Cybersecurity is just as relevant for large organizations as it is for SMEs. Small businesses sometimes make the mistake of underestimating the risk, yet as we saw in our previous article, the effects of a cyberattack can have a severe impact on these sometimes fragile structures.
When you consider that an SME employee is 350%[1] more likely to be targeted by social engineering attacks than an employee at a large corporation, it is time to protect yourself.
Let’s look at the challenges and how to put safeguards in place to protect against these cyber risks.

- Small businesses and SMEs: prime targets for cyberattackers
- What protection solutions are available for your business?
Small businesses and SMEs: prime targets for cyberattackers
Cybercriminals are well aware that small businesses and SMEs are prime targets. When you look at the numbers these companies represent, it is easy to understand why attackers are interested in them.

It is worth remembering that these companies are both subcontractors and suppliers to large corporations, making them even more likely to be targeted in supply chain attacks.
According to a 2021 Symantec study, "71% of small businesses and SMEs that are hit by a cyberattack do not recover."
Among our European neighbors:
- 75% of German companies were victims of data theft, industrial espionage, or sabotage in 2019. (Source: German Association for Information Technology, Telecommunications and New Media)
- Spain is a country of SMEs, and that is where a cyberattack can be devastating and even lead to bankruptcy. In June 2021, the country suffered 40,000 cyberattacks per day: government agencies and SMEs are among the most vulnerable targets. The most affected sectors are insurance, TMT (telecommunications, media, and technology), manufacturing, banking, and public administration.
Economic stakes
A large corporation might survive an attack, but what about a smaller organization?
Proportionally, a cyberattack costs more for an SME than for a large corporation, which is more likely to have a security team to quickly mitigate the disruption. SMEs, conversely, will bear the full brunt of a productivity halt, leading to a net loss in revenue.
According to a survey conducted by MEDEF (the Movement of the Enterprises of France, an organization representing French businesses), in 2020, "20% of small businesses affected by an attack suffered damages exceeding 50,000 euros, with this figure even surpassing 100,000 euros for 13% of them."
Prioritizing IT security is a competitive lever; it guarantees performance by anticipating and avoiding revenue loss.
Implementing a security policy also protects an organization's reputation. We know that an attacked company can potentially lose clients, have orders cancelled, see its image degraded, and experience a loss of trust, thereby favoring the competition.
A cyberattack directly impacts revenue, jobs, and the life of the company.
20% of small businesses affected by an attack suffered damages exceeding 50,000 euros, with this figure even surpassing 100,000 euros for 13% of them.
Boomerang effect
Small and medium-sized enterprises can be both subcontractors and suppliers. They are particularly exposed to attacks. Cybercriminals may seek to reach the IT networks of their partners.
Beyond their own security, these small organizations must be secure for their clients. Every company is legally responsible. Furthermore, large corporations increasingly demand to know the defense capabilities of their partners, at the risk of no longer being able to work with them.
The 2021 Acronis report[2]reveals that "4 out of 5 companies have experienced a cybersecurity breach due to a vulnerability affecting their third-party supplier ecosystem."
They can also be attacked because their client is being attacked. A successful attack can compromise hundreds or thousands of SMEs, as was the case with the SolarWinds and Kaseya attacks.
Cloud security
With the rise of remote work, data storage has evolved significantly. The cloud has become essential. As a result, 40% of SMEs have already invested in cloud-hosted solutions.[3]This does not yet represent the majority of SMEs. Business leaders remain hesitant due to fear or a lack of knowledge, with some favoring hybrid storage.
"According to a Gartner study, public cloud spending could account for up to 14% of global IT spending in 2024."[4]
Naturally, this proliferation of storage zones also multiplies the risks, providing yet another reason to integrate cybersecurity into the choice of solution, as well as across the entire information chain: from the cloud to mobile devices and the network, ensuring end-to-end security.
