Promoting and enhancing cybersecurity among small and medium-sized enterprises for the sustainable development: trends and best practices
This panel discussion focused on promoting and enhancing cybersecurity among small and medium-sized enterprises (SMEs) as a matter of sustainable development, examining the threat landscape, best practices, and multistakeholder cooperation .
Charles Odii, Director General of Nigeria's SMEDAN, underscored the economic significance of SMEs, noting that Nigeria alone has approximately 39 million SMEs, which contribute around 50% of GDP and employ some 16 million people . He emphasised that most SMEs lack the financial resources and manpower to invest in cybersecurity, unlike large corporations or government bodies that have dedicated budgets and teams . Arik Banihardi of the National Cyber Security Agency of Indonesia (BSSN), reinforced this point, noting that over 64 million SMEs account for 99% of all business units in Indonesia, contributing more than 60% to national GDP and absorbing over 90% of the workforce .
Yulia Shlychkova of Kaspersky outlined the key cyber threats facing SMEs, including malicious programmes disguised as legitimate software tools, fake AI services - with attacks of this type increasing fivefold in the first half of the year - and phishing campaigns targeting business credentials and banking accounts . Sheila Birgen of the Digital Cooperation Organisation (DCO) added that AI, while offering SMEs significant opportunities to increase productivity and lower costs, also introduces new risks, and that a lack of confidence and trust remains a primary barrier to digital adoption .
On solutions, panellists converged on a three-pillar approach encompassing technology, processes, and people . BSSN promotes a four-stage framework of awareness, self-assessment, cyber hygiene, and resilience-building, supported by a practical self-assessment tool called Paman Kami . DCO's WeElevate initiative supports over 10,000 micro and small businesses, building capacity holistically across founders and their teams .
Panellists unanimously debunked the myth that cybersecurity is only relevant to large enterprises, stressing that SMEs are deeply embedded in digital supply chains and that their vulnerabilities affect national economic resilience and consumer trust as a whole . The discussion concluded with broad agreement that securing SMEs requires collaborative effort from governments, technology providers, international organisations, and the SMEs themselves, with accessible, affordable, and scalable solutions being essential to meaningful progress .
Overall Purpose
- The discussion aims to examine the cybersecurity challenges facing small and medium-sized enterprises (SMEs), explore the threat landscape in which they operate, and identify best practices, policy approaches, and collaborative strategies to enhance their cyber resilience as part of broader sustainable economic development.
- --
Major Discussion Points
- The critical economic role of SMEs and their vulnerability to cyber threats: SMEs represent a disproportionately large share of national economies - for example, Nigeria has approximately 39 million SMEs contributing around 50% of GDP and employing 16 million people , while Indonesia's 64 million SMEs account for over 60% of national GDP and 90% of the workforce . Despite this importance, SMEs are attractive targets for cyber criminals precisely because they lack the manpower, budgets, and robust security frameworks of larger enterprises . Attackers view SMEs not only as direct targets for financial gain but also as entry points into larger enterprises and national ecosystems .
- The evolving cyber threat landscape for SMEs, including AI-related risks: Three key attack vectors were identified as particularly prevalent: malicious programmes masquerading as legitimate software tools, fake AI services exploiting SMEs' growing adoption of AI (with attacks of this type increasing fivefold in the first half of the year, with 30,000 such attacks detected) , and phishing and scam campaigns targeting business credentials, banking accounts, and social media . The dark web trade in SME credentials was highlighted as a lucrative and growing market .
- The role of AI as both an opportunity and a risk for SMEs: AI was identified as a potential equaliser for SMEs, enabling them to increase productivity, lower operating costs, conduct market research, and accelerate growth in ways previously only accessible to large enterprises . However, the transition to AI - and digital tools more broadly - is hindered by a lack of confidence and trust among SME owners . Cybersecurity was framed as foundational to building that trust, without which digital transformation, including AI adoption, cannot be sustained .
- Multi-stakeholder and government-led approaches to strengthening SME cyber resilience: Speakers emphasised that no single actor can address SME cybersecurity alone . Indonesia's BSSN outlined a four-stage framework - awareness, self-assessment, cyber hygiene, and resilience building - supported by a practical self-assessment tool called Paman Kami . Nigeria's SMEDAN highlighted the importance of policy reform and public-private partnerships, including free cybersecurity tools provided through collaboration with Kaspersky . Kaspersky recommended a balanced approach across technology, processes, and people, noting that scalable, affordable solutions exist for businesses of all sizes .
- International cooperation as essential to SME cyber resilience: The Digital Cooperation Organisation (DCO) highlighted that SMEs across its 16 member states face varying levels of digital maturity, and that international platforms enable countries and entrepreneurs to learn from one another rather than facing challenges in isolation . The WeElevate initiative was cited as an example of holistic support - covering awareness, domestic e-commerce, and export readiness - that builds both digital capability and cyber confidence across borders . International cooperation was framed as critical not merely for threat mitigation but for enabling full and equitable participation in the digital economy .
- --
Overall Tone
- The overall tone of the discussion is constructive, collaborative, and solutions-oriented. From the outset, the moderator and panellists frame cybersecurity not as an insurmountable obstacle but as a shared challenge requiring coordinated action . There is a consistent sense of urgency - particularly when discussing the scale of threats and the economic stakes involved - but this is balanced by optimism about available tools, partnerships, and frameworks. The tone remains professional and measured throughout, with speakers building on one another's contributions. Towards the end, during the myth-busting segment and audience Q&A, the tone becomes slightly more accessible and conversational , as panellists seek to demystify cybersecurity and make it feel approachable for SME leaders.
Expanded Summary: Promoting and Enhancing Cybersecurity Among SMEs for Sustainable Development
#
Session Overview and Context
This panel discussion, convened at an international forum, focused on promoting and enhancing cybersecurity among small and medium-sized enterprises (SMEs) as a matter of sustainable development . Moderated by Dina Matar, the session brought together policymakers, cybersecurity experts, and industry representatives to examine the threat landscape facing SMEs, share experiences from existing initiatives and partnerships, and outline best practices for achieving cyber resilience . The panel comprised Charles Odii, Director General and CEO of the Small and Medium Enterprises Development Agency of Nigeria (SMEDAN); Sheila Birgen, Innovation Driven Market Director of the Digital Cooperation Organization (DCO); Yulia Shlychkova, Vice President of Global Public Affairs at Kaspersky; and Arik Banihardi, Senior Cryptographer at BSSN, Indonesia's Directorate of Cybersecurity and Cryptography for Finance, Trade and Tourism . The moderator framed the session around three interconnected themes: the threat landscape for SMEs, the multi-stakeholder approach to promoting cybersecurity, and best practices for building cyber resilience .
#
The Economic Importance of SMEs and Their Vulnerability
A foundational theme running throughout the discussion was the critical economic role played by SMEs and the paradox that their very importance makes their cybersecurity vulnerability a matter of national concern. Charles Odii opened by noting that Nigeria alone has approximately 39 million small and medium businesses, contributing around 50% of the country's GDP and employing approximately 16 million people . He drew comparisons with other emerging economies such as Vietnam and India, emphasising that SMEs are not peripheral actors but the engines that keep economies moving . Critically, Odii observed that many SMEs - ranging from one- or two-person operations to businesses employing up to 200 people - simply do not have the financial resources or manpower to invest in cybersecurity, in stark contrast to large corporations and government bodies that maintain dedicated budgets and teams for this purpose .
Arik Banihardi reinforced this picture from an Indonesian perspective, noting that Indonesia has more than 64 million SME units representing approximately 99% of all business units in the country, contributing more than 60% to national GDP and absorbing over 90% of the national workforce . He further highlighted that around 27 million Indonesian SMEs have already adopted digital technology, with that number continuing to grow . Sheila Birgen added a global dimension, observing that SMEs - particularly women-led and youth-led businesses - are the majority supporters of most economies globally, yet their growth tends to be slower than that of startups, making sustained support all the more important . Dina Matar framed SMEs as critical links in value chains and critical supply chains, underscoring why their security posture has implications far beyond the individual business .
#
The Cyber Threat Landscape for SMEs
Yulia Shlychkova provided the most technically detailed account of the cyber threat landscape facing SMEs, drawing on Kaspersky's global threat intelligence. She challenged the widespread misconception that small businesses are unattractive targets for attackers, explaining that cybercriminals do not think about the size of a business but rather about how easy it is to penetrate . Limited manpower and budgets make SMEs highly accessible targets, and Shlychkova identified three primary attack vectors .
The first vector involves malicious programmes that masquerade as legitimate software tools - such as messaging applications and productivity suites - which, once downloaded, can steal data and credentials or encrypt files with potentially catastrophic consequences . The second, and rapidly growing, vector involves attackers impersonating legitimate AI services. Shlychkova revealed that in the first half of the year alone, Kaspersky's systems detected 30,000 attacks of this type targeting SMEs - a fivefold increase compared to the previous period - with attackers specifically impersonating ChatGPT, Claude, and DeepSeek . The third vector encompasses phishing and scam campaigns designed to lure businesses into surrendering their credentials, corporate social media accounts, Google Business accounts, or banking details, often by exploiting SMEs' legitimate interest in securing financing or business loans . Shlychkova also noted that the dark web trade in SME credentials is a lucrative and growing market, further incentivising attacks .
A particularly significant observation from Shlychkova was that SMEs are targeted not only for direct financial gain but also by advanced cyber espionage groups seeking to use them as proxies to penetrate larger enterprises or national ecosystems . This reframing - from SME cybersecurity as a business-level concern to a matter of national cyber resilience - proved to be one of the most intellectually consequential contributions of the session, setting the stage for subsequent discussions about systemic risk and shared responsibility .
#
The Dual Role of AI: Opportunity and Risk
The discussion devoted considerable attention to artificial intelligence, which emerged as both a transformative opportunity for SMEs and a significant new attack surface. Sheila Birgen argued that AI functions as an equaliser for SMEs, enabling them to increase productivity, lower operating costs, conduct market research, make better decisions, and accelerate growth in areas where progress had previously stagnated - capabilities that had historically been accessible only to large enterprises . Through DCO's WeElevate initiative, which has supported more than 10,000 micro and small businesses across its member states in a single year, Birgen observed first-hand how AI is beginning to transform the prospects of smaller businesses .
However, Birgen introduced an important qualification: the transition to digital tools, including AI, is hindered not primarily by technology gaps but by a lack of confidence rooted in distrust . She argued that if SME owners do not feel safe enough to transition to the digital economy or use digital tools, AI is no exception to that reluctance, and that this is precisely where the cybersecurity conversation becomes critical . Without addressing confidence and trust, she warned, the same conversations about digital transformation would be repeated in five or ten years without meaningful progress .
Shlychkova's data on AI-masquerading attacks provided a sharp counterpoint to the optimistic framing of AI's potential, illustrating that the very platforms being promoted as productivity tools for SMEs are simultaneously being weaponised against them . Dina Matar synthesised both perspectives, acknowledging that AI is being used both as a tool for digital transformation and as a source of concern in cybersecurity . This duality - AI as equaliser and AI as attack vector - was not fully resolved in the session but represented one of its most intellectually generative tensions.
#
Real-World Consequences of Cyber Exploitation
Arik Banihardi provided a detailed account of the real-world consequences of cyber exploitation for SMEs, grounding the discussion in concrete operational realities. He argued that what is at stake extends far beyond systems, applications, or data, encompassing livelihoods, business continuity, customer trust, digital payment confidence, and local economic resilience . He outlined specific risk scenarios: SMEs using digital payment systems may face fraud and account takeover, directly affecting daily income; those using e-commerce or social commerce may suffer credential theft, fake administrator schemes, or impersonation, resulting in loss of sales and customer trust; those using unmanaged devices may face operational disruption; and those dependent on logistics platforms or third-party services may find that a disruption in one part of the chain affects their ability to deliver products and services .
Banihardi emphasised that a cyber incident for an SME can immediately become a business continuity crisis, given that small businesses typically lack the financial buffers, technical teams, or recovery capacity of larger enterprises . At scale, he argued, the consequences extend beyond individual businesses: widespread SME cyber incidents can reduce trust in digital payment systems, undermine consumer confidence in online transactions, and disrupt local supply chains . Crucially, Banihardi reframed the entire cybersecurity challenge as fundamentally a question of trust - trust in digital platforms, payment systems, between SMEs and their customers, and in the digital economy as a whole - arguing that strengthening SME cybersecurity is inseparable from enabling sustainable digital transformation .
