Back to News
2bo Insights

Cybersecurity for South African SMEs: The Attacks That Actually Hit Small Business

By 2bo Tech & Infrastructure Insights
Cybersecurity for South African SMEs: The Attacks That Actually Hit Small Business

Most South African small and mid-sized businesses believe they are too small to be worth attacking. The incident data says the opposite: automated attacks do not check your turnover before they strike, and smaller businesses are targeted precisely because their defences are thinner.

The good news is that the attacks hitting SMEs are not exotic. They are a short, well understood list, and most of them are stopped by controls that cost far less than a single incident.

R2.2bn
Estimated annual cost of cybercrime to the South African economy
43%
Of cyberattacks globally now target small businesses
24h
Typical time between a stolen password and its first malicious use

The four attacks that actually hit SMEs

  • Business email compromise: A spoofed or hijacked mailbox sends a fake invoice or a bank detail change to your finance person. No malware involved, just trust and a convincing email. Still the single most expensive attack type for small businesses.
  • Ransomware through remote access: An exposed remote desktop port or a VPN account with a weak password gives attackers a way in after hours. By morning, file servers and backups are encrypted.
  • Credential phishing: A fake Microsoft 365 login page harvests passwords, and the mailbox is used to reset passwords everywhere else. One phished account often becomes a full compromise.
  • Supplier and software chain attacks: Your accounting plugin, your IT provider's remote tool, your point of sale vendor. Attackers go through whoever has access to you, not just through you.

Why SMEs get hit harder

Large enterprises get attacked more often, but they also carry insurance, security teams and tested backups. A mid-sized business usually has none of those, which means the same incident that inconveniences a corporate can close a smaller company for weeks.

  • No separation between networks: Guest Wi-Fi, point of sale, cameras and finance laptops on one flat network means one infected device can reach everything.
  • Shared and recycled passwords: The same password on the firewall, the email and the accounting package turns one leak into total access.
  • Backups that have never been restored: A backup that has never been tested is a hope, not a plan. Ransomware specifically hunts and encrypts reachable backups first.

The controls that stop most of it

  1. 1

    Turn on multi-factor authentication everywhere

    Email, remote access, finance systems and admin accounts. MFA alone blocks the majority of credential-based attacks and costs almost nothing.

  2. 2

    Segment the network

    Separate guest Wi-Fi, cameras, point of sale and staff devices into isolated zones. A compromised smart TV should never be able to see the finance server.

  3. 3

    Keep one offline or immutable backup

    At least one copy of critical data must be unreachable from the network, and a restore must be tested at least twice a year.

  4. 4

    Patch the edge first

    Firewalls, VPN concentrators and remote access tools are the front door. They get updates before anything else, without exception.

  5. 5

    Train the people who move money

    Finance and admin staff need a simple rule: any bank detail change or urgent payment request gets verified by a phone call to a known number. Every time.

POPIA makes this a legal issue, not just an IT one

If your business holds customer or employee personal information, Section 19 of POPIA requires appropriate technical measures to protect it. A breach caused by a flat network, no MFA and untested backups is not just downtime; it is a compliance failure with reporting duties and potential fines attached.

How 2bo approaches SME security

We start with a practical assessment of your network, access and backups, then fix the highest-risk gaps first: segmentation, MFA, edge patching and tested recovery. No enterprise price tag, no hundred-page report, just the controls that stop the attacks that actually happen.

Not sure where your gaps are?

Book a practical security assessment with the 2bo team and we will show you the highest-risk gaps in your network, in plain language, with a fixed plan to close them.

Found this useful?

Back to News