Summary Points
- Medium-sized SMEs face higher cyber threat exposure, with 76% experiencing attacks in the past six months and nearly half suffering moderate to severe impacts such as financial loss and device damage.
- AI-enabled scams, deepfakes, and sophisticated cyber attacks have become the fourth most prominent threat, making fraud attempts more convincing and harder to detect.
- Under-reporting of cyber incidents hampers understanding of the threat landscape; many businesses dismiss lower-level attacks as insignificant, reducing the ability to respond and learn.
Threats, Techniques, and Targets
The research shows that small and medium-sized enterprises (SMEs) in New Zealand are facing rising cyber threats. Nearly half of the SMEs, 43%, believe they are vulnerable to cyber attacks. Larger SMEs, with six to 49 employees, feel more exposed, with up to 59% feeling at risk.
Medium-sized businesses are more likely to face direct threats. Over three-quarters, 76%, of companies with 20 to 49 employees, reported experiencing a cyber threat or attack in the last six months. Many faced moderate to severe impacts, including financial loss, device damage, and stress.
The threats are becoming more sophisticated. Artificial intelligence (AI) is now used by cybercriminals. AI helps make scams, phishing attempts, deepfakes, and impersonation attacks more convincing. Criminals use AI to increase the effectiveness of their attacks and make them harder to recognize.
Impact, Security Implications, and Guidance
The impact of these threats can be serious. Many businesses reported moderate to severe effects. Despite the rising threats, many SMEs still rely mainly on technical controls. Staff training on cybersecurity remains limited, with nearly one-third of SMEs not training employees at all.
Under-reporting of incidents is common. About 68% of SMEs report or disclose cyber threats, but almost a third do not. Many do not see the value in reporting minor incidents. This limits understanding of the broader threat landscape and reduces support for victims.
To strengthen security, businesses should keep software updated, use multi-factor authentication, and regularly back up data. Staff should be trained to recognize suspicious activity and respond appropriately. For specific remediation steps, organizations should consult their security vendors or relevant authorities.
Expand Your Tech Knowledge
Explore the future of technology with our detailed insights on Artificial Intelligence.
Explore past and present digital transformations on the Internet Archive.
ThreatIntel-V1
