WSIS Forum 2026
AI-generated report

Promoting and enhancing cybersecurity among small and medium-sized enterprises for the sustainable development: trends and best practices

8 speakers
Summary

This panel discussion focused on promoting and enhancing cybersecurity among small and medium-sized enterprises (SMEs) as a matter of sustainable development, examining the threat landscape, best practices, and multistakeholder cooperation .

Charles Odii, Director General of Nigeria's SMEDAN, underscored the economic significance of SMEs, noting that Nigeria alone has approximately 39 million SMEs, which contribute around 50% of GDP and employ some 16 million people . He emphasised that most SMEs lack the financial resources and manpower to invest in cybersecurity, unlike large corporations or government bodies that have dedicated budgets and teams . Arik Banihardi of the National Cyber Security Agency of Indonesia (BSSN), reinforced this point, noting that over 64 million SMEs account for 99% of all business units in Indonesia, contributing more than 60% to national GDP and absorbing over 90% of the workforce .

Yulia Shlychkova of Kaspersky outlined the key cyber threats facing SMEs, including malicious programmes disguised as legitimate software tools, fake AI services - with attacks of this type increasing fivefold in the first half of the year - and phishing campaigns targeting business credentials and banking accounts . Sheila Birgen of the Digital Cooperation Organisation (DCO) added that AI, while offering SMEs significant opportunities to increase productivity and lower costs, also introduces new risks, and that a lack of confidence and trust remains a primary barrier to digital adoption .

On solutions, panellists converged on a three-pillar approach encompassing technology, processes, and people . BSSN promotes a four-stage framework of awareness, self-assessment, cyber hygiene, and resilience-building, supported by a practical self-assessment tool called Paman Kami . DCO's WeElevate initiative supports over 10,000 micro and small businesses, building capacity holistically across founders and their teams .

Panellists unanimously debunked the myth that cybersecurity is only relevant to large enterprises, stressing that SMEs are deeply embedded in digital supply chains and that their vulnerabilities affect national economic resilience and consumer trust as a whole . The discussion concluded with broad agreement that securing SMEs requires collaborative effort from governments, technology providers, international organisations, and the SMEs themselves, with accessible, affordable, and scalable solutions being essential to meaningful progress .

Keypoints
  • Overall Purpose

  • The discussion aims to examine the cybersecurity challenges facing small and medium-sized enterprises (SMEs), explore the threat landscape in which they operate, and identify best practices, policy approaches, and collaborative strategies to enhance their cyber resilience as part of broader sustainable economic development.
  • --
  • Major Discussion Points

  • The critical economic role of SMEs and their vulnerability to cyber threats: SMEs represent a disproportionately large share of national economies - for example, Nigeria has approximately 39 million SMEs contributing around 50% of GDP and employing 16 million people , while Indonesia's 64 million SMEs account for over 60% of national GDP and 90% of the workforce . Despite this importance, SMEs are attractive targets for cyber criminals precisely because they lack the manpower, budgets, and robust security frameworks of larger enterprises . Attackers view SMEs not only as direct targets for financial gain but also as entry points into larger enterprises and national ecosystems .
  • The evolving cyber threat landscape for SMEs, including AI-related risks: Three key attack vectors were identified as particularly prevalent: malicious programmes masquerading as legitimate software tools, fake AI services exploiting SMEs' growing adoption of AI (with attacks of this type increasing fivefold in the first half of the year, with 30,000 such attacks detected) , and phishing and scam campaigns targeting business credentials, banking accounts, and social media . The dark web trade in SME credentials was highlighted as a lucrative and growing market .
  • The role of AI as both an opportunity and a risk for SMEs: AI was identified as a potential equaliser for SMEs, enabling them to increase productivity, lower operating costs, conduct market research, and accelerate growth in ways previously only accessible to large enterprises . However, the transition to AI - and digital tools more broadly - is hindered by a lack of confidence and trust among SME owners . Cybersecurity was framed as foundational to building that trust, without which digital transformation, including AI adoption, cannot be sustained .
  • Multi-stakeholder and government-led approaches to strengthening SME cyber resilience: Speakers emphasised that no single actor can address SME cybersecurity alone . Indonesia's BSSN outlined a four-stage framework - awareness, self-assessment, cyber hygiene, and resilience building - supported by a practical self-assessment tool called Paman Kami . Nigeria's SMEDAN highlighted the importance of policy reform and public-private partnerships, including free cybersecurity tools provided through collaboration with Kaspersky . Kaspersky recommended a balanced approach across technology, processes, and people, noting that scalable, affordable solutions exist for businesses of all sizes .
  • International cooperation as essential to SME cyber resilience: The Digital Cooperation Organisation (DCO) highlighted that SMEs across its 16 member states face varying levels of digital maturity, and that international platforms enable countries and entrepreneurs to learn from one another rather than facing challenges in isolation . The WeElevate initiative was cited as an example of holistic support - covering awareness, domestic e-commerce, and export readiness - that builds both digital capability and cyber confidence across borders . International cooperation was framed as critical not merely for threat mitigation but for enabling full and equitable participation in the digital economy .
  • --
  • Overall Tone

  • The overall tone of the discussion is constructive, collaborative, and solutions-oriented. From the outset, the moderator and panellists frame cybersecurity not as an insurmountable obstacle but as a shared challenge requiring coordinated action . There is a consistent sense of urgency - particularly when discussing the scale of threats and the economic stakes involved - but this is balanced by optimism about available tools, partnerships, and frameworks. The tone remains professional and measured throughout, with speakers building on one another's contributions. Towards the end, during the myth-busting segment and audience Q&A, the tone becomes slightly more accessible and conversational , as panellists seek to demystify cybersecurity and make it feel approachable for SME leaders.
Speakers Overview
CO
Charles Odii
140 wpm · 5 min
AB
Ariq Bani Hardi
139 wpm · 7 min
SB
Sheila Birgen
127 wpm · 13 min
DM
Dina Matar
97 wpm · 15 min
YS
Yuliya Shlychkova
117 wpm · 9 min
AM
Audience Member
97 wpm · 58 s
AB
Arik Banihardi
146 wpm · 4 min
II
Ife Inwa
137 wpm · 42 s

Expanded Summary: Promoting and Enhancing Cybersecurity Among SMEs for Sustainable Development

#

Session Overview and Context

This panel discussion, convened at an international forum, focused on promoting and enhancing cybersecurity among small and medium-sized enterprises (SMEs) as a matter of sustainable development . Moderated by Dina Matar, the session brought together policymakers, cybersecurity experts, and industry representatives to examine the threat landscape facing SMEs, share experiences from existing initiatives and partnerships, and outline best practices for achieving cyber resilience . The panel comprised Charles Odii, Director General and CEO of the Small and Medium Enterprises Development Agency of Nigeria (SMEDAN); Sheila Birgen, Innovation Driven Market Director of the Digital Cooperation Organization (DCO); Yulia Shlychkova, Vice President of Global Public Affairs at Kaspersky; and Arik Banihardi, Senior Cryptographer at BSSN, Indonesia's Directorate of Cybersecurity and Cryptography for Finance, Trade and Tourism . The moderator framed the session around three interconnected themes: the threat landscape for SMEs, the multi-stakeholder approach to promoting cybersecurity, and best practices for building cyber resilience .

#

The Economic Importance of SMEs and Their Vulnerability

A foundational theme running throughout the discussion was the critical economic role played by SMEs and the paradox that their very importance makes their cybersecurity vulnerability a matter of national concern. Charles Odii opened by noting that Nigeria alone has approximately 39 million small and medium businesses, contributing around 50% of the country's GDP and employing approximately 16 million people . He drew comparisons with other emerging economies such as Vietnam and India, emphasising that SMEs are not peripheral actors but the engines that keep economies moving . Critically, Odii observed that many SMEs - ranging from one- or two-person operations to businesses employing up to 200 people - simply do not have the financial resources or manpower to invest in cybersecurity, in stark contrast to large corporations and government bodies that maintain dedicated budgets and teams for this purpose .

Arik Banihardi reinforced this picture from an Indonesian perspective, noting that Indonesia has more than 64 million SME units representing approximately 99% of all business units in the country, contributing more than 60% to national GDP and absorbing over 90% of the national workforce . He further highlighted that around 27 million Indonesian SMEs have already adopted digital technology, with that number continuing to grow . Sheila Birgen added a global dimension, observing that SMEs - particularly women-led and youth-led businesses - are the majority supporters of most economies globally, yet their growth tends to be slower than that of startups, making sustained support all the more important . Dina Matar framed SMEs as critical links in value chains and critical supply chains, underscoring why their security posture has implications far beyond the individual business .

#

The Cyber Threat Landscape for SMEs

Yulia Shlychkova provided the most technically detailed account of the cyber threat landscape facing SMEs, drawing on Kaspersky's global threat intelligence. She challenged the widespread misconception that small businesses are unattractive targets for attackers, explaining that cybercriminals do not think about the size of a business but rather about how easy it is to penetrate . Limited manpower and budgets make SMEs highly accessible targets, and Shlychkova identified three primary attack vectors .

The first vector involves malicious programmes that masquerade as legitimate software tools - such as messaging applications and productivity suites - which, once downloaded, can steal data and credentials or encrypt files with potentially catastrophic consequences . The second, and rapidly growing, vector involves attackers impersonating legitimate AI services. Shlychkova revealed that in the first half of the year alone, Kaspersky's systems detected 30,000 attacks of this type targeting SMEs - a fivefold increase compared to the previous period - with attackers specifically impersonating ChatGPT, Claude, and DeepSeek . The third vector encompasses phishing and scam campaigns designed to lure businesses into surrendering their credentials, corporate social media accounts, Google Business accounts, or banking details, often by exploiting SMEs' legitimate interest in securing financing or business loans . Shlychkova also noted that the dark web trade in SME credentials is a lucrative and growing market, further incentivising attacks .

A particularly significant observation from Shlychkova was that SMEs are targeted not only for direct financial gain but also by advanced cyber espionage groups seeking to use them as proxies to penetrate larger enterprises or national ecosystems . This reframing - from SME cybersecurity as a business-level concern to a matter of national cyber resilience - proved to be one of the most intellectually consequential contributions of the session, setting the stage for subsequent discussions about systemic risk and shared responsibility .

#

The Dual Role of AI: Opportunity and Risk

The discussion devoted considerable attention to artificial intelligence, which emerged as both a transformative opportunity for SMEs and a significant new attack surface. Sheila Birgen argued that AI functions as an equaliser for SMEs, enabling them to increase productivity, lower operating costs, conduct market research, make better decisions, and accelerate growth in areas where progress had previously stagnated - capabilities that had historically been accessible only to large enterprises . Through DCO's WeElevate initiative, which has supported more than 10,000 micro and small businesses across its member states in a single year, Birgen observed first-hand how AI is beginning to transform the prospects of smaller businesses .

However, Birgen introduced an important qualification: the transition to digital tools, including AI, is hindered not primarily by technology gaps but by a lack of confidence rooted in distrust . She argued that if SME owners do not feel safe enough to transition to the digital economy or use digital tools, AI is no exception to that reluctance, and that this is precisely where the cybersecurity conversation becomes critical . Without addressing confidence and trust, she warned, the same conversations about digital transformation would be repeated in five or ten years without meaningful progress .

Shlychkova's data on AI-masquerading attacks provided a sharp counterpoint to the optimistic framing of AI's potential, illustrating that the very platforms being promoted as productivity tools for SMEs are simultaneously being weaponised against them . Dina Matar synthesised both perspectives, acknowledging that AI is being used both as a tool for digital transformation and as a source of concern in cybersecurity . This duality - AI as equaliser and AI as attack vector - was not fully resolved in the session but represented one of its most intellectually generative tensions.

#

Real-World Consequences of Cyber Exploitation

Arik Banihardi provided a detailed account of the real-world consequences of cyber exploitation for SMEs, grounding the discussion in concrete operational realities. He argued that what is at stake extends far beyond systems, applications, or data, encompassing livelihoods, business continuity, customer trust, digital payment confidence, and local economic resilience . He outlined specific risk scenarios: SMEs using digital payment systems may face fraud and account takeover, directly affecting daily income; those using e-commerce or social commerce may suffer credential theft, fake administrator schemes, or impersonation, resulting in loss of sales and customer trust; those using unmanaged devices may face operational disruption; and those dependent on logistics platforms or third-party services may find that a disruption in one part of the chain affects their ability to deliver products and services .

Banihardi emphasised that a cyber incident for an SME can immediately become a business continuity crisis, given that small businesses typically lack the financial buffers, technical teams, or recovery capacity of larger enterprises . At scale, he argued, the consequences extend beyond individual businesses: widespread SME cyber incidents can reduce trust in digital payment systems, undermine consumer confidence in online transactions, and disrupt local supply chains . Crucially, Banihardi reframed the entire cybersecurity challenge as fundamentally a question of trust - trust in digital platforms, payment systems, between SMEs and their customers, and in the digital economy as a whole - arguing that strengthening SME cybersecurity is inseparable from enabling sustainable digital transformation .

#

Best Practices and Recommendations

On the question of solutions, panellists converged on a multi-dimensional approach that balances technology, processes, and people. Shlychkova described this as a pyramid in which all three elements must be in balance . On the technology side, she recommended that SMEs use cybersecurity protection solutions scaled to their size and needs, noting that vendors including Kaspersky offer solutions suitable for businesses with or without dedicated IT security teams, from two to two hundred people . On the process side, she recommended hardening existing systems by reviewing access to sensitive systems and financial transactions, ensuring strong passwords, and implementing two-factor authentication - measures that, she argued, require only 20% of effort but can deliver 80% of the security benefit . On the people side, she stressed that even a one-person operation must take cybersecurity seriously and build awareness, noting that being aware of the problem means being half prepared, and that free awareness materials and online courses are widely available .

Banihardi outlined BSSN's four-stage practical framework for SMEs: awareness, self-assessment, cyber hygiene, and resilience-building . The awareness stage focuses on helping SMEs understand that cybersecurity is about protecting trust and business continuity, not merely computers and systems . The self-assessment stage encourages SMEs to understand their own cybersecurity condition, identify gaps, and prioritise improvements . The cyber hygiene stage promotes basic, repeatable practices - including strong passwords, multi-factor authentication, regular backups, device security, anti-phishing awareness, and access control - which are not always expensive but are highly effective . The resilience-building stage encourages SMEs to develop a continuity and recovery mindset, asking not only how to prevent incidents but how to keep operating and recover when disruption occurs .

A practical embodiment of this framework is Paman Kami - an acronym in Bahasa Indonesia for "Information Security Self-Assessment Tool for SMEs" - which BSSN developed to help SMEs understand their current information security practices, identify gaps, and prioritise improvements . Banihardi emphasised that Paman Kami is designed as a capacity-building instrument rather than a compliance burden, helping SMEs move from not knowing where to start to knowing what to improve first . The tool operates through a structured process of socialisation, self-assessment, verification, and monitoring and evaluation .

#

Government Policy and Public-Private Partnerships

Charles Odii addressed the role of government policy and public-private partnerships in incentivising SME cybersecurity adoption. He noted that many SMEs have never tried cybersecurity tools before, and that the most effective way to encourage adoption is to allow businesses to experience the benefits firsthand through discounted or free access, enabling them to see how protection translates into revenue security over a period of months . He described a double-edged approach: incentivising awareness on one hand, and reforming policy to ensure that every small business owner protects themselves - particularly those processing data from third parties - on the other . He also noted that Nigeria is in the process of reviewing its national MSME policy, with cybersecurity identified as a key component alongside intellectual property protections and provisions addressing the needs of women and youth entrepreneurs .

A concrete example of this approach is the partnership between SMEDAN and Kaspersky, through which free cybersecurity tools and educational webinars have been made available to Nigerian SMEs . Odii used the analogy of gradually heating water to describe the philosophy behind this approach: rather than demanding an abrupt transition from zero to full cybersecurity compliance, the goal is to gradually bring SMEs into the cybersecurity ecosystem, educate them, and allow them to discover the value of protection for themselves . This gradual onboarding model was presented as a practical compromise between the cost concerns of SMEs and the urgent need for improved security posture.

#

Multi-Stakeholder and International Cooperation

A consistent theme across all speakers was that no single actor can address SME cybersecurity alone, and that effective solutions require coordinated multi-stakeholder cooperation. Banihardi outlined the roles of different actors in Indonesia's approach: BSSN provides guidance and security frameworks; local governments support outreach and capacity building; digital platforms and cloud providers should make security easier for SMEs; financial institutions can help with fraud prevention and trusted payment practices; and SME associations and communities can deliver messages in practical and relatable ways . He also highlighted the complementary role of cybersecurity service providers such as Kaspersky in offering affordable, easy-to-use, SME-friendly solutions that government alone cannot provide .

Shlychkova articulated the shared responsibility principle most directly, stating that cybersecurity is not just the individual SME's problem but a collective concern for companies, governments, and organisations alike, because cyber incidents affect the economy, society, and the future . This framing validated the multi-stakeholder approaches described by other panellists and provided a unifying ethical foundation for the session's policy recommendations.

Sheila Birgen highlighted the specific contribution of international organisations to this ecosystem. She noted that DCO's 16 member states span a wide range of digital maturity levels, meaning that cybersecurity challenges differ significantly across countries and that a diversity of experience creates opportunities for mutual learning . International cooperation, she argued, enables countries and entrepreneurs to share best practices and leverage lessons from one another rather than facing challenges in isolation . She framed cyber resilience in the context of international cooperation not merely as threat mitigation but as a means of enabling entrepreneurs to participate fully and equitably in the digital economy .

Birgen illustrated the importance of sustained digital participation with a vivid example: an entrepreneur who begins attracting customers through social media but then loses everything to a cyber incident has little reason to continue engaging with the digital economy and may simply revert to offline operations . This observation reinforced the view that cybersecurity is not merely a technical safeguard but a prerequisite for inclusive and sustained digital economic participation.

DCO's WeElevate initiative was presented as a model of holistic international support. Rather than focusing solely on the business founder, WeElevate builds capacity across the entire business entity, including the team . It progresses through a phased digital growth model: awareness, domestic e-commerce trading, export readiness, and international selling, with cybersecurity integrated throughout rather than treated as a separate or preliminary requirement . This graduated approach is designed to ease SMEs into the digital economy without overwhelming them with complexity, starting with local platforms and familiar payment gateways before introducing the additional compliance and logistical demands of international markets . Birgen also noted that because WeElevate serves a large number of countries, it enables businesses to become peer mentors to one another across borders, creating networks of shared experience and mutual support .

#

Debunking Cybersecurity Myths

The session concluded with a myth-busting segment in which panellists were invited to identify one cybersecurity misconception they would want SME leaders to stop believing. The responses were revealing both for their content and for the degree of convergence they demonstrated across very different institutional perspectives.

Birgen challenged the myth that cybersecurity is only relevant to large enterprises and governments, calling it "a big lie" and arguing that small businesses have a vital role to play and that their insecurity can expose everyone else in society . She also challenged the related myth that cybersecurity is solely about technology, reframing it as a matter of confidence, customer protection, and full participation in the digital economy - using the analogy of locking a door to illustrate how cybersecurity builds rather than constrains confidence . Shlychkova's myth-busting contribution centred on shared responsibility: she argued that a cyber incident affecting one SME is not merely that business's problem but a collective concern requiring cooperation from all stakeholders - companies, governments, and organisations alike . Banihardi addressed a closely related misconception, reinforcing that SMEs are already embedded in the digital ecosystem through payments, marketplaces, social media, and cloud applications, meaning they are already exposed to cyber risk regardless of whether they recognise it . It is worth noting that both Birgen and Banihardi independently challenged the notion that cybersecurity is the exclusive concern of large enterprises, reflecting the strength of this misconception across different national and institutional contexts.

#

Audience Questions and Unresolved Issues

The session's audience Q&A surfaced two important issues that were only partially addressed. The first, raised by Ife Inwa from Nigeria, concerned the role of cyber threat intelligence in enabling SMEs to protect themselves collectively, given that multiple businesses are often attacked using the same techniques, tactics, and procedures . Shlychkova affirmed the value of threat intelligence for medium-sized businesses, noting that it is increasingly packaged as machine-readable data feeds that can be integrated into cybersecurity solutions to search for specific indicators of compromise . Banihardi, however, suggested that the topic warrants a dedicated forum, as SMEs face more direct and immediate cyber attacks rather than the sophisticated threat intelligence scenarios relevant to larger organisations . This brief but notable divergence illustrated a genuine difference in how the two speakers assess the practical relevance of threat intelligence tools for the SME segment.

The second question, from an unnamed audience member, raised the challenge of bridging the gap between the technical risk perspective of cybersecurity professionals and the financial mindset of business managers who view cybersecurity as an additional expense rather than a protective investment . Odii's response focused on the gradual onboarding model - offering free tools to allow SME owners to experience the value of protection firsthand before committing financially - as a practical mechanism for shifting this perception . However, a more comprehensive framework for aligning technical and financial perspectives on cybersecurity investment was not fully developed within the session, representing one of several issues that remain open for further exploration.

#

Overall Assessment

The discussion was characterised by a high degree of consensus across speakers from markedly different institutional backgrounds - an SME development agency, a digital cooperation organisation, a global cybersecurity company, a national cybersecurity agency, and a moderator. All speakers agreed that SMEs are economically critical yet disproportionately vulnerable; that cybersecurity transcends technical IT concerns and is fundamentally about trust, business continuity, and national resilience; that a multi-stakeholder approach combining government guidance, private sector tools, international cooperation, and capacity building is essential; and that practical, graduated, and affordable approaches to cybersecurity adoption are more effective than demanding immediate compliance . The session's most intellectually significant contributions were the reframing of SME cybersecurity as a national security matter, the identification of confidence and trust - rather than technology alone - as the primary barrier to digital adoption, and the presentation of concrete data on the rapid growth of AI-masquerading attacks as a new and urgent threat vector for SMEs . Together, these insights point towards the need for cybersecurity strategies that are simultaneously technically robust, psychologically accessible, economically affordable, and internationally coordinated.

