Over Half of SMBs Experience Phishing and Social Engineering Attacks

Stu Sjouwerman | Dec 2, 2019

PonemonThe assertion that SMBs aren’t a cyber-target is officially dead. SMBs are victims of the very same attacks as enterprises in growing numbers, according to new research.

Most SMBs don’t have the same cybersecurity resources as larger organizations, so it’s critical for them to focus on protecting against the most prevalent types of attacks SMBs face.

According to the latest data from Ponemon in their 2019 Global State of Cybersecurity in Small and Medium Businesses report, SMBs are feeling the heat of cyberthreats:

  • 66% experienced a cyberattack in the last 12 months
  • 63% experienced a data breach in the last 12 months
  • 69% say cyberattacks are becoming more targeted
  • 60% say cyberattacks are becoming more sophisticated
  • 61% say cyberattacks experienced are becoming more severe in terms of negative consequences
  • 39% say more time is needed to respond to cyber incidents

So, what are the big attack vectors SMBs are experiencing? According to the research:

  • Social Engineering / Phishing plague 53% of SMBs
  • Web-based attacks (50%)
  • Malware (39%)
  • Compromised or Stolen Devices (37%)
  • Credential Theft (29%)

The big issue here is the use of social engineering; whether as part of a phishing or web-based attacks, the use of social engineering tactics help to draw the victim in, create a sense of urgency, and do enough to cause the victim user to act in the desired way. Users are not educated with Security Awareness Training to be vigilant, looking for indications that an email may be malicious in nature. And in SMBs especially, the lack of a security culture and proper security tools in place is cause enough to focus on aspects of security that will have a material impact on keeping the organization secure.

Ready to Build a Security Culture That Lasts?

Stop treating training like a checkbox exercise. Using 15+ years of behavioral data, our AI-powered platform personalizes training for every user to significantly reduce human risk and stop attacks before they start.

Get a Quote

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.