Home News Small businesses now prime targets for cybercriminals, warns security expert

Small businesses now prime targets for cybercriminals, warns security expert

by Thaabit Kamaar
Image Source: Skillcast

Local – Small and medium-sized businesses in South Africa can no longer assume that cybercriminals are only interested in big corporates, according to vulnerability and technical compliance manager Zaamir Bismillah. He said attacks that were once aimed mainly at large companies are now reaching smaller enterprises, and that a single mistake can have serious consequences.

Bismillah named phishing, ransomware and data breaches as the three biggest threats facing local SMMEs, from small accounting and legal firms to IT shops and paint shops.

He explained that phishing, where criminals send emails, SMSs or WhatsApp messages pretending to be a bank, supplier or even a company’s CEO, remains one of the most common ways attackers get in.

“The reality is that from a cyber security perspective, from a threat perspective, they don’t look at the size of the business. They look at the fact that you are a business and you are something that is lucrative for them.”

He pointed to a 2026 Sophos report that found nearly two-thirds of ransomware incidents in South Africa end with data being encrypted, a rate higher than the global average. He also cited the 2020 Experian breach, in which an attacker posed as a legitimate client and exposed about 24 million South African records and nearly 800,000 businesses.

Simple Steps, Big Difference

Many small business owners believe cybersecurity is a costly exercise reserved for companies with large IT budgets. In practice, the starting point is working out what a business most needs to protect, whether that is a law firm’s case files, a marketing agency’s client information or a doctor’s patient records.

Bismillah said most small firms already run Microsoft 365, which comes with built-in identity and access tools. He added that security updates should be as routine as updating apps on a phone, and that regular backups, short staff awareness sessions and an incident response plan add further layers of defence.

“Multifactor authentication is becoming the biggest and most critical component of our daily lives. A username and password is simply not the route to go anymore.”

Test What Matters Most

For businesses that handle personal information, such as financial services providers running banking apps or client portals, a security failure can lead to a breach or even a fine. Systems that capture names, addresses, and other customer details are critical, and any weakness can be costly.

Bismillah recommended penetration testing, in which a dedicated team of ethical hackers tries to break into a company’s systems and then advises on how to close the gaps.

He said a business’s most important systems should be tested at least once a year, and that any public-facing change should be validated before it goes live, so the business can show it took reasonable steps to stay secure.


“The reality is, a consumer like myself, making use of a banking platform or whatever that is, I put my trust in that space that they have taken the necessary precautions to ensure that their platform is, in fact, safe, and the reality is, when a breach takes place, your reputation is on the line, and that is either something that’s going to make you or break your business.”


Watch the Full Interview Here.


Related Videos