Dina Matar
Thank you. Good afternoon. Good afternoon, distinguished guests, colleagues, ladies and gentlemen. Welcome to today's panel discussion. Recording in progress. Our session will focus on promoting and enhancing cybersecurity among small and medium -sized enterprises for their sustainable development. We will be looking at trends and best practices. so small and medium enterprises play a crucial role in facilitating sustainable development in multiple ways from serving daily needs of consumers no okay not sure if we heard you okay okay so I'll do a quick restart so thanks again for joining the session today the topic of our session is promoting and enhancing cyber security among small and medium sized enterprises for sustainable development we'll be looking mostly at trends and best practices today so small and medium enterprises play a crucial role in facilitating sustainable development thank you And they do that in several ways, mainly from serving consumers on a daily basis, but also they play an important link in the value chain, in the critical supply chain. At the same time, such businesses are highly susceptible to cyber attacks, and we see these cyber attacks happening ever more frequently. And SMEs are easy targets, and their security measures are less robust than other corporate enterprises. So with this, promoting cybersecurity and the resilience of SMEs should be considered as a matter of primary importance. And this requires collaborative efforts from public sector, technology vendors, and industry associations as well. So the session today will focus on the cyber security issue. It will focus on awareness building, and we will be trying to outline current trends. And we will try to share experiences from existing initiatives and partnerships, as well as new approaches and joint measures for reaching cyber resilience. So the session today will bring policymakers, cybersecurity, and industry experts to discuss existing cyber threats to SMEs. We will talk about the threat landscape for SMEs. We will talk about the multi -stakeholder approach and cooperation for promoting cybersecurity. And we will also try to delve into best practices of promoting cyber resilience. We are very fortunate today to have an outstanding group of experts. And with me on the panel are Mr. Charles Odi, Director General and CEO of Small and Medium Enterprises Development Agency of Nigeria, that is known as SMEDN. We have Ms. Sheila Bergen. Innovation Driven Market Director of the Digital Cooperation Organization, DCO. We have Ms. Yulia Shishkova, Vice President of Global Public Affairs at Kaspersky. And last but not least, Mr. Arik Banihardi, Senior Cryptographer at BSSN, which is the Directorate of Cybersecurity and Cryptography for Finance and Trade and Tourism in Indonesia. We will start by looking at a general overview about this topic. So I will start with Mr. Odi as Director General and CEO of SMIDAN. And as we try to assess the specifics of cybersecurity for SMEs, it is important to remind ourselves about the role of SMEs in the economy in particular and the role that they play. So in your opinion, what is the importance of SMEs and how do they compare to the corporate and public sectors? and why do they need a special government
Charles Odii
agency responsible for SME support? Thank you. Thank you so much. And again, let me thank Kaposky for this opportunity to be here today. So my name is Charles Odi. I am the Director General of the largest SME development agency on the continent of Africa. We have approximately 40 million small and medium enterprises cutting across different sectors from transport to education to trade. And these small businesses are very critical. The last time we did a census and we counted these small businesses, we have approximately 39 million plus small and medium businesses in Nigeria. And these small and medium businesses, you know, help to contribute approximately 50 % of the GDP for Nigeria. And so they are very important because they employ approximately 16 million people in Nigeria. And if you have economies that are very similar to Nigeria, so if you're an emerging economist like Vietnam, India, you know, and the likes, you can actually see the importance of these small businesses because excluding employing people, they also help to galvanize and move the economy going. And many of the small businesses, you know, from mom and pop shops to laundromats on the corner of the street, many of them usually do not have the capacity to employ many people. Some of them are just one or two people show, and they usually do not have the well -with -all and the financing for cybersecurity. And so if you compare them to large organizations and government organizations, governments, in a sense, have different frameworks and even budgets for cybersecurity. And large organizations also have the same thing. They have the manpower and they have the budget. But usually small businesses who are just one or two people, the largest will be about 200 people, you know, usually don't have that funding. But they're a very critical to the economy because they employ more people and they help to get things forward. And so, you know, helping with this group of people, they need actually a lot of government support and a lot of partnership to get their businesses secure and to get things going. But again, they're very, very critical.
Dina Matar
They're very important to the ecosystem where they play. Thank you very much, Mr. Odi. Indeed, this is what we've seen. SMEs are really playing a crucial role and they struggle when it comes to financing. But there is another topic. I mean, we are in a session about cybersecurity and IT in the IT industry. At the same time, the biggest or the most frequent and popular word used in IT today is AI. So, Ms. Bergin, is it true that, I mean, how do you see artificial
Sheila Birgen
intelligence technologies affecting SMEs in your area in DCO? Thank you so much. I think that's a very useful question. But before I get to the answer, I'd like to introduce you to DCO. We're a digital corporation organization. We represent 16 member states in Africa, in Europe, and in Asia. And our main focus is to be able to support countries in their digital transformation and growth of their digital economy. And if I could talk about the question now and AI and what we've seen. We have an initiative called We Elevate. where we support micro and small businesses across our member states. And most of those businesses are women -led businesses and youth -led businesses, and predominantly all the employee youths in their businesses. We've been able to support more than 10 ,000 of these businesses in just a year. And one of the things we've noticed, I think, is the transformation on AI has also been happening, is AI has a really big opportunity to be able to transform these businesses. It provides an equalizer for the SMEs because in the past it was assumed that only big enterprises would be able to afford technology, but AI is changing that for small businesses. Like my colleague Charles mentioned, most of them don't employ a lot of people. because they cannot afford operationally. It becomes very expensive for them to do that. Secondly, their growth is also not as rapid as, for instance, you would say for startups, while they're the ones who majority support economies of most of the countries globally. And so AI is creating a lot of opportunities for these businesses, for them to be able to increase their productivity, to lower their operating costs, to make better decisions, to do market research. I mean, we can go on and on. But I think one of the biggest opportunities that I think AI is creating for small businesses is to be able to accelerate their growth in areas where it would have stagnated in the past. And I mean, you know, looking at things like scale. If they want to scale to 9%, they need to be able to scale to 10%. And they need information about these new markets. if they want to be able to deploy solutions in these new markets. It's making that slightly easier, not the physical element, but the technology element for the SMEs to do that. But I think the question on AI when we talk about small businesses is not really about technology only, because what we've seen is most of the small businesses do not transition to technology in general, forget AI, because of lack of confidence. And confidence ultimately is driven by trust. And if they don't feel safe enough to transition to the digital economy or use digital tools, then AI is not an exemption to that. And I think that's where the cybersecurity conversation becomes very critical, because it goes beyond whichever technology tool we use, it goes to the capabilities and capacity that the business owners have. to be able to trust the technologies that they are using for the technologies to work for them. So I would say, yes, it's great, and it's doing a lot of things, but if we don't handle the confidence, trust issues, and that heavily relies on
Dina Matar
cyber security and cyber resilience, really, then it will still be the same conversations that we have in five, ten years from now. Thank you very much, Ms. Bergen. Definitely, from your answer and from, again, what we observe, AI is being used both as a tool for digital transformation, but as well it is a source of concern in cyber security. So with this, turning to Ms. Triskova, we see that small and medium -sized enterprises have their own specifics, but what about... ...cyber security
Yuliya Shlychkova
