Skip to content

Kaspersky Study: 90 Percent of European SMEs Reported Security Incidents Last Year

Bottom line: 90 percent of European SMEs reported at least one security incident last year, with a lack of expertise cited more often than insufficient technology as the cause.

A recent Kaspersky survey shows that nearly all small and medium-sized enterprises in Europe experienced at least one cyber incident in the past year. The cause is seen less in a lack of security technology than in insufficient expertise within IT and security teams.

Only ten percent of the European SMEs surveyed said they had not experienced a security incident in the past year. Phishing remains the most common attack vector at 23 percent. In addition, companies increasingly report more complex methods: 18 percent report attacks that exploited vulnerabilities related to artificial intelligence. 15 percent each were affected by software vulnerabilities, business email compromise, supply chain attacks, or deepfakes.

The attribution of causes is notable: 24 percent of companies see insufficient expertise in IT and security teams as a key risk factor, 22 percent cite weaknesses in security leadership or low employee engagement, and 21 percent point to a lack of security awareness. In contrast, only 16 percent name the absence of suitable security solutions as the main cause. For CISOs, this means that investing in technology alone falls short if know-how, clear responsibilities, and a lived security culture are missing.

Companies are responding accordingly by increasing budgets: 74 percent of the SMEs surveyed have raised their cybersecurity budget this year. The focus is on personnel — 36 percent are expanding their IT and security teams, 35 percent are investing in protecting remote and hybrid work environments, and 34 percent in cloud and hybrid infrastructures. Also 34 percent are allocating additional funds for security training, 32 percent plan to deploy more comprehensive platforms such as XDR, NDR, or SIEM. 65 percent intend to further develop existing security functions.

Sören Kohls, Head of Channel DACH at Kaspersky, points to the shortage of skilled workers as a limiting factor: fragmented defense mechanisms can easily be bypassed by highly sophisticated attacks, which is why both advanced technology and experienced teams are needed. At the same time, security solutions need to be easier to operate so that not every additional tool requires highly specialized personnel — an argument for centrally manageable, automated platforms with lower administrative overhead. At the same time, attackers are also increasingly using AI to make their campaigns more efficient and complex.


Source: www.it-daily.net · Published August 13, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: