding compromised systems often far exceed the attackers’ financial demands. In today’s digital economy, resilience has become just as important as prevention.

AI Has Changed the Economics of Cybercrime

AI has made it a level playing field for both cybersecurity attackers and defense teams. AI has given cybercriminals the ability to automate reconnaissance, generate convincing phishing emails, create fake websites and even develop malware that can evade traditional security controls. Attacks that once took months to prepare can be executed in minutes, allowing attackers to launch highly personalised campaigns at unprecedented scale.

The result is a growing asymmetry, pushing organizations to defend every endpoint, employee, cloud workload and connected device every day, against a single successful compromise to an entire corporate network via a convincing email, a stolen password or an unpatched laptop. Therefore, prevention alone is no longer enough as AI is making it easier for some attacks to bypass traditional security controls, pushing for the need to invest in early detection, investigation and response.

Complexity Has Become the New Vulnerability

Though corporations can invest in more security products, SMBs have limited budgets as each attack needs its own solution. This also leads to more complexity as the fragmented environments need multiple dashboards, overlapping alerts and disconnected workflows. For SMBs, this complexity becomes a significant operational burden, and valuable time is spent managing tools instead of reducing cyber risk. The more complex the environment becomes the more vulnerable the organizations become as these would require more experienced expert teams than general IT managers.

SMBs should not answer by buying more technology, but by simplifying their security operations. This brings a unified visibility across endpoints, cloud environments, identities and networks, allowing security teams to identify threats faster and respond more effectively.

The Human Firewall Still Matters

Despite the fact that an organization can put spend behind beefing up its cybersecurity technology, people remain one of the most important components of any cybersecurity strategy. Phishing, credential theft and social engineering continue to exploit human behaviour far more often than an organization’s technical vulnerabilities.

Every organization should empower its people to become an active layer of defense rather than being viewed as its weakest link. Firms should invest in regular security awareness training, strong password policies, multi-factor authentication and simple incident response procedures. Making people the center of your cybersecurity strategy remains one of the most effective and affordable investments your businesses can make.

This is particularly relevant in Kenya and across Africa, where many growing businesses operate without dedicated cybersecurity teams. Building a security-conscious culture can significantly reduce risk while complementing investments in modern security technologies.

Why Detection and Response Matter More Than Ever

The first line of defense is usually a traditional antivirus software, but modern cyber threats increasingly require broader visibility and faster response capabilities. This has accelerated the adoption of Endpoint Detection and Response (EDR), which continuously monitors endpoint activity to identify suspicious behaviour before attacks escalate.

Many organizations are now extending these capabilities through Extended Detection and Response (XDR), which correlates security data across endpoints, cloud services, email, identities and networks to provide a more complete view of potential threats. By reducing alert fatigue and automating investigations, XDR enables even smaller IT teams to respond more efficiently to sophisticated attacks.

For businesses undergoing digital transformation, unified security platforms provide an opportunity to simplify cybersecurity while improving operational resilience.

Building Business Resilience with Kaspersky Next

The cybersecurity conversation is increasingly shifting from prevention to resilience. The objective is no longer simply stopping every attack, as this is unrealistic, but ensuring organizations can detect threats early, contain incidents quickly and recover with minimal disruption.

This philosophy underpins Kaspersky Next, the company’s enterprise cybersecurity portfolio designed to combine Endpoint Protection, Endpoint Detection and Response (EDR), Extended Detection and Response (XDR), cloud security and automated investigation within a unified platform.

By reducing operational complexity and providing organizations with deeper visibility across their digital environments, Kaspersky Next enables security teams to identify risks earlier and respond more efficiently. Its AI-powered capabilities, including intelligent threat detection, automated investigation, and risk-based prioritization, help security teams spend less time managing alerts and more time addressing genuine threats.

For SMBs with limited cybersecurity resources, integrated platforms also reduce the need to manage multiple disconnected security products, allowing lean IT teams to improve security without significantly increasing operational overhead.

Cybersecurity Is Now a Business Strategy

As Kenya and the wider African continent continue their digital transformation, cybersecurity will increasingly become a defining factor in business success. Organizations that can protect customer data, maintain operational continuity and recover quickly from cyber incidents will enjoy stronger customer confidence, more resilient supply chains and greater competitive advantage.

The businesses that succeed over the coming decade will not necessarily be those with the largest security budgets. They will be those that build resilience by aligning people, processes and technology under a unified cybersecurity strategy.

For African enterprises, this is no longer simply about protecting IT systems. It is about protecting revenue, reputation, customer trust and long-term growth.

In an economy where every business is becoming a digital business, cybersecurity is no longer merely an IT function, it is a business strategy.

View Kaspersky’s practical framework designed for SMBs and small cybersecurity teams to cut complexity and strengthen security posture, here.

Previous articleWayaWaya Appoints Former Chase Bank Executive Raj Singh to Board
Sam Wakoba
Sam Wakoba is a Kenyan technology entrepreneur, media innovator, and digital transformation leader. He is the Founder & CEO of Moran Digital, building technology solutions that empower businesses and institutions across Africa in the age of AI. He is also the Founder & CEO of Moran Media which runs BusinessTech Kenya, CEO Weekends, Startup East Awards & Summit and TechMoran, a popular African technology news and startup platform. With experience across technology, media, fintech, communications, and entrepreneurship, Sam is passionate about using innovation to accelerate Africa’s digital economy and create opportunities through technology. Sam is building Africa’s digital future through Innovation, Technology, and Purpose. Follow him on X: @SamWakoba