and what does... the cyber threat landscape look like for SMEs? What are the trends that we see? And why are malicious actors increasingly targeting SMEs? So I would, as I'm representing global cybersecurity company, which is protecting businesses of all sizes more than three decades. So my responses will be a little bit more technical. But I would like to start with the question, why small businesses are being attacked? And the majority of SMEs are thinking they are small. So probably we are not interesting for attackers. But it's vice versa. Attackers are not thinking about the size. They are thinking about how easy it is to penetrate your business. And because, as Charles said, like no manpower, not enough budget. So for attackers, it's really easy to get into smaller businesses. And we have the situation when SMBs are a very interesting and attractive target for cyber criminals who are there for money, for quick access to your credentials. But also SMBs are very interesting for advanced cyber espionage groups who are trying to penetrate to get access to SMBs in order for them to be proxied to get into larger enterprise. Or national ecosystem. So resilience of SMBs is actually the question not about protecting them, but also about protecting national cyber resilience. So it's a very serious question and challenge. So recently Kaspersky issued a report about the threat landscape for small and medium businesses in 2036. And you can scan QR code and have a good long read. But I would like to highlight maybe three main vectors of attacks for this specific segment. first of all businesses are looking for the tools trying steps in digital arena so they're looking for messengers they're looking for Microsoft Office tools and applications and we see very high number of malicious programs which masquerade themselves as these legitimate tools and once downloaded they can steal your data they can steal your credentials encrypt your files which can lead to very catastrophic consequences so these types of attacks are very very similar and they are high in number for several years in a row the new vector which we are seeing is AI as many businesses turn to AI to automate their operations to help them with support with market research as Sheila said But attackers are also trying to masquerade themselves as legitimate AI services. So only in the first half of the year, we see the number of attacks masqueraded as AI services increased five times more than comparing to the previous period. So our systems detected 30 ,000 attacks of these sorts targeting SMBs. And they're trying to masquerade themselves as Judge Deputy, Claude, and Dipsyc, so three most popular AI services. And the third vector, which I also would like to mention, is scammers and phishing campaigns, which are trying to lure... businesses to share their credentials, access to their corporate social media accounts, Google business accounts, or banking accounts. And again, what attackers are doing, they are playing on legitimate interest of smaller businesses. For example, they are looking for financing and business loans. So what attackers will do, they will put a landing page which will advertise that we are a global trust bank. We will give you very favorable conditions. Please input your business bank account, business data, and this will be stolen. So therefore, those are just three key, the most popular tricks. But again, in the dark web, a lot of the amount. Of fun. credentials offered for purchase to get into smaller businesses are really high. So this is a very lucrative market and then it's all about money so we really need to increase the bar and increase
Dina Matar
the resilience of small and medium businesses to make the life harder for attackers to penetrate. So I would stop there to let the speakers also to add. Thank you. Thank you, Ilya. Mr. Hardy, we see from what the other speakers have shared with us today that SMEs one, they're playing an increasingly important role in the economy and on the other hand they are being
Arik Banihardi
increasingly targeted by cyber criminals. What are in your experience real world consequences of the exploitation of vulnerabilities of SMEs in cyberspace and what is actually at stake? Thank you for the question. Because it is very much aligned with the data and message that I bring to this forum based on guidance and directive from approval and approval from our director in BSSN institution. Let me start from the initial context here. From initial perspective, what is actually at stake is much bigger than a system application or data. When we talk about cybersecurity for SMEs, we are also talking about left -freehood, business continuity, customer trust, digital payment confidence, and local economic resilience. In Indonesia, SMEs are the backbone of the economy. We have more than 64 million SMEs unit representing around 99 % of all business unit. SMEs also contribute more than 60 % to the national GDP and absorb more than 90 % of the national workforce. At the same time, Around 27 million SMEs have already adopted digital technology And now the number continues to grow So when SMEs become more digital, they gain many opportunities They can reach new markets through e -commerce and social commerce They can receive payment faster through the digital payment channel They can use cloud application, mobile devices, logistic platform, and digital supply chain This is very positive for economic inclusion and sustainable development Especially in Indonesia So next slide please So as we know, digitalization brings opportunity But it also brings exposure and risk For example, like Yulia said When SMEs use digital payment, they may face fraud or contact over The impact is not only technical It can disrupt payments and directly affect the daily income of the SMEs When SMEs When SMEs use digital payment, they may face fraud and contact over When SMEs use e -commerce or social commerce, they may face the credential theft, fake admin scheme, or impersonation. The consequence can be loss of sales and loss of customer trust. When they use unmanaged devices with access control and misconfiguration system, it can interrupt the business operations. And when SMEs depend on a logistic platform or third -party services, a disruption in one part of the chain can affect the ability to deliver product and services to the customer. I think Yulia may be able to elaborate more on this point, especially from the perspective of the current cyber threat trend and what Kaspersky observes in the field. This way, we should not see cybersecurity for SMEs only as an IT issue. For many SMEs, a cyber incident can immediately become a business continuity issue. A small business may not have the same financial buffer, technical team, or recovery capacity as a large enterprise. One successful attack can cause financial losses, reputational damage, operational disruption, or even force the business to stop operating temporarily At this scale, this also becomes a broader economic issue If many SMEs are affected, the impact can go beyond individual businesses It can reduce trust in digital payment, reduce consumer confidence in online transaction, and disrupt the local supply chains Therefore, the goal is not to slow down digital transformation in Indonesia for SMEs Digitalization is important and must continue The real goal is to make digital adoption more trustworthy and resilient In a simple way, what is a stack is not only cybersecurity What is a stack is trust Trust in digital platform, trust in payment system, trust between SMEs and
Dina Matar
their customers, trust in the digital economy as a whole So for us, strengthening SMEs cybersecurity is not only about preventing the cybersecurity It is about making sure the SMEs can continue to grow, serve their customers, and contribute to the digital economy in a secure and resilient way Thank you very much, Mr. Hadi. Now that we've gone through the landscape, essentially, about the SMEs and the cyber threats they are facing, maybe it's time to start looking at the solutions. So, Ms. Lischkova, cybersecurity is always about
Yuliya Shlychkova
a multifaceted and comprehensive approach. And, of course, there is no magic pill which would be able to single -handedly make an enterprise totally cyber resilient. But still, if you were asked to provide one recommendation or best practice for SMEs to enhance their cybersecurity, which one would you highlight? I can't provide one. I will provide three because, in the end, it's pyramids, technology, people, and processes. So, this. It has to be in balance. First of all, definitely, we highly recommend to use cybersecurity protection technology. And different vendors, cybersecurity vendors, including ourselves, have solutions which fit the size and needs of smaller businesses, whether with the IT security team or without the IT security team, whether it's two people or 200 people. So the solution can actually be scalable to business size. But you need to protect your endpoints and the network. Then processes. You need to start with hardening and strengthening what you already have to understand who has access to your sensitive systems, to your financing transactions, to review this access, to ensure that password. Third policy is strong. There is two -factor authentication. These simple steps. which actually can like you do 20 % of effort but you will make yourself like 80 % secure and the people like the last but not the least component even if you're only one person one man show, one woman show you need to start taking this seriously and increase your awareness about cyber threats because when you are aware of the problem you are half prepared and again, cyber security industry is issuing a lot of free materials about awareness Kaspersky has a cyber hygiene course available online like
Dina Matar
for example with Smidon we did a free webinar for SMBs in Nigeria to educate them on the threat so lots of things are available online AI is also helping to search for this information so we strongly recommend businesses to start looking into this and educate themselves to build their confidence as jailers Thank you. Thank you very much. So now, of course, in terms of solutions, the best practice is there and can be efficient. But these solutions have to be adopted by businesses. So, Mr. Odi, again, based on your experience and the agency's role in incentivizing SMEs to adopt solutions, I'm sure you mentioned in your earlier section that this comes at a cost for enterprises. So in this regard, what is to a large enterprise. Many of these people have never tried it before, and the best way for them to secure themselves is actually to get into their environment, probably at the discounted rate or at the free rate, so that they can enjoy the perks for a few months and see how they can increase their revenue, protect their revenue, get their revenue, because now they're protected. We're in the process of reviewing the national MSME policy for Nigeria, and in cybersecurity is one of the conversations that we're having in addition to intellectual property and factors that affect women and youth. So it's a double -edged approach. One is to incentivize them to become more aware, and second is now to change policy that makes sure that every small business owner protect themselves, especially if you are getting information and processing data from other people. Absolutely, and very, very important point that you made, Mr. Odi. Mr. Hardy, since SMEs usually serve as links in supply chains their own cyber security is not only their business it has a direct impact on national cyber resilience as a whole so as a national cyber security agency what does BSSN do from its side to
Ariq Bani Hardi
enhance cyber security of SMEs? Thank you again, Tina this is very related to what Yulia said about the golden triangle in people, process and technology as the national cyber security agency of Indonesia BSSN sees SMEs cyber security as a part of the national cyber resilience because SMEs are directly connected to the customer digital platform, financial services and supply chain our approach is to make cyber security more practical more measurable and more accessible for SMEs like this slide thank you we understand the SMEs have a different level of capacity. Some of them are already quite mature digitally, while others are just starting to use digital tools only. So the solution cannot be too complex or too compliance -heavy from the beginning. We try to make cybersecurity easier to understand and easier to implement. The approach that we promote can be described in four stages. The first stage is awareness. SMEs need to understand that cybersecurity is not only about protecting computer or system only. It is about protecting the trust and business continuity. For SMEs, trust is very important. If a customer loses trust in the business because of the fraud, data leakage, or a compromised business impact can be serious. And the second stage is self -assessment. We encourage SMEs to understand their own cybersecurity condition. This is important because business improves faster when they know their own gaps. Self -assessment helps SMEs see where they are today, what risks they are facing, and what improvements should be prioritized first. The third stage is cyber hygiene. For SMEs, basic and repeatable practice can significantly reduce the risk. This includes practical usage of strong passwords, multi -factor authentication, regular backup, device security, anti -phishing awareness, and access control. These practices are not always expensive, but they are very important. The fourth stage and the last one is building the resilience. SMEs need to develop a continuity and recovery mindset. The question is not only how to prevent an incident, but also how to keep operating and recovery when disruption or cyber incident happens. One practical example of business and approach is Paman Kami. Paman Kami in Bahasa Indonesia, which stands for Penilaian Mandiri Keamanan Informasi, untuk UMKM. Paman Kami in Bahasa Indonesia, which stands for Penilaian Mandiri Keamanan Informasi, untuk UMKM. Paman Kami in Bahasa Indonesia, which stands for Penilaian Mandiri Keamanan Informasi, untuk UMKM. Paman Kami in Bahasa Indonesia, which stands for Penilaian Mandiri Keamanan Informasi, untuk UMKM. Paman Kami in Bahasa Indonesia, which stands for Penilaian Mandiri Keamanan Informasi, untuk UMKM. In English, Paman Kami is the information security self -assessment tools for SMEs. Paman Kami is designed to help SMEs understand their current information security practices, identify the gaps, and prioritize the practical area to be improved. The important point is that Paman Kami is designed for capacity building, not as a heavy compliance burden. It helps SMEs move from not knowing where to start to knowing what to improve first. First, through Paman Kami, the process includes socialization and assistance, self -assessment, verification requests, verification and result, then monitoring and evaluation. This makes improvement more structured and measurable. However, we also recognize the government cannot do this alone. Securing SMEs requires multi -stakeholder cooperation. National Cyber Security Agency can provide guidance and security framework like BSSN, release the Paman Kami, real -time ministries, and research. Local government can support outreach and capacity building. Thank you. Digital platforms and cloud providers should make security easier for SMEs Financial institutions can help with fraud prevention and trusted payment practices SMEs, associations, and communities can help deliver the message in a practical and relatable way So BSSN roles is not only to regulate BSSN, also acts as an enabler We translate complex cyber risks into simple and scalable resilience practices that SMEs can actually adopt Another important point I think should also be highlighted is the role of the cybersecurity service provider including Gaspersky They can complement government effort by offering affordable, easy to use, and SMEs -friendly solutions This is important because many SMEs have a limited
Dina Matar
budget and limited technical capacity. In summary, our lesson is make the first step easy, make security improvement measurable, and make resilience continuous for SMEs. So our main message is that SMEs, cyber security should be simple enough to start, practical enough to adapt, and strong enough to support national cyber resilience. BSSN will continue to support SMEs not only through regulation, but also through
Sheila Birgen
guidance, capacity building program, practical tools, and collaboration with the wider ecosystem. Thank you very much, Mr. Hardy. You've highlighted the importance of what authorities in the country can do to support SMEs. Nevertheless, cyber security is a global concern and requires cross -border cooperation. So, Ms. Birgin, in your view, how can international organizations contribute to enhancing SMEs' resilience specifically, if you could share, please, what DCO is already doing or is planning to do in this regard? Thank you very much. Thank you. I think cyber hygiene should be a very central part to what they think about as well when they're transitioning. And for us as this year, we have member states that span across the digital maturity. And so challenges that you'll have in one country for SMEs or for an entrepreneur might look very different from an SME or a founder in a different country. And so that diversity allows us to be able to provide an avenue for countries to learn from each other, for entrepreneurs to share best practice, for countries to be able to leverage lessons from other countries. And that's where international cooperation becomes quite critical because entrepreneurs don't have to struggle on their own. Countries don't have to struggle on their own. You don't need to go through. Challenge is independently. There's that. mutual support of transition or transformation in the digital space across the different countries that then trickles down to the business owners. And so why cyber resilience is important, especially when we talk about international cooperation, is it goes beyond protecting business from cyber threats. It really is about allowing entrepreneurs or giving entrepreneurs an opportunity for them to participate fully in the digital economy. Because if they are getting into the digital space and losing, then there's no incentive for them to continue to do this. They would rather just continue to sell offline. Because if I'm joining this thing you're telling me, there's a lot of opportunities for me as an entrepreneur. I'm getting customers on Instagram. Then suddenly I've lost everything. what's the point and my shop is offline. So I'd rather stay offline. But if we build the capacities of the entrepreneurs themselves for them to know how to protect themselves and leverage these digital tools, then it provides an avenue for them to be able to participate fully in the digital economy. So what are we doing? So with WeElevate, the way we look at the digital transformation of SMEs is in a number of ways. We look at the business journeys for small businesses or individual entrepreneurs in this case. They need to know, so awareness information is critical, but not just for the founders. I think that's sometimes where we lose it out for the business itself. Yes, the founder is the owner of the business. but they don't run the business alone. They have a team that works with them. If you build the capacity of the founder and you don't build capacity of their team, you are adding more work for them to now again start training the team and they don't have that much time. So we look at it holistically as a business entity with the people who are working in the business as well as the founder. Then we look at e -commerce trading or digital social commerce trading in domestic markets. So we do awareness throughout, but we ensure that they trade on local platforms. Why do we do that? Because for most countries, for instance, that have mobile money and payment gateways locally, it becomes easy for them to start accepting payments and things like that. It's an easier way of easing them into the digital economy without scaring them. As opposed to saying, okay, there's this global platform that we want you to start selling. on, and they have to think about logistics, they have to think about compliance. There's just a lot of complexities that then pushes them away. So WeElevate looks at that knowledge, domestic trading or domestic e -commerce, and then after that, we get them export ready, not jump straight into export trading. What do you need to be export ready? Are you compliant enough? Which market would you be able to sell to? What do you need to know about that market when you're trying to export into this market? Then they sell internationally. So we look at end -to -end growth of the business, when they start all the way to when they'll be able to sell. And when I talk about exporting, we start with cross -border, again, proximity to home, understanding the culture, the markets, and then opening up the rest of the markets for them. So it doesn't push them. into drastic shockwave of growth before they are ready for that growth. And so for the trainings, we do that through something called Skills Universe, and we ensure that we look at the needs, the capacity gaps that they have as businesses and recommend the specific courses that would be critical for the founders, for the team. It's not a blanket training that all of them have to go. And so that allows us to be able to help individual entrepreneurs. But because we serve a large number of countries, it also allows these businesses to become peer mentors to other businesses, to get networks across borders, to ask questions to a fellow entrepreneur in another country. The same thing applies. The same thing applies for countries, for governments, if they are talking about policy, for banks that are planning to invest in businesses. How is the business environment in the country that you have? And that's very critical. in international cooperation. If I could just go back to cyber resilience in relation to international cooperation. I think international cooperation
Dina Matar
provides an avenue for mutual understanding of these gaps because all of us somehow go through the same processes. But even more important, it provides an avenue for all of those different voices, despite of their diversity in the digital maturity, to be able to talk to each other. That's why it's important. And it would not make a lot of sense for individual countries to just run through these challenges on their own when you have such a big platform for you to be able to leverage that. Absolutely. Thank you very much for your input here, Ms. Bergen. This is a very complex problem, and we were barely able, I think,
Charles Odii
to scratch the surface of what is needed and what's the best way to proceed. Nevertheless, we've learned a lot. Maybe one final question to all our panelists is, I think we all know that it's not easy to change someone's mind, let alone to fix broad misconceptions. Still, today we can try to become myth busters for the session today. What is one cybersecurity myth that you would want SME leaders to stop believing? Maybe if each one of you could give us a view on this point. Okay, so when...
Sheila Birgen
When we hear about cybersecurity and for our small businesses... When we hear about cybersecurity and for our small businesses... one thing that comes to mind is it's for large enterprises and it's for government entities, it doesn't really affect small businesses and I think that that's a big lie because I think that small businesses actually have a big vital role to play and if they are not secure they can actually expose everyone else in society so I think we should actually correct that or mitigate against that that's actually for everyone, not just large enterprises and governments I think the biggest myth I'd like to demystify is that cyber security is only about technology it's not it's about ensuring that you protect yourself, your customers but you also participate fully in the digital economy and cyber security should not be a hurdle for them to grow or to embark on their digital transformation. It
Yuliya Shlychkova
should be something that builds their confidence. It's like when you lock your door, you feel more secure when you're in the house as opposed to if the door is open. So if you're, as a business owner, if you're able to have that confidence in your business, then it allows you to fully participate in the journey, grow your business, and that starts with you learning but also building that confidence and trust in yourself and
Ariq Bani Hardi
in the team. It's not about technology. Just start with the confidence in learning and then slowly grow from there for you and your team. it's hard to be the third in answering this question because i agree with what charles and chela said but i also i think would demystify opinion that if it's your business it's your problem actually it's all of us a problem and it's shared responsibility uh cyber security companies governments organizations needs to join forces and to help because again it affects economy it affects society it affects future so a cooperation is the key here thank you and this is a important point from uh this is um my message from uh my institution the one meet uh we would like sme leaders to stop believing is uh cyber security is only for large enterprises this is no longer true Today, even the smallest businesses are part of the digital ecosystem They use digital payments, online marketplaces, social media accounts, mobile devices, cloud applications, and logistic platforms This means SMEs are already connected to a digital economy and a digital supply chain If an SME account is taken over, if payments are disrupted, if customer data is leaked, or
Dina Matar
Thank you very much for all your very productive and constructive input. This was a very insightful session, at least for me. I'm not sure if we have questions for our panelists. We would love to hear your opinion. Yes, please.
Ife Inwa
Greetings, everyone. Thank you for this session. I'm Ife Inwa from Nigeria. Thank you very much. I want to ask, you have mentioned how to build a robust and promoting strategy. So I want to ask, what is your opinion on how to build a robust and promoting strategy? What's the role of cyber threat intelligence to enable small -scale medium business in protecting themselves? because cyber threat intelligence enhances communication because one small business can be attacked using the same techniques, tactics, and procedures. So I want you to draw more lines of that. Thank you.
Yuliya Shlychkova
Definitely, maybe not for like two men, two women shop, but for like more medium -sized businesses, threat intelligence should be part of protection strategy because, as you said, right now a lot of threat intelligence, it's also packed in machine learning. I mean, so you can buy feeds like machine -readable data and include this in the way how you, how you protect your organization so that your cybersecurity solution is searching for specific indicators of compromise and it's like constantly enriches. Definitely, this is also what we recommend. so you're right, the
Ariq Bani Hardi
and maybe Eric if you can I think I talked about cyber threat intelligence we need a different forum because SMEs face it more like cyber attack thank you,
Dina Matar
is there any other question? looks like we yes yes yes please
Audience Member
Hello
Dina Matar
Yes we can hear you Please go ahead
Audience Member
I have one question How can we bridge the gap between technical risk And the financial mindset To confuse the stakeholders And how can the government And the conspiracy Reduce subsized Security modules that Fit the budget of smaller Developers securing critical national Infrastructure
Dina Matar
Can you please repeat the first part of your question Because the second was about How to design affordable solutions But the first one was I think more about Closing the gap between Can you repeat this Between Technical cybersecurity engineer And The Financial
Audience Member
Hello?
Dina Matar
Yes, as we can hear you
Audience Member
Between technical risk That cybersecurity engineer And financial mindset Financial manager Because they didn't know They need security I don't know I see the money I will cost it In cybersecurity I think I want to Buy anything to The company They didn't know the importance Of cybersecurity
Charles Odii
So for us In Nigeria, one way Of doing this Is the partnership we have With Kapaski So what Kapaski has done Is given us Some free tools where small businesses can actually come and use them. And after they use them, they can experience them real time, and they can then make the decision themselves probably after a month or two to know if they've been able to protect their revenue or if it's a good product for them to use. So I think actually a question in short is just basically Kaposky having this kind of fantastic relationship with government to basically help to intensify, incentivize people to come into this cybersecurity net, vis -a -vis them just looking at cybersecurity as an additional expense. It's just basically getting, you know how you want to kill a frog in hot water. You don't turn the water hot. You don't go from zero to 100. It's a gradual process. When you get the small businesses in, you start to educate them. They start to see the essence of cybersecurity, and before you know it, almost everybody is secure. That's how it works. thank
Dina Matar
you very much we are mindful of the time thank you for your attention and your questions and we hope to see you soon recording

Disclaimer: This is not an official session record. DiploAI generates these resources from audiovisual recordings, and they are presented as-is, including potential errors. Due to logistical challenges, such as discrepancies in audio/video or transcripts, names may be misspelled. We strive for accuracy to the best of our ability.