Cyber insurance
Some small and medium-sized business leaders believe their level of cyber protection is sufficient, to the point of not needing to take out cyber insurance. And when they do consider it, they often fail to fully grasp the prerequisites required by firms: BCP (Business Continuity Plan), backups, staff awareness training, required patches, and so on. Consequently, some do not understand these levels of requirements, while others lack the capacity to meet them. These gaps in understanding the contract affect SME adoption of these policies.
The question of budget inevitably weighs in the balance; indeed, price increases do not help in the decision-making process.
Yet, for every company, having this coverage is a critical security issue. Cyber insurers will need to adapt to this new market, offer solutions specific to SMEs, and help and guide them in this choice—which is exactly what our partner Stoik does. Stoik offers comprehensive insurance dedicated to SMEs, with broader eligibility conditions at a price suited to these structures. They provide advice, audits, and awareness training.
What protection solutions are right for your company?
TEHTRIS: The solution for SMEs
The cost of a cyberattack is high, but the cost of inaction is just as high, if not higher. However, companies tend to think in terms of benefit-investment ratios or ROSI (Return On Security Investment). This opposition between a "risk culture" and a "productivity culture" does not help. We must shift the paradigm and consider security as one of the prerequisites for productivity.
Good IT security requires anticipation, which is why TEHTRIS supports SMEs in choosing technical solutions adapted to their structure. There are tools that can be implemented in advance to prevent risks and remediate them.
The solution TEHTRIS OPTIMUS combines the power ofEDR (Endpoint Detection & Response) and the efficiency of a Next-Gen antivirus within a single agent to detect and neutralize known and unknown threats in real time, without human intervention.
By combining the best of these two technologies, OPTIMUS utilizes all the major features deployed by TEHTRIS since 2012, including CTI, sandboxes, an antivirus database, or Cyberia artificial intelligence.
TEHTRIS OPTIMUS offers the simplicity of a turnkey solution tailored for SMEs.
The TEHTRIS XDR Platform is also a solution suited to SMEs, as it enables:
- adapting detection rules using cyber threat intelligence
- operational efficiency through hyper-automated neutralization
- easy integration
Finally, TEHTRIS solutions meet the needs of SMEs ; namely, having a local team to support them while offering a flexible solution.
Good cyber hygiene
In addition to TEHTRIS solutions and standard best practices such as ensuring you have a password manager, two-factor authentication (2FA), and limited access rights, we recommend:
- backing up data
- implementing a business continuity plan
- raising employee awareness
Alongside these actions, the French government has also addressed the issue.
- In July 2021, it introduced an alert system for cyberattacks. ANSSI and cybermalveillance.gouv offer a guide for executives to help them react as quickly as possible. We recommend reading the ANSSI guide: https://www.ssi.gouv.fr/guide/la-cybersecurite-pour-les-tpepme-en-douze-questions/
- The government advocates for "security by design" in software sold to small and medium-sized businesses (SMBs), proposing a package of simple solutions tailored to their needs.
- It recommends the pooling of employers.
- It proposes short cybersecurity training programs.
- Finally, it suggests a tax credit to encourage training and/or financial assistance for equipment purchases.
Other organizations have opted for a coalition approach. This is the case for Airbus, Thales, Dassault, and Safran, which launched AirCyber in January 2019 through BoostAerospace (established in 2011) to help aeronautical SMBs adopt cybersecurity solutions endorsed by major accounts. It is "a mutual support and maturity assessment program initiated by the sector's equipment manufacturers."
Here is the link: https://boostaerospace.com/aircyber/
In Spain, the plan focuses on fostering a culture of cybercrime prevention among citizens and businesses, as well as promoting training and specialization in cybersecurity and cybercrime for members of the armed forces.
While the maturity of small and medium-sized businesses is evolving, they still require support to make a culture of security automatic and intuitive. TEHTRIS works every day to adapt its products and solutions to all organizations, whether small or large.
[1] Barracuda Networks, 2022
[2] Acronis Cyberthreats Report Mid-year 2021
[3] Usine Digitale, [Study] Losses due to cybercrime amount to more than 1% of global GDP
[4] According to a Gartner study published on 11/18/2020