#
Best Practices and Recommendations
On the question of solutions, panellists converged on a multi-dimensional approach that balances technology, processes, and people. Shlychkova described this as a pyramid in which all three elements must be in balance . On the technology side, she recommended that SMEs use cybersecurity protection solutions scaled to their size and needs, noting that vendors including Kaspersky offer solutions suitable for businesses with or without dedicated IT security teams, from two to two hundred people . On the process side, she recommended hardening existing systems by reviewing access to sensitive systems and financial transactions, ensuring strong passwords, and implementing two-factor authentication - measures that, she argued, require only 20% of effort but can deliver 80% of the security benefit . On the people side, she stressed that even a one-person operation must take cybersecurity seriously and build awareness, noting that being aware of the problem means being half prepared, and that free awareness materials and online courses are widely available .
Banihardi outlined BSSN's four-stage practical framework for SMEs: awareness, self-assessment, cyber hygiene, and resilience-building . The awareness stage focuses on helping SMEs understand that cybersecurity is about protecting trust and business continuity, not merely computers and systems . The self-assessment stage encourages SMEs to understand their own cybersecurity condition, identify gaps, and prioritise improvements . The cyber hygiene stage promotes basic, repeatable practices - including strong passwords, multi-factor authentication, regular backups, device security, anti-phishing awareness, and access control - which are not always expensive but are highly effective . The resilience-building stage encourages SMEs to develop a continuity and recovery mindset, asking not only how to prevent incidents but how to keep operating and recover when disruption occurs .
A practical embodiment of this framework is Paman Kami - an acronym in Bahasa Indonesia for "Information Security Self-Assessment Tool for SMEs" - which BSSN developed to help SMEs understand their current information security practices, identify gaps, and prioritise improvements . Banihardi emphasised that Paman Kami is designed as a capacity-building instrument rather than a compliance burden, helping SMEs move from not knowing where to start to knowing what to improve first . The tool operates through a structured process of socialisation, self-assessment, verification, and monitoring and evaluation .
#
Government Policy and Public-Private Partnerships
Charles Odii addressed the role of government policy and public-private partnerships in incentivising SME cybersecurity adoption. He noted that many SMEs have never tried cybersecurity tools before, and that the most effective way to encourage adoption is to allow businesses to experience the benefits firsthand through discounted or free access, enabling them to see how protection translates into revenue security over a period of months . He described a double-edged approach: incentivising awareness on one hand, and reforming policy to ensure that every small business owner protects themselves - particularly those processing data from third parties - on the other . He also noted that Nigeria is in the process of reviewing its national MSME policy, with cybersecurity identified as a key component alongside intellectual property protections and provisions addressing the needs of women and youth entrepreneurs .
A concrete example of this approach is the partnership between SMEDAN and Kaspersky, through which free cybersecurity tools and educational webinars have been made available to Nigerian SMEs . Odii used the analogy of gradually heating water to describe the philosophy behind this approach: rather than demanding an abrupt transition from zero to full cybersecurity compliance, the goal is to gradually bring SMEs into the cybersecurity ecosystem, educate them, and allow them to discover the value of protection for themselves . This gradual onboarding model was presented as a practical compromise between the cost concerns of SMEs and the urgent need for improved security posture.
#
Multi-Stakeholder and International Cooperation
A consistent theme across all speakers was that no single actor can address SME cybersecurity alone, and that effective solutions require coordinated multi-stakeholder cooperation. Banihardi outlined the roles of different actors in Indonesia's approach: BSSN provides guidance and security frameworks; local governments support outreach and capacity building; digital platforms and cloud providers should make security easier for SMEs; financial institutions can help with fraud prevention and trusted payment practices; and SME associations and communities can deliver messages in practical and relatable ways . He also highlighted the complementary role of cybersecurity service providers such as Kaspersky in offering affordable, easy-to-use, SME-friendly solutions that government alone cannot provide .
Shlychkova articulated the shared responsibility principle most directly, stating that cybersecurity is not just the individual SME's problem but a collective concern for companies, governments, and organisations alike, because cyber incidents affect the economy, society, and the future . This framing validated the multi-stakeholder approaches described by other panellists and provided a unifying ethical foundation for the session's policy recommendations.
Sheila Birgen highlighted the specific contribution of international organisations to this ecosystem. She noted that DCO's 16 member states span a wide range of digital maturity levels, meaning that cybersecurity challenges differ significantly across countries and that a diversity of experience creates opportunities for mutual learning . International cooperation, she argued, enables countries and entrepreneurs to share best practices and leverage lessons from one another rather than facing challenges in isolation . She framed cyber resilience in the context of international cooperation not merely as threat mitigation but as a means of enabling entrepreneurs to participate fully and equitably in the digital economy .
Birgen illustrated the importance of sustained digital participation with a vivid example: an entrepreneur who begins attracting customers through social media but then loses everything to a cyber incident has little reason to continue engaging with the digital economy and may simply revert to offline operations . This observation reinforced the view that cybersecurity is not merely a technical safeguard but a prerequisite for inclusive and sustained digital economic participation.
DCO's WeElevate initiative was presented as a model of holistic international support. Rather than focusing solely on the business founder, WeElevate builds capacity across the entire business entity, including the team . It progresses through a phased digital growth model: awareness, domestic e-commerce trading, export readiness, and international selling, with cybersecurity integrated throughout rather than treated as a separate or preliminary requirement . This graduated approach is designed to ease SMEs into the digital economy without overwhelming them with complexity, starting with local platforms and familiar payment gateways before introducing the additional compliance and logistical demands of international markets . Birgen also noted that because WeElevate serves a large number of countries, it enables businesses to become peer mentors to one another across borders, creating networks of shared experience and mutual support .
#
Debunking Cybersecurity Myths
The session concluded with a myth-busting segment in which panellists were invited to identify one cybersecurity misconception they would want SME leaders to stop believing. The responses were revealing both for their content and for the degree of convergence they demonstrated across very different institutional perspectives.
Birgen challenged the myth that cybersecurity is only relevant to large enterprises and governments, calling it "a big lie" and arguing that small businesses have a vital role to play and that their insecurity can expose everyone else in society . She also challenged the related myth that cybersecurity is solely about technology, reframing it as a matter of confidence, customer protection, and full participation in the digital economy - using the analogy of locking a door to illustrate how cybersecurity builds rather than constrains confidence . Shlychkova's myth-busting contribution centred on shared responsibility: she argued that a cyber incident affecting one SME is not merely that business's problem but a collective concern requiring cooperation from all stakeholders - companies, governments, and organisations alike . Banihardi addressed a closely related misconception, reinforcing that SMEs are already embedded in the digital ecosystem through payments, marketplaces, social media, and cloud applications, meaning they are already exposed to cyber risk regardless of whether they recognise it . It is worth noting that both Birgen and Banihardi independently challenged the notion that cybersecurity is the exclusive concern of large enterprises, reflecting the strength of this misconception across different national and institutional contexts.
#
Audience Questions and Unresolved Issues
The session's audience Q&A surfaced two important issues that were only partially addressed. The first, raised by Ife Inwa from Nigeria, concerned the role of cyber threat intelligence in enabling SMEs to protect themselves collectively, given that multiple businesses are often attacked using the same techniques, tactics, and procedures . Shlychkova affirmed the value of threat intelligence for medium-sized businesses, noting that it is increasingly packaged as machine-readable data feeds that can be integrated into cybersecurity solutions to search for specific indicators of compromise . Banihardi, however, suggested that the topic warrants a dedicated forum, as SMEs face more direct and immediate cyber attacks rather than the sophisticated threat intelligence scenarios relevant to larger organisations . This brief but notable divergence illustrated a genuine difference in how the two speakers assess the practical relevance of threat intelligence tools for the SME segment.
The second question, from an unnamed audience member, raised the challenge of bridging the gap between the technical risk perspective of cybersecurity professionals and the financial mindset of business managers who view cybersecurity as an additional expense rather than a protective investment . Odii's response focused on the gradual onboarding model - offering free tools to allow SME owners to experience the value of protection firsthand before committing financially - as a practical mechanism for shifting this perception . However, a more comprehensive framework for aligning technical and financial perspectives on cybersecurity investment was not fully developed within the session, representing one of several issues that remain open for further exploration.
#
Overall Assessment
The discussion was characterised by a high degree of consensus across speakers from markedly different institutional backgrounds - an SME development agency, a digital cooperation organisation, a global cybersecurity company, a national cybersecurity agency, and a moderator. All speakers agreed that SMEs are economically critical yet disproportionately vulnerable; that cybersecurity transcends technical IT concerns and is fundamentally about trust, business continuity, and national resilience; that a multi-stakeholder approach combining government guidance, private sector tools, international cooperation, and capacity building is essential; and that practical, graduated, and affordable approaches to cybersecurity adoption are more effective than demanding immediate compliance . The session's most intellectually significant contributions were the reframing of SME cybersecurity as a national security matter, the identification of confidence and trust - rather than technology alone - as the primary barrier to digital adoption, and the presentation of concrete data on the rapid growth of AI-masquerading attacks as a new and urgent threat vector for SMEs . Together, these insights point towards the need for cybersecurity strategies that are simultaneously technically robust, psychologically accessible, economically affordable, and internationally coordinated.
SMEs contribute approximately 50% of Nigeria's GDP and employ around 16 million people, making them critical to the national economy - Economic backbone of Nigeria
Arg. 1Charles Odii highlights the enormous economic significance of SMEs in Nigeria, noting that the country has approximately 39 million small and medium businesses across various sectors. These businesses collectively contribute around 50% of Nigeria's GDP and provide employment for approximately 16 million people, making them indispensable to the national economy.
Odii stated that Nigeria has approximately 39 million plus small and medium businesses , that these businesses contribute approximately 50% of the GDP for Nigeria , and that they employ approximately 16 million people in Nigeria .
on: SMEs are easy targets for cyber attackers due to limited resources, manpower, and budget
Governments can incentivise SMEs by offering free or discounted cybersecurity tools to allow businesses to experience the benefits firsthand before committing financially - Incentivising adoption through free tools
Arg. 2Charles Odii argues that the most effective way to get SMEs to adopt cybersecurity solutions is to offer them free or discounted access so they can experience the benefits in real time. Once they see how cybersecurity protects their revenue, they are more likely to commit to it as an ongoing investment rather than viewing it as an additional expense.
Odii explained that the best way for SMEs to secure themselves is to get them into the environment at a discounted or free rate so they can enjoy the perks for a few months and see how they can protect their revenue . He also noted that Nigeria is reviewing its national MSME policy, with cybersecurity as one of the key conversations, alongside intellectual property and issues affecting women and youth .
on: Awareness and education are foundational first steps for improving SME cybersecurity
Public-private partnerships, such as the collaboration between SMEDAN and Kaspersky to provide free cybersecurity tools and webinars to Nigerian SMEs, are effective models for bridging the gap between awareness and adoption - Public-private partnership model
Arg. 3Charles Odii points to the partnership between SMEDAN and Kaspersky as a concrete example of how public-private collaboration can effectively bring cybersecurity within reach of SMEs. By combining government outreach with industry expertise and free tools, such partnerships help shift SMEs' perception of cybersecurity from a burden to a business enabler.
Odii described the partnership with Kaspersky, which provided free tools for small businesses to use and experience in real time before deciding to adopt them . He also referenced a free webinar conducted with SMEDAN to educate SMBs in Nigeria on cyber threats .
on: A multi-stakeholder approach involving governments, private sector, international organisations, and industry associations is essential for SME cybersecurity
Gradual exposure through free or discounted cybersecurity tools allows SME owners to experience the value of protection firsthand, shifting their perception of cybersecurity from an expense to an investment - Gradual onboarding to change financial mindset
Arg. 4Odii argues that the key to changing the financial mindset of SME owners regarding cybersecurity is a gradual onboarding process rather than an abrupt demand for compliance or expenditure. By allowing businesses to experience cybersecurity tools for free or at a discount, they can witness the tangible benefits before making a financial commitment.
Odii used the analogy of not turning water hot immediately to illustrate the gradual approach - going from zero to 100 is counterproductive, and instead a step-by-step process of education and experience is needed . He referenced the Kaspersky partnership as a practical example of this approach, where free tools are offered so businesses can experience them in real time .
Indonesia has over 64 million SME units representing 99% of all businesses, contributing more than 60% to national GDP and absorbing over 90% of the national workforce - Economic backbone of Indonesia
Arg. 1Ariq Bani Hardi underscores the critical role of SMEs in Indonesia's economy, noting that they represent the overwhelming majority of all business units in the country. Their contribution to GDP and employment makes their digital security a matter of national economic importance.
Hardi stated that Indonesia has more than 64 million SME units representing around 99% of all business units , that SMEs contribute more than 60% to the national GDP and absorb more than 90% of the national workforce , and that around 27 million SMEs have already adopted digital technology with the number continuing to grow .
on: SMEs are critical to national economies and serve as economic backbones
SMEs face risks including fraud in digital payments, credential theft in e-commerce, operational disruption from unmanaged devices, and supply chain disruptions from third-party service vulnerabilities - Real-world cyber risks for SMEs
Arg. 2Hardi outlines the concrete cyber risks that SMEs face as they digitalise, demonstrating that these threats are not abstract but have immediate and tangible consequences for business operations and income. Each digital tool or platform that SMEs adopt introduces a corresponding vulnerability that malicious actors can exploit.
Hardi explained that when SMEs use digital payment, they may face fraud or account takeover, directly affecting daily income . When using e-commerce or social commerce, they risk credential theft, fake admin schemes, or impersonation, leading to loss of sales and customer trust . Unmanaged devices with access control issues can interrupt business operations , and dependence on third-party logistics platforms means a disruption in one part of the chain can affect product and service delivery .
A successful cyber attack on an SME can cause financial losses, reputational damage, operational disruption, or even force the business to cease operations temporarily, with broader economic consequences - Business continuity at stake
Arg. 3Hardi argues that for SMEs, a cyber incident is not merely a technical problem but a direct threat to business continuity. Unlike large enterprises, SMEs lack the financial buffers, technical teams, and recovery capacity to absorb such shocks, meaning a single successful attack can be devastating.
Hardi noted that a small business may not have the same financial buffer, technical team, or recovery capacity as a large enterprise, and that one successful attack can cause financial losses, reputational damage, operational disruption, or even force the business to stop operating temporarily . He further stated that at scale, this becomes a broader economic issue affecting trust in digital payments, consumer confidence in online transactions, and local supply chains .
on: SMEs are easy targets for cyber attackers due to limited resources, manpower, and budget
What is ultimately at stake is not just cybersecurity but trust — trust in digital platforms, payment systems, and the digital economy as a whole - Trust as the core issue
Arg. 4Hardi reframes the cybersecurity challenge for SMEs as fundamentally a question of trust rather than a purely technical issue. He argues that strengthening SME cybersecurity is about ensuring that SMEs can continue to grow, serve customers, and contribute to the digital economy in a secure and resilient manner.
Hardi stated that what is at stake is not only cybersecurity but trust - trust in digital platforms, trust in payment systems, trust between SMEs and their customers, and trust in the digital economy as a whole . He emphasised that the goal is not to slow down digital transformation but to make digital adoption more trustworthy and resilient .
on: Cybersecurity for SMEs is not merely a technical IT issue but a matter of business continuity, trust, and economic resilience
on: Whether cybersecurity is fundamentally a technical issue or a trust and business continuity issue
BSSN promotes a four-stage approach for SMEs: awareness, self-assessment, cyber hygiene, and building resilience, supported by the practical tool Paman Kami for information security self-assessment - Four-stage cybersecurity approach
Arg. 5Hardi describes BSSN's structured four-stage framework designed to make cybersecurity accessible and practical for SMEs at varying levels of digital maturity. The approach is complemented by the Paman Kami tool, which enables SMEs to assess their own information security posture and identify priority areas for improvement without imposing heavy compliance burdens.
Hardi outlined the four stages as: awareness (understanding cybersecurity as protecting trust and business continuity) , self-assessment (understanding their own cybersecurity condition and gaps) , cyber hygiene (basic practices such as strong passwords, multi-factor authentication, regular backup, and anti-phishing awareness) , and building resilience (developing a continuity and recovery mindset) . He described Paman Kami as an information security self-assessment tool designed for capacity building rather than compliance, helping SMEs move from not knowing where to start to knowing what to improve first .
on: Basic cyber hygiene practices such as strong passwords, multi-factor authentication, and regular backups can significantly reduce risk for SMEs at low cost
Securing SMEs requires multi-stakeholder cooperation involving national cybersecurity agencies, local governments, digital platforms, financial institutions, SME associations, and cybersecurity service providers - Multi-stakeholder cooperation
Arg. 6Hardi argues that no single actor can address SME cybersecurity alone, and that a coordinated multi-stakeholder approach is essential. BSSN's role is not only regulatory but also that of an enabler, translating complex cyber risks into simple and scalable resilience practices that SMEs can actually adopt.
Hardi stated that the government cannot do this alone and that securing SMEs requires multi-stakeholder cooperation . He outlined the roles of different actors: national cybersecurity agencies providing guidance and frameworks, local governments supporting outreach and capacity building, digital platforms and cloud providers making security easier, financial institutions helping with fraud prevention, and SME associations delivering practical messages . He also highlighted the role of cybersecurity service providers like Kaspersky in offering affordable, easy-to-use, SME-friendly solutions .
on: A multi-stakeholder approach involving governments, private sector, international organisations, and industry associations is essential for SME cybersecurity
SMEs are already part of the digital ecosystem through payments, marketplaces, and social media, meaning they are already exposed and cannot afford to believe cybersecurity does not apply to them - SMEs are already in the digital ecosystem
Arg. 7Hardi challenges the myth that cybersecurity is irrelevant to small businesses by pointing out that SMEs are already deeply embedded in the digital ecosystem through the tools they use daily. This existing digital exposure means they are already at risk, regardless of whether they acknowledge it.
Hardi stated that today, even the smallest businesses use digital payments, online marketplaces, social media accounts, mobile devices, cloud applications, and logistic platforms, meaning they are already connected to the digital economy and digital supply chain . He warned that if an SME account is taken over, payments are disrupted, or customer data is leaked, the consequences are real and immediate .
on: The myth that cybersecurity is only relevant to large enterprises must be debunked, as SMEs are already embedded in the digital ecosystem and equally at risk
Governments and cybersecurity providers need to design affordable, accessible, and SME-friendly solutions that account for limited budgets and technical capacity - Affordable and accessible solutions
Arg. 8Hardi acknowledges that many SMEs have limited budgets and technical capacity, making it essential that cybersecurity solutions are designed with these constraints in mind. He emphasises that making the first step easy, improvement measurable, and resilience continuous are the key principles for effective SME cybersecurity support.
Hardi noted that many SMEs have limited budget and limited technical capacity, making it important for cybersecurity service providers to offer affordable, easy-to-use, and SME-friendly solutions . He summarised BSSN's lesson as: make the first step easy, make security improvement measurable, and make resilience continuous for SMEs .
SMEs, particularly women-led and youth-led businesses, are the majority supporters of economies globally, yet their growth is slower than startups - SMEs as economic majority
Arg. 1Sheila Birgen highlights that SMEs, especially those led by women and youth, form the backbone of most global economies despite growing more slowly than startups. Through DCO's WeElevate initiative, she has observed that these businesses are critical economic contributors even though they face structural constraints on growth.
Birgen noted that most businesses supported through the WeElevate initiative are women-led and youth-led businesses that predominantly employ youths , and that DCO has been able to support more than 10,000 of these businesses in just a year . She observed that SMEs' growth is not as rapid as startups, while they are the ones who majority support economies of most countries globally .
on: SMEs are critical to national economies and serve as economic backbones
AI acts as an equaliser for SMEs by increasing productivity, lowering operating costs, enabling better decision-making, and accelerating growth in areas where it previously stagnated - AI as an equaliser for SMEs
Arg. 2Birgen argues that AI represents a transformative opportunity for SMEs by levelling the playing field between small businesses and large enterprises. Previously, only large organisations could afford advanced technology, but AI is changing this dynamic by making powerful tools accessible to smaller businesses.
Birgen stated that AI provides an equaliser for SMEs because in the past it was assumed only big enterprises could afford technology, but AI is changing that . She noted that AI creates opportunities for SMEs to increase productivity, lower operating costs, make better decisions, conduct market research, and accelerate growth in areas where it would have previously stagnated .
SMEs' transition to digital tools, including AI, is hindered not just by technology gaps but by lack of confidence and trust, which is fundamentally a cybersecurity issue - Confidence and trust as barriers to AI adoption
Arg. 3Birgen argues that the primary barrier to SMEs adopting digital tools and AI is not a lack of technology but a lack of confidence and trust. She contends that cybersecurity is central to building this confidence, as SMEs will not engage with digital tools if they do not feel safe doing so.
Birgen observed that most small businesses do not transition to technology in general - not just AI - because of lack of confidence, which is ultimately driven by trust . She argued that if SMEs do not feel safe enough to transition to the digital economy or use digital tools, AI is not an exception to that, making the cybersecurity conversation critical .
on: Cybersecurity for SMEs is not merely a technical IT issue but a matter of business continuity, trust, and economic resilience
on: The primary barrier to SME cybersecurity adoption: confidence and trust versus technical and process gaps
If SMEs experience losses in the digital space, they lose incentive to participate in the digital economy and revert to offline operations, undermining digital transformation goals - Loss of digital participation incentive
Arg. 4Birgen warns that if SMEs enter the digital economy and suffer losses due to cyber incidents, they will have no incentive to continue and will revert to offline operations. This creates a significant risk for digital transformation efforts, as negative experiences can permanently deter SMEs from engaging with digital tools.
Birgen illustrated this with the example of an entrepreneur who starts getting customers on Instagram but then loses everything due to a cyber incident, asking 'what's the point?' and preferring to stay offline . She argued that building the capacities of entrepreneurs to protect themselves and leverage digital tools is essential for enabling full participation in the digital economy .
Capacity building should be holistic, covering not just the business founder but also their team, and should progress gradually from domestic digital trading to export readiness - Holistic capacity building
Arg. 5Birgen argues that effective capacity building for SMEs must go beyond training the founder alone and must encompass the entire team, as the founder cannot be expected to then train staff without support. She also advocates for a graduated approach to digital engagement, starting with domestic e-commerce before moving to cross-border and international trading.
Birgen noted that if you build the capacity of the founder but not their team, you add more work for the founder who already lacks time . She described the WeElevate approach as looking at the business holistically, covering domestic e-commerce first, then export readiness, then international selling, to avoid a drastic shockwave of growth before businesses are ready . Training is delivered through Skills Universe, tailored to specific capacity gaps rather than as blanket training .
on: Awareness and education are foundational first steps for improving SME cybersecurity
International organisations such as DCO enable countries and entrepreneurs to learn from each other, share best practices, and leverage mutual support across different levels of digital maturity - International cooperation as a learning platform
Arg. 6Birgen argues that international organisations like DCO play a vital role in facilitating peer learning and mutual support among countries and entrepreneurs at different stages of digital maturity. This cross-border exchange of knowledge and experience means that no country or entrepreneur has to navigate digital transformation challenges alone.
Birgen noted that DCO's diversity of member states spanning different levels of digital maturity allows countries to learn from each other, entrepreneurs to share best practices, and countries to leverage lessons from others . She stated that international cooperation is critical because entrepreneurs and countries don't have to struggle independently , and that it provides an avenue for mutual understanding of gaps and for diverse voices to talk to each other .
on: A multi-stakeholder approach involving governments, private sector, international organisations, and industry associations is essential for SME cybersecurity
The myth that cybersecurity only concerns large enterprises and governments is false; small businesses are deeply embedded in the digital ecosystem and their compromise can expose everyone else - Cybersecurity is not only for large enterprises
Arg. 7Birgen challenges the widespread misconception that cybersecurity is only relevant to large organisations, arguing that small businesses play a vital role and that their insecurity can expose the broader ecosystem. She emphasises that cybersecurity is for everyone, not just large enterprises and governments.
Birgen stated that one common myth is that cybersecurity is for large enterprises and government entities and does not really affect small businesses, calling this 'a big lie' . She argued that small businesses have a vital role to play and that if they are not secure, they can expose everyone else in society .
on: The myth that cybersecurity is only relevant to large enterprises must be debunked, as SMEs are already embedded in the digital ecosystem and equally at risk
Cybersecurity is not solely about technology; it is about protecting customers, building confidence, and enabling full participation in the digital economy - Cybersecurity is more than technology
Arg. 8Birgen argues that the biggest myth to debunk is that cybersecurity is purely a technology issue. She reframes it as a matter of confidence, trust, and enabling SMEs to participate fully and safely in the digital economy.
Birgen stated that the biggest myth she would like to demystify is that cybersecurity is only about technology - it is about ensuring that you protect yourself and your customers, and that you participate fully in the digital economy . She used the analogy of locking a door to illustrate how cybersecurity builds confidence: when you lock your door, you feel more secure, and the same applies to business owners who have confidence in their cybersecurity .
on: Cybersecurity for SMEs is not merely a technical IT issue but a matter of business continuity, trust, and economic resilience
on: Whether cybersecurity is fundamentally a technical issue or a trust and business continuity issue
SMEs play a crucial role in the value chain and critical supply chain, making their security a matter of primary importance - SMEs in supply chains
Arg. 1Dina Matar, as moderator, frames the discussion by highlighting that SMEs are not only important as individual economic actors but also as critical links in broader value and supply chains. This interconnected role means that their cybersecurity vulnerabilities have cascading consequences beyond their own operations.
Matar noted that SMEs play an important link in the value chain and in the critical supply chain , and that such businesses are highly susceptible to cyber attacks which are happening ever more frequently . She stated that promoting cybersecurity and the resilience of SMEs should be considered a matter of primary importance, requiring collaborative efforts from the public sector, technology vendors, and industry associations .
on: SMEs are critical to national economies and serve as economic backbones
Attackers target SMEs not because of their size but because of how easy it is to penetrate them due to limited manpower and budget - SMEs as easy targets
Arg. 1Shlychkova challenges the common misconception among SMEs that their small size makes them unattractive to attackers. She explains that cybercriminals are motivated by ease of access rather than the size of the target, and that SMEs' limited resources make them particularly vulnerable.
Shlychkova stated that the majority of SMEs think they are small and therefore not interesting for attackers, but the reality is the opposite - attackers think about how easy it is to penetrate a business, not its size . She noted that because SMEs have no manpower and not enough budget, it is really easy for attackers to get into smaller businesses .
on: The myth that cybersecurity is only relevant to large enterprises must be debunked, as SMEs are already embedded in the digital ecosystem and equally at risk
Three main attack vectors for SMEs include malicious programmes masquerading as legitimate tools, AI-service impersonation attacks (increasing fivefold in the first half of the year), and phishing/scam campaigns targeting credentials and banking accounts - Key attack vectors
Arg. 2Shlychkova outlines three primary categories of cyber attacks targeting SMEs, drawing on Kaspersky's threat intelligence data. These vectors exploit SMEs' reliance on common digital tools, their growing adoption of AI services, and their interest in financial opportunities such as business loans.
Shlychkova described the first vector as malicious programmes masquerading as legitimate tools like Microsoft Office or messengers, which can steal data, credentials, or encrypt files . The second vector involves attackers masquerading as legitimate AI services, with Kaspersky detecting 30,000 such attacks targeting SMBs in the first half of the year alone - a fivefold increase - impersonating ChatGPT, Claude, and DeepSeek . The third vector involves phishing and scam campaigns targeting credentials, corporate social media accounts, Google business accounts, and banking accounts, often exploiting SMEs' interest in financing and business loans .
Advanced cyber espionage groups target SMEs as proxies to gain access to larger enterprises or national ecosystems, making SME resilience a national security concern - SMEs as proxy targets
Arg. 3Shlychkova highlights that SMEs are not only targeted for direct financial gain but also serve as entry points for sophisticated threat actors seeking to infiltrate larger organisations or national infrastructure. This elevates SME cybersecurity from a business issue to a matter of national security.
Shlychkova noted that SMBs are interesting not only for cybercriminals seeking money or credentials, but also for advanced cyber espionage groups who try to penetrate SMBs in order to use them as proxies to get into larger enterprises or national ecosystems . She concluded that the resilience of SMBs is therefore a question not just about protecting them, but about protecting national cyber resilience .
Cybercriminals are masquerading as legitimate AI services, with attacks of this type increasing fivefold in the first half of the year, targeting popular platforms such as ChatGPT, Claude, and DeepSeek - AI as a new attack vector
Arg. 4Shlychkova identifies the exploitation of SMEs' growing interest in AI tools as a rapidly emerging attack vector. Cybercriminals are creating fake versions of popular AI services to steal credentials and data from businesses that are trying to leverage AI for their operations.
Shlychkova reported that Kaspersky's systems detected 30,000 attacks masquerading as AI services targeting SMBs in the first half of the year, representing a fivefold increase compared to the previous period . These attacks impersonated the three most popular AI services: ChatGPT, Claude, and DeepSeek .
Cybersecurity for SMEs must balance three pillars: technology (endpoint and network protection), processes (access control, strong passwords, two-factor authentication), and people (awareness and education) - The technology-process-people pyramid
Arg. 5Shlychkova advocates for a balanced, three-pillar approach to SME cybersecurity that addresses technology, processes, and people simultaneously. She argues that no single element is sufficient on its own and that even basic measures across all three pillars can dramatically improve an SME's security posture.
Shlychkova described the three pillars as: technology (using cybersecurity protection solutions scalable to business size, protecting endpoints and networks) ; processes (hardening existing systems, reviewing access to sensitive systems and financial transactions, ensuring strong passwords and two-factor authentication) ; and people (increasing awareness about cyber threats, noting that being aware of the problem means being half prepared) . She noted that doing 20% of the effort in these areas can make a business 80% more secure .
on: Basic cyber hygiene practices such as strong passwords, multi-factor authentication, and regular backups can significantly reduce risk for SMEs at low cost
on: Whether cybersecurity is fundamentally a technical issue or a trust and business continuity issue
Cybersecurity is a shared responsibility; companies, governments, and organisations must join forces because cyber incidents affect the economy, society, and the future - Shared responsibility
Arg. 6Shlychkova argues that cybersecurity cannot be treated as the sole responsibility of individual SMEs but must be understood as a collective challenge requiring cooperation across all stakeholders. The broader economic and societal impacts of cyber incidents make this a shared concern for everyone.
Shlychkova stated that if it is your business, it is not only your problem - it is all of our problem and a shared responsibility, with cybersecurity companies, governments, and organisations needing to join forces . She argued that cooperation is the key because cyber incidents affect the economy, society, and the future .
on: A multi-stakeholder approach involving governments, private sector, international organisations, and industry associations is essential for SME cybersecurity
Cyber threat intelligence, particularly machine-readable feeds integrated into cybersecurity solutions, is a relevant tool for medium-sized businesses to proactively identify indicators of compromise - Role of cyber threat intelligence
Arg. 7Shlychkova responds to an audience question by affirming the value of cyber threat intelligence for medium-sized SMEs, explaining that modern threat intelligence is increasingly packaged in machine-readable formats that can be integrated directly into cybersecurity solutions. This allows businesses to proactively search for specific indicators of compromise and continuously enrich their defences.
Shlychkova noted that for more medium-sized businesses, threat intelligence should be part of the protection strategy . She explained that threat intelligence is increasingly packed in machine learning and can be purchased as machine-readable data feeds that are included in cybersecurity solutions to search for specific indicators of compromise and constantly enrich the organisation's defences .
on: The relevance and applicability of cyber threat intelligence for SMEs
Cyber threat intelligence enhances communication and protection for SMEs because one small business can be attacked using the same techniques, tactics, and procedures as others - Role of cyber threat intelligence for SMEs
Arg. 1The audience member argues that cyber threat intelligence is a valuable tool for SMEs because attacks on one small business often use the same methods as attacks on others. Sharing and leveraging this intelligence can therefore help SMEs collectively protect themselves more effectively.
The audience member asked the panellists to elaborate on the role of cyber threat intelligence in enabling small and medium businesses to protect themselves, noting that cyber threat intelligence enhances communication because one small business can be attacked using the same techniques, tactics, and procedures .
There is a gap between the technical risk mindset of cybersecurity engineers and the financial mindset of financial managers in SMEs, which hinders investment in cybersecurity - Gap between technical and financial mindsets
Arg. 2The audience member identifies a fundamental disconnect between cybersecurity professionals who understand the risks and financial decision-makers who focus on costs. This gap means that financial managers in SMEs often do not appreciate the importance of cybersecurity investment and resist spending on it.
The audience member asked how to bridge the gap between the technical risk perspective of cybersecurity engineers and the financial mindset of financial managers, noting that financial managers do not know they need security and see cybersecurity spending only as a cost rather than recognising its importance .
Governments should subsidise or reduce the cost of cybersecurity modules to make them affordable for smaller developers securing critical national infrastructure - Government subsidies for affordable cybersecurity
Arg. 3The audience member calls on governments to take an role in making cybersecurity solutions financially accessible to smaller businesses, particularly those involved in securing critical national infrastructure. The argument is that without government intervention on pricing, many SMEs will remain unable to afford adequate protection.
The audience member asked how the government and cybersecurity providers can reduce or subsidise security modules to fit the budget of smaller developers who are securing critical national infrastructure .
Cybersecurity for SMEs is not merely an IT issue but a business continuity issue, as SMEs lack the financial buffers and technical teams to recover from cyber incidents - Cybersecurity as a business continuity issue
Arg. 1Hardi argues that framing cybersecurity purely as an IT concern misses the broader reality for SMEs, for whom a cyber incident can immediately threaten the survival of the business itself. Unlike large enterprises, SMEs do not have the resources to absorb and recover from attacks, making prevention and resilience existential concerns.
Hardi stated that cybersecurity for SMEs should not be seen only as an IT issue, because for many SMEs a cyber incident can immediately become a business continuity issue . He noted that a small business may not have the same financial buffer, technical team, or recovery capacity as a large enterprise, and that one successful attack can cause financial losses, reputational damage, operational disruption, or even force the business to stop operating temporarily .
on: Cybersecurity for SMEs is not merely a technical IT issue but a matter of business continuity, trust, and economic resilience
Cyber threat intelligence for SMEs requires a different forum and approach, as SMEs face more direct and immediate cyber attacks rather than sophisticated intelligence-driven threats - Cyber threat intelligence is not the primary focus for SMEs
Arg. 2Hardi suggests that while cyber threat intelligence is a valuable concept, it is not the most immediately relevant tool for SMEs, which tend to face more direct and practical cyber attacks. He implies that the conversation about threat intelligence for SMEs requires a dedicated and more specialised discussion.
Hardi responded to the audience question on cyber threat intelligence by stating that discussing cyber threat intelligence for SMEs requires a different forum, because SMEs face it more like direct cyber attacks rather than the sophisticated threat intelligence scenarios discussed for larger organisations .
on: The relevance and applicability of cyber threat intelligence for SMEs
Cyber threat intelligence is a valuable tool for SMEs because attacks on one small business often use the same techniques, tactics, and procedures, enabling shared learning and collective defence - Cyber threat intelligence for collective SME protection
Arg. 1Ife Inwa raises the point that cyber threat intelligence can serve as a communication and protection tool for SMEs, given that attackers frequently reuse the same methods across multiple targets. By sharing intelligence about these common attack patterns, SMEs can collectively strengthen their defences.
Ife Inwa asked what role cyber threat intelligence plays in enabling small and medium businesses to protect themselves, arguing that cyber threat intelligence enhances communication because one small business can be attacked using the same techniques, tactics, and procedures as others . She requested that the panellists draw more lines on this point .
Session Knowledge Graph
Speakers · Topics · Arguments · Relationships
