Cybersecurity has become a business necessity, regardless of company size. Ransomware, phishing, BEC attacks, and DDoS attacks can affect anyone. No organization is immune to an attack. Smaller structures are no exception—in fact, why are they specifically targeted by cyberattacks?
It is clear that the number of cyberattacks against SMEs and micro-businesses is on the rise, as their security systems are often less sophisticated due to a lack of resources, information, or the implementation of inadequate measures to prevent cyber threats. Business leaders must recognize the risks and the stakes involved by adopting suitable solutions, despite the burden of costly investments and the need to train their teams.

- Why are small and medium-sized businesses targeted by cyberattacks?
- Downplaying risks
- Cybersecurity maturity
- Skills shortage
- Budgetary issues
Why are small and medium-sized businesses targeted by cyberattacks?
Let’s begin this overview by clearly defining the terms SME, micro-business, and mid-cap company.
SME: "Small and medium-sized enterprises are those that, on the one hand, employ fewer than 250 people, and on the other hand, have an annual turnover not exceeding 50 million euros"
INSEE
- SME: "Small and medium-sized enterprises are those that, on the one hand, employ fewer than 250 people, and on the other hand, have an annual turnover not exceeding 50 million euros" (INSEE)
- Micro-business stands for "very small enterprise"; they have no more than ten employees and an annual turnover that does not exceed two million euros. (Infonet)
- Mid-cap company is "an intermediate-sized enterprise with fewer than 5,000 employees and an annual turnover not exceeding 1.5 billion euros" (écono Gouv.fr)
Are SMEs well-prepared, equipped, and protected against these attacks?
Looking at the figures below, we can clearly see the key facts and begin to answer these questions. We still observe a lack of awareness regarding cyber issues and a lack of security maturity, even if this is starting to change.
The shortage of skills within technical teams—who mostly prefer working for large corporations—and the tight budgets dedicated to cybersecurity are further areas that need to be addressed.
Key figures:
- 95% of business leaders feel they have a good understanding of what cybersecurity is.*
- 1/3 of small businesses report having an IT specialist in charge of their company's cybersecurity.*
- For 6 out of 10 companies, the budget allocated to cybersecurity barely exceeds €1,000 per year.**
- Only 1 in 2 business leaders uses a VPN.**
*2021 IFOP survey
**Study revealed by Europe 1 in 2021
Risk mitigation
SMEs do not always prioritize attack prevention. Ransom demands, reputational damage, denial-of-service attacks, or sabotage are risks that are sometimes overlooked or underestimated by smaller organizations. They often believe that attackers prefer to target larger entities.
54% of SMEs believe they are safe from a cyberattack because they are not large enough to be targets.
ANSSI
However, Senate information report no. 678 states that in 2020, "43% of SMEs experienced a cybersecurity incident." In March 2020, the French National Cybersecurity Agency (ANSSI) noted a 400% increase in phishing attempts. Forrester Consulting reports that "between November 2020 and January 2021, the share of SMEs/micro-businesses with fewer than 250 employees affected by cyberattacks reached 33% over the previous 12 months."
These figures clearly prove that large organizations and smaller ones alike can be targets for cyber attackers. Everyone should feel concerned. Yet, according to Source IT in 2021, "among the 47% of SMEs that do not make cybersecurity a priority, 40% report having suffered an attack that resulted in a loss of revenue for 50% of them and a production stoppage for 23%." The importance of cybersecurity in business strategy remains underestimated.
For example, the lingerie group Lise Charmel was the victim of a ransomware attack in 2019. The group's 1,150 employees were affected, and the company was placed in receivership.[1]
Finally, let's look at these latest figures regarding tools: "97% use antivirus software, 88% use a firewall, and 79% implement data backups managed internally by their teams"1. For some, simply having an antivirus leads them to believe that the risk is covered or that their equipment is protected, forgetting about updates and the fact that antivirus software only detects threats based on previously known attacks. This lack of digital literacy puts them at great risk.
We can, however, temper these remarks in light of the pandemic and the rise of remote work. Companies have equipped themselves and are increasingly taking cyber risks into consideration.
Cybersecurity maturity
60% of European technology SMEs have insufficient resources to guarantee their cyber protection.
Oliver Wyman - European Digital Sovereignty
The other aspect addressed here is the low level of security maturity observed in SMEs/micro-businesses.
Even though "99% of business leaders claim to use at least one specific tool to protect their company," only "1 in 2 business leaders uses a VPN."[2].
The observation is that few SME/micro-business leaders are sufficiently supported in choosing their security solutions. In cases where IT points of contact exist, they are not necessarily cybersecurity specialists.
Another issue raised: when these medium-sized structures are equipped, half of the features are not activated and the tools are not properly configured due to a lack of knowledge, giving attackers free rein. There is therefore a real lack of protection.
Furthermore, it is clear that not all small structures have internal departments, and on top of that, employees are not always trained in cybersecurity. Yet, security maturity also requires through awareness of their staff. It is clear that there are still gaps or weaknesses in this area.
It is essential to provide regular, educational reminders that clicking on a malicious link is dangerous, that changing passwords regularly is important, that having a strong password is vital, that multi-factor authentication is essential, and that personal phones should not be used for professional purposes. These fundamentals must be reinforced.
Skills shortage
As we have noted, one of the major problems facing SMEs and micro-businesses is the lack of staff dedicated to cybersecurity within their organization. According to the Senate report, "human resources are becoming practically inaccessible." According to the Wavestone report5, more than 15,000 positions are available but unfilled. Skills are becoming increasingly scarce given the demand, and this shortage particularly affects small organizations that struggle to compete with the offers of large groups and attract talent. According to the Ifop survey[1], "1 in 5 SMEs has no one in charge of IT security," and "one-third of companies with 20 to 249 employees have a staff member dedicated to these issues." Consequently, it is the business owner themselves who ends up managing security issues. These companies do not always think to rely on experts.
Budgetary issues
"For six out of ten French companies, the budget allocated to cybersecurity does not exceed 1,000 euros per year"
Europe 1 study
Small organizations are increasingly aware of the efforts they must make regarding cybersecurity. Recent events in Ukraine and the global pandemic, which have fueled attacks, have raised awareness. However, the budgets allocated are still insufficient. The complexity of attacks requires equipping oneself with multiple tools, which entails costs. "Of the total IT budget for companies, 6.1% is dedicated to security"[3].
SMEs often equip themselves with free products and feel secure. They do not understand why they should pay for protection when they believe they can be protected without straining their budget. The problem is that unknown threats do not enter an antivirus signature database. This is why it is necessary to use a hyper-automated and hyper-industrialized solution. There is therefore a real need for support for this audience. It is urgent to raise awareness, advise, support, and establish cybersecurity systems in these companies. SMEs do not yet have access to "products adapted" to their budget.
TEHTRIS EDR is a solution provided in SaaS mode, via the cloud, with the ability to predict, prevent, detect, and react in terms of cybersecurity. The TEHTRIS EDR is sovereign, hyper-automated, and automatically neutralizes known or unknown threats in real time without human intervention.
Finally, it should be noted that for ANSSI, the budget dedicated to security for a company should represent 5 to 10% of the total budget.
We have seen that medium-sized companies are often limited in financial, technological, and human resources. This is why TEHTRIS recommends its TEHTRIS XDR Platform is modular, allowing each organization to add extra modules as needed. The TEHTRIS XDR Platform protects workstations, servers, mobile devices, tablets, networks, and data flows from attacks, while neutralizing threats. This offering is particularly well-suited to the needs of SMEs with 100 or more workstations.
Our solution enables:
- adapting detection rules using cyber threat intelligence.
- operational efficiