Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      Woan's ghost exorcised - Solly Malatsi

      Woan’s ghost exorcised

      25 September 2026
      Eskom's profit doubles even as it sells less electricity - Mteto Nyati

      Mteto Nyati to stay on as Eskom chairman

      25 September 2026
      Meta's new gadget is a pocket watch for its viral AI agent - Muse Charm

      Meta’s new gadget is a pocket watch for its viral AI agent

      25 September 2026
      Insurers carry the can for MIP breach, regulators say

      Insurers carry the can for MIP breach, regulators say

      25 September 2026
      South Africa's car exports face an EV reckoning

      South Africa’s car exports face an EV reckoning

      25 September 2026
    • World
      Anthropic weighs new model launch to blunt OpenAI's Astra surge - Anthropic CEO Dario Amodei and OpenAI CEO Sam Altman

      Anthropic weighs new model launch to blunt OpenAI’s Astra surge

      21 September 2026
      Hackers hack hackers: ShinyHunters seizes cl0p's dark web site

      Hackers hack hackers as dark web feud erupts

      21 September 2026
      Film piracy malware is reaching corporate machines

      Film piracy malware is reaching corporate machines

      21 September 2026
      Crypto's big bet fails as US senate sinks Clarity Act

      Crypto’s big bet fails as US senate sinks Clarity Act

      16 September 2026
      'This is not circular': Jensen Huang defends $3.5-billion MediaTek deal

      ‘This is not circular’: Jensen Huang defends $3.5-billion MediaTek deal

      2 September 2026
    • In-depth
      Meta to the AI industry: slow down without us - Mark Zuckerberg

      Meta to the AI industry: slow down without us

      16 September 2026
      Google DeepMind CEO Demis Hassabis. Image: John Sears

      The plan to stop AI from breaking the world

      16 July 2026
      The internet has a Strait of Hormuz problem

      The internet has a Strait of Hormuz problem

      15 July 2026
      AI boom sparks rally, frenzy and fear

      AI boom sparks rally, frenzy and fear

      11 June 2026
      Every plug-in hybrid on sale in South Africa, ranked by price - Lamborghini Temerario

      Every plug-in hybrid on sale in South Africa, ranked by price

      7 June 2026
    • TCS
      TCS | Octotel's Trevor van Zyl on the fibre merger question

      TCS | Octotel’s Trevor van Zyl on the MetroFibre merger question

      16 September 2026
      Meet the CIO | Shoprite's Chris Shortt on what a supermarket becomes

      Meet the CIO | Shoprite’s Chris Shortt on what a supermarket becomes

      9 September 2026
      Rubicon's EV charging network is profitable - and growing fast - Watts & Wheels

      Rubicon’s EV charging network is profitable – and growing fast

      8 September 2026
      Winstone Jordaan on building a national EV charging network

      Winstone Jordaan on building a national EV charging network

      2 September 2026
      Watts & Wheels S1E8: 'Tesla lands in Africa, just not here'

      Watts & Wheels S1E8: ‘Tesla lands in Africa, just not here’

      24 August 2026
    • Opinion
      Regulating AI: apply the laws we have first - Dirk de Vos

      Regulating AI: apply the laws we have first

      21 September 2026
      The end is nigh, and the shares go on sale in October - Duncan McLeod

      The end is nigh, and the shares go on sale in October

      14 September 2026
      The fragile joint in the Capitec machine - Pambos Soteriades

      The R197-billion market the banks can’t reach

      25 August 2026
      South African tech's compounding debt problem - Jannie van Zyl

      Management consulting as we know it is over

      21 August 2026
      South African tech's compounding debt problem - Jannie van Zyl

      The most dangerous customer is the quiet one

      10 August 2026
    • Company Hubs
      • 1Stream
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • Ascent Technology
      • AvertITD
      • BBD
      • Braintree
      • CallMiner
      • CambriLearn
      • CM.com
      • Contactable
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • HOSTAFRICA
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • Kaspersky
      • LSD Open
      • Mitel
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Telviva
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Vox
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • HealthTech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Policy and regulation
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
      • Watts & Wheels
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Sections » Information security » Finding focus: a strategic approach to cybersecurity for SMBs

    Finding focus: a strategic approach to cybersecurity for SMBs

    Promoted | Ransomware, phishing and skills shortages don't require an enterprise budget to address, says Kaspersky.
    By Kaspersky6 July 2026
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    Get breaking news on WhatsApp

    Finding focus: a strategic approach to cybersecurity for SMBs - Kaspersky

    Small and medium-sized businesses (SMBs) hold valuable data, serve as entry points into larger supply chains and often lack the defences of enterprise organisations. These facts alone make SMBs an attractive target for cyberattacks. Their top challenges include the rise of commoditised ransomware, phishing attacks and staff shortages. Each of these issues poses a significant risk and can overwhelm lean teams.

    The good news is that none of them requires an enterprise budget to address. The solution in each case is the same: reduce complexity, consolidate visibility and build on what your existing team can realistically manage.

    Challenge 1: The commoditisation of ransomware

    Ransomware was once the domain of sophisticated, well-resourced criminal groups. That is no longer the case. The rise of ransomware as a service means that relatively low-skilled attackers can now purchase pre-built ransomware kits and deploy them against businesses of any size.

    For SMBs, this shift is significant. Ransomware groups have also become more targeted and financially precise, calculating their demands based on what a victim can plausibly pay. Around half of organisations globally now consider ransomware their top cyber risk, according to the World Economic Forum.

    Addressing this requires a layered approach rather than a single tool. Anti-ransomware protection driven by machine learning can block known threats automatically, while AI-powered behavioural analytics can identify suspicious patterns that signature-based controls miss. Automating endpoint isolation limits how far an attack can spread, and alert aggregation helps teams investigate potential incidents without being overwhelmed. Regular data backups and user awareness training round out a strategy that treats ransomware as a constant, manageable risk rather than a catastrophe.

    Challenge 2: Most breaches involve the human element

    Phishing continues to be one of the most effective initial attack vectors, largely because it targets the one element no technical control can fully secure: human judgment. Modern phishing attacks are convincing, often exploiting legitimate-looking e-mails, trusted sender identities and, increasingly, AI-generated content that personalises messages at scale.

    The statistics make uncomfortable reading. User execution and phishing techniques rank among the top three threats, according to Kaspersky’s “Anatomy of a Cyber World: 2026 Security Services Global Report”, demonstrating that users are still a weak link. For many SMBs, the organisational structures and resources that large enterprises use to build a strong human firewall simply do not exist.

    An effective defence needs to work across three dimensions simultaneously:

    • Process controls, such as multi-person authorisation for high-value transactions and tightly governed access to sensitive data, reduce the blast radius when someone does click;
    • People-focused training that is continuous rather than periodic, with automatic re-enrolment triggered by risky behaviour, turns mistakes into learning moments; and
    • Technology that provides real-time scanning of e-mails, links and attachments, combined with behavioural controls that act after a click, provides the technical backstop.

    None of these layers alone is sufficient. Together, though, they significantly reduce both the likelihood and the impact of a successful phishing attack.

    Challenge 3: Staff shortages and the skills gap

    Three-quarters of businesses globally consider the cybersecurity skills shortage a serious issue, according to Kaspersky data. For SMBs, the consequences are particularly acute. Most cannot compete for dedicated security talent, which means general IT staff often serve as the de facto first line of defence against sophisticated threats they were never trained to handle.

    A dangerous middle ground exists. Advanced cybersecurity training is too specialised for IT generalists, while basic cyber hygiene programmes don’t equip them to investigate or respond to real incidents. The result is that skilled attackers slip through gaps that a dedicated security team might catch.

    The sustainable response is to deliberately upskill existing IT staff into cyber first responders. For generalists and system administrators, this means building practical skills in incident response fundamentals, secure cloud configuration and working effectively with endpoint detection and response (EDR) and extended detection and response (XDR) tools. IT teams benefit from training that helps them recognise and triage security alerts, not just IT tickets.

    Formalising security responsibilities in job descriptions helps ensure these capabilities are retained and developed over time, and investment in training can improve employee loyalty, reducing the churn that compounds the skills gap in the first place.

    Building resilience without building complexity

    The common thread running through each of these challenges is complexity. SMBs are making diligent efforts to take cybersecurity seriously, but they are struggling to keep pace with a threat environment that has evolved more rapidly than their tools and teams can manage. Adding more products rarely solves this problem – in fact, it frequently deepens it, increasing alert volume, integration overhead and the risk of coverage gaps.

    The more effective path is consolidation: converging prevention, detection, response and awareness into platforms that are genuinely manageable by small teams. To protect against the wide range of threats targeting SMBs, organisations can look to solutions such as Kaspersky Next Optimum, which provides real-time protection, threat visibility, and investigation and response capabilities spanning both EDR and XDR, adapted for lean teams. Companies that don’t have the time or resources to develop internal expertise can instead gain robust managed protection through a tailored managed extended detection and response (MXDR) solution.

    When complexity decreases, resilience follows. Incidents are contained faster, downtime is reduced and teams regain the capacity to be proactive rather than permanently reactive. SMBs can explore how to enhance their security posture with Kaspersky’s expert guidance tailored specifically for their environment, and use that knowledge to strengthen their processes and build solid cyber resilience.

    • Read more articles by Kaspersky on TechCentral
    • This promoted content was paid for by the party concerned
    Add TechCentral as a preferred source on GoogleFollow TechCentral on Google NewsGet breaking news on WhatsApp


    Kaspersky
    WhatsApp YouTube
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleWhy voice-first communication matters more in the AI era
    Next Article Eskom chair and business lobby in open war over grid reform

    Related Posts

    Film piracy malware is reaching corporate machines

    Film piracy malware is reaching corporate machines

    21 September 2026
    How to build a security operations centre that actually works - Kaspersky

    How to build a security operations centre that actually works

    3 September 2026
    Kaspersky on how to secure a supply chain you do not control

    Kaspersky on how to secure a supply chain you do not control

    13 August 2026
    Add A Comment

    Comments are closed.

    Company News
    The Courier Guy enhances customer engagement with Telviva

    The Courier Guy enhances customer engagement with Telviva

    23 September 2026
    Pinnacle takes its channel to Mauritius for TechScape 2026

    Pinnacle takes its channel to Mauritius for TechScape 2026

    23 September 2026
    Why true customer enablement starts on the inside - Backspace Technologies COO Graeme Thomson

    Why true customer enablement starts on the inside

    23 September 2026
    Opinion
    Regulating AI: apply the laws we have first - Dirk de Vos

    Regulating AI: apply the laws we have first

    21 September 2026
    The end is nigh, and the shares go on sale in October - Duncan McLeod

    The end is nigh, and the shares go on sale in October

    14 September 2026
    The fragile joint in the Capitec machine - Pambos Soteriades

    The R197-billion market the banks can’t reach

    25 August 2026

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    Woan's ghost exorcised - Solly Malatsi

    Woan’s ghost exorcised

    25 September 2026
    Eskom's profit doubles even as it sells less electricity - Mteto Nyati

    Mteto Nyati to stay on as Eskom chairman

    25 September 2026
    Meta's new gadget is a pocket watch for its viral AI agent - Muse Charm

    Meta’s new gadget is a pocket watch for its viral AI agent

    25 September 2026
    Insurers carry the can for MIP breach, regulators say

    Insurers carry the can for MIP breach, regulators say

    25 September 2026
    © 2009 - 2026 NewsCentral Media
    Built and maintained by Chronon
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}
    🇿🇦 Sign up to the TechCentral newsletter