Cybersecurity threats targeting businesses are becoming increasingly difficult to contain, with Kaspersky reporting that its security tools blocked more than 4.1 million online and on-device attack attempts in Nigeria in the first half of 2026.
The figure comprised more than 1.6 million online attack attempts targeting Nigerian users, including malware attacks involving password stealers, spyware and exploits, while another 2.5 million on-device threats were blocked, including malware delivered through infected USB drives.
The disclosure comes as Kaspersky warned that small and medium-sized businesses (SMBs) are increasingly being exposed to the same range of cyber threats previously associated with larger enterprises.
According to the cybersecurity company, password-stealer detections in Africa increased by 51 percent over the past year, while spyware detections rose by 16 percent and backdoor detections increased by 23 percent.
Kaspersky said the malware categories are particularly concerning because they can be used to gain access to corporate environments, steal confidential information, maintain persistent access to compromised systems and support subsequent stages of cyberattacks.
The company based its assessment on cybersecurity statistics and findings from a global survey conducted by its Internal Research Center, which involved IT security specialists from SMBs and larger enterprises across 18 countries.
The survey found that only 14 percent of businesses with between 100 and 499 employees globally reported avoiding a cyber incident in the past year. In the Middle East, Turkiye and Africa (META) region, the proportion was slightly higher at 18 percent.
Globally, businesses experienced an average of three different types of security incidents over the period under review.
Among SMBs, phishing was the most frequently reported incident, affecting 20 percent of organisations, followed by exploitation of software vulnerabilities at 17 percent and attacks involving external remote access at 16 percent.
In the META region, phishing and software vulnerability exploitation each affected 19 percent of SMBs, while weak or stolen credentials accounted for 18 percent and external remote access for 16 percent.
The findings indicate that businesses are facing threats not only from conventional malware but also from compromised credentials, vulnerabilities in software and remote access systems.
Kaspersky said the growing exposure of smaller businesses reflects the rapid digitalisation of SMBs and the declining cost of launching cyberattacks, which has made them increasingly attractive targets for cybercriminals.
The company noted that threat actors are also exploiting emerging technologies and gaps in organisations’ security controls, making it increasingly difficult for businesses to rely on their size as a form of protection against cyberattacks.
Beyond technology gaps, Kaspersky identified human and organisational weaknesses as significant contributors to cyber risk.
Globally, SMBs ranked insufficient expertise among IT security personnel as the leading factor increasing the likelihood of successful cyberattacks, cited by 24 percent of respondents. This was followed by inadequate cybersecurity awareness among non-IT employees at 23 percent.
Insufficient IT security policies and outdated software and hardware were each cited by 21 percent of respondents, while 20 percent identified the heavy workload of IT security teams as a major risk factor.
The challenges were more pronounced in the META region, where 25 percent of SMB respondents cited insufficient IT security expertise and inadequate IT security policies as major risks.
This was followed by the workload of IT security departments at 24 percent, while 23 percent pointed to a lack of centralised control over IT infrastructure and the presence of shadow IT.
Another 22 percent cited inadequate cybersecurity awareness among employees and business decisions being made without sufficient consideration of IT security implications.
Despite these challenges, businesses are increasing their investment in cybersecurity.
Kaspersky said 75 percent of SMBs globally had increased their cybersecurity budgets this year, compared with 70 percent in the META region.
The survey also showed that 70 percent of SMBs globally and 69 percent in the META region planned to strengthen their IT security functions.
Some of the additional spending is being directed towards expanding IT and security teams, with 41 percent of SMBs globally and 36 percent in META allocating funds for this purpose.
Another 32 percent globally and in META said they had allocated additional funds for cybersecurity training, while 30 percent globally and 24 percent in META planned to adopt more advanced security technologies, including extended detection and response, network detection and response, and security information and event management solutions.
Commenting on the findings, Ilya Markelov, head of Unified Platform Product Line at Kaspersky, said businesses of all sizes were now exposed to increasingly sophisticated cyber threats.
He said growing companies often face budget constraints and difficulties recruiting cybersecurity professionals, making it necessary for security solutions to offer stronger protection without adding excessive complexity.
For SMBs, Kaspersky recommended strengthening internal access controls, promptly revoking employee permissions when staff leave organisations and incorporating automated data backups into daily operations.
The company also advised businesses to improve employee awareness through regular cybersecurity training, particularly around phishing, vishing and deepfakes, while ensuring that new software installations are subject to appropriate IT approval.
Kaspersky further recommended that businesses adopt cybersecurity solutions that match their size, budgets and industry requirements, with emphasis on scalability and ease of management.





