Menu

Small businesses, big targets: The evolving cyber threat landscape for SMEs

VIP Guest 9 hours ago

Organisations worldwide continue to fall victim to cyberattacks, but small businesses often face the greatest impact due to limited resources. In Malaysia, where SMEs account for roughly 97% of all business establishments, the impact of a cyber incident can be particularly disruptive. As businesses adopt cloud services, digital payments and AI-powered tools, many SMEs lack the cybersecurity expertise needed to keep pace with evolving threats.

Sophos’ 2025 Threat Report uncovered the trends in cybercrime techniques, tactics and practices used against small- and medium-sized businesses. These trends are also reflected locally, with MyCERT data showing fraud, intrusion and data breaches remain among the most common cybersecurity incidents affecting Malaysians.

This article is contributed byAaron Bugal, Field CISO APJ, Sophos.

Ransomware extends its range to wreak further havoc

Ransomware remains a significant threat even as organisations strengthen their defences. Sophos’ State of Ransomware 2026 found that more than half (56%) of ransomware attacks succeeded in encrypting data, including 16% where data was both encrypted and stolen. This marks an increase from the previous year, showing that attackers are continuing to find ways to cause disruption and increase pressure on victims.

Smaller organisations can be particularly exposed. Only 34% of organisations with 100–250 employees successfully stopped attacks before encryption or extortion, compared with 46% of organisations with 3,001–5,000 employees. For SMEs operating with leaner cybersecurity teams and fewer resources, this narrower margin for error can make the operational and financial impact of an attack especially difficult to absorb.

The dangerous middleman stealing SMEs credentials

Deception tactics used by threat actors to obtain user credentials have also evolved. Multi-factor authentication (MFA) has increased the difficulty to gather user credentials, so cybercriminals have responded with new tactics to capture both credentials and multifactor tokens in real time.

MFA phishing leverages an “adversary-in-the-middle” approach, where the phishing platform acts as a proxy to actual authentication process for the multifactor-protected service. The platform then passes captured credentials and session tokens to the threat actor, enabling access to legitimate services. In Malaysia, similar tactics are often seen in smishing campaigns impersonating banks, e-wallets and delivery services, as well as scam calls claiming to be from organisations such as PDRM, LHDN or MCMC.

AI is compressing the attack clock

AI is changing the cyber threat landscape, not necessarily by creating entirely new ways to attack, but by helping cybercriminals carry out existing techniques much faster. Tasks that previously required significant time and manual effort can increasingly be automated, allowing attackers to move from reconnaissance and initial access to attack execution at greater speed. Sophos has observed threat actors using multiple AI agents to develop and test malicious code, compressing work that could previously have taken weeks into just a few days. This reduces the time defenders have to detect suspicious activity and respond before an attack escalates.

For Malaysian SMEs with leaner IT and cybersecurity resources, this shrinking response window can be particularly challenging. As AI accelerates the speed and scale of attacks, businesses will need to ensure their defences can identify and respond to threats just as quickly.

EDR killers creating an unguarded door for threat actors

Sophos’ 2025 Threat Report also observed the growing availability of "EDR killers" on criminal marketplaces designed to disable endpoint security before ransomware or other malware is deployed.

At the same time, Sophos’ State of Ransomware 2026 highlights the importance of securing the initial point of entry, with 79% of ransomware attacks starting with an identity-based approach, either by obtaining credentials for abuse or exploiting credentials that had already been compromised.

Malicious email (26%) and phishing (24%) were the two most common root causes of ransomware attacks, while compromised credentials accounted for a further 23%, reinforcing the importance of protecting identities alongside endpoint security.

Don’t let size define your cybersecurity expertise

Effective lifecycle management of systems – like routers, firewalls, and VPNs – is crucial to reduce exposure to attacks, particularly since unpatched or unsupported devices are prime targets for cybercriminals conducting large-scale scans.

Prioritising a defence-in-depth strategy is vital and typically requires SMEs to shift their mindsets rather than increase cyber investment. Businesses should strengthen identity protections, deploy phishing-resistant MFA across access points, patch perimeter devices promptly, maintain comprehensive endpoint and email protection, and regularly test backups. Regular attack surface assessments and support from external cybersecurity specialists can also help organisations identify vulnerabilities and respond to threats more effectively.

As Malaysian businesses continue to embrace digitalisation, cloud adoption and AI-powered technologies, cybersecurity can no longer be viewed as a challenge reserved for large enterprises. By adopting these practical steps, small- and medium-sized organisations can significantly strengthen their cybersecurity posture to better defend against today’s sophisticated threats and build greater resilience for the future.

This article is contributed by Aaron Bugal, Field CISO APJ, Sophos

%d