This page was machine-translated and may differ from the original. View original
Software Vulnerability Exploitation, Phishing, and Malware—Three Major Threats
Nearly 9 out of 10 SMBs in the Asia-Pacific (APAC) region have experienced cybersecurity incidents within the past year. Attackers are applying the same attack techniques to smaller companies that they use against large enterprises, making the strengthening of security systems for SMBs an urgent priority.
Kaspersky announced its '2026 SMB Threat Landscape Report' on the 7th.
According to a survey conducted by Kaspersky's Internal Research Center targeting a total of 1,800 IT security professionals across 18 countries, in the APAC region only 13% of companies with fewer than 500 employees had not experienced cybersecurity incidents over the past year.
By country, Vietnam had the highest incident experience rate at 97%, followed by Malaysia at 95%, Indonesia at 92%, and India at 87%.
Thailand and China fell below the APAC average at 82% and 67%, respectively.
Companies in the APAC region experienced an average of three types of security incidents over the past year.
The most frequently occurring incident types among SMBs were △software vulnerability exploitation (20%), △phishing (19%), and △large-scale malware attacks (18%).
Zero-day attacks occurred at a low frequency of 6%, but companies exposed to this type of threat reportedly suffered severe damage.
Regarding internal factors that increase the likelihood of successful attacks, insufficient security awareness among non-IT employees (26%) was cited most frequently.
This was followed by lack of expertise among IT security personnel (24%), outdated software or hardware (23%), insufficient regular risk assessments (22%), and lack of necessary security solutions (22%).
In response to rising threats, 75% of companies in the APAC region plan to strengthen their IT security capabilities.
78% of SMBs have already increased their cybersecurity budgets this year.
The allocation of additional budgets ranked as follows: △IT and security personnel expansion (48%), △adoption of advanced security solutions such as XDR, NDR, and SIEM (32%).
Ilya Markelov, Director General of Kaspersky's Unified Platform Product Group, stated, "Sophisticated attacks can easily bypass fragmented security defense systems, requiring advanced tools and specialized personnel, but growing-stage companies often face difficulties due to budget constraints and personnel shortages. Modern cybersecurity solutions must evolve in a direction that reduces complexity while delivering greater security with fewer resources."
Kaspersky recommended the following for strengthening security in SMBs: △establishing internal security processes, △implementing security awareness training for employees, and △deploying security solutions suitable for company size and budget.
For product offerings, Kaspersky presented Kaspersky Small Office Security Premium for small companies with fewer than 50 employees, Kaspersky Next Optimum with advanced detection and response capabilities, and Kaspersky Security for Mail Server for email threat response.
To request a correction, reply or follow-up report on this article, see how to file a request. Previously published statements are collected in corrections & replies.















