Indian small and medium-sized businesses are preparing to increase cybersecurity spending as cyber incidents become more frequent, while gaps in monitoring, in-house expertise and employee awareness continue to leave many firms exposed.
Around 84% of SMEs intend to increase cybersecurity spending over the next 12 to 24 months. The shift comes as 40% of SMEs reported experiencing a cyber incident during the past two years.
How Many SMEs Have Faced Cyberattacks?
The cyber threat is already widespread among smaller businesses. A separate survey found that 87% of Indian small and medium-sized businesses surveyed had experienced a cyber incident during the previous year.
Across the Asia-Pacific region, phishing, software vulnerability exploitation and mass malware were among the most frequently encountered threats.
Smaller businesses were found to be facing many of the same cyber risks as larger companies, despite having fewer resources and less specialised security expertise.
The survey covered IT security specialists across small and medium-sized businesses and enterprises in 15 countries. On average, organisations in the Asia-Pacific region experienced three different types of security incidents during the previous year.
What Cyber Threats Are SMEs Facing?
For small and medium-sized businesses, the most commonly encountered incidents included software vulnerability exploitation, phishing and mass malware attacks.
Software vulnerability exploitation accounted for 20% of incidents, followed by phishing at 19% and mass malware attacks at 18%. Zero-day exploits were encountered by 6% of organisations.
India recorded an incident rate of 87% among SMEs surveyed. Vietnam had the highest rate in the region at 97%, followed by Malaysia at 95%, Indonesia at 92% and Thailand at 88%.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Why Are Businesses Spending More?
The growing number of incidents is influencing cybersecurity budgets. Around 84% of Indian SMEs intend to increase cybersecurity investments during the next 12 to 24 months.
The planned spending covers areas including digital systems, employees working across different environments and growing exposure to online threats.
However, increasing budgets does not automatically mean businesses are building continuously monitored cyber operations. Only 12% of SMEs continuously monitor their cybersecurity environment.
Where Is the Cybersecurity Money Going?
Nearly 35% of SMEs use multiple cybersecurity tools but have limited visibility into their risks. This creates another challenge because using several security products does not necessarily provide businesses with a complete picture of what is happening across their systems.
Among SMEs planning to increase cybersecurity spending across the Asia-Pacific region, 78% are directing additional funds towards cybersecurity budgets this year.
Nearly half, or 48%, are expected to put additional money towards IT and IT security teams. Around 32% plan further spending on advanced security solutions such as extended detection and response, network detection and response, and security information and event management.
The findings indicate that cybersecurity spending is increasingly being directed towards both software and the people and capabilities needed to manage security.
Why Is Cybersecurity Expertise a Problem?
A shortage of skilled cybersecurity professionals remains one of the clearest weaknesses. Around 45% of Indian SMEs identified a lack of in-house cybersecurity expertise as their biggest challenge.
The problem extends beyond specialist security teams. Among SMEs surveyed across the Asia-Pacific region, 26% identified a lack of cybersecurity awareness among non-IT employees as a factor increasing the risk of successful cyberattacks.
Another 24% pointed to a lack of expertise among IT security staff.
Other weaknesses included outdated software or hardware, the inability to centrally monitor and respond to alerts, irregular risk assessments and the absence of necessary security solutions.
How Can Employees Increase Cyber Risk?
Cybersecurity risks are not confined to an organisation’s IT department. Employees who handle emails, documents, passwords, payments and company systems can also become part of the security chain.
Businesses were advised to establish clear cybersecurity guidelines covering browsing and passwords, while requiring IT approval for new software.
The findings suggest that improving cybersecurity requires more than buying additional security products. Businesses also need better monitoring, regular assessments, trained employees and sufficient expertise to identify and respond to threats.
What Role Could AI Play?
Artificial intelligence is emerging both as an additional cybersecurity tool and as a potential source of further risk for smaller businesses.
Around 35% of Indian SMEs view AI as an enabler for cybersecurity, while 34% expect AI-powered threats to affect their businesses.
This creates a dual challenge for smaller firms. The same technology that can strengthen security teams, detect threats and improve defensive capabilities may also be used by attackers to increase the scale or complexity of cyberattacks.
As SMEs increase cybersecurity budgets, the figures indicate that spending alone may not close existing security gaps. Continuous monitoring, skilled personnel, employee awareness and stronger visibility across digital systems remain important parts of improving cyber preparedness.
The420 Cyber Readiness Check
Higher cybersecurity spending can strengthen small and medium-sized businesses, but money alone cannot close every security gap.
The findings show that continuous monitoring, trained employees, regular risk assessments and skilled cybersecurity staff remain equally important.
As AI-powered threats grow alongside traditional attacks such as phishing and malware, businesses need to focus on both technology and the people responsible for using and protecting it.
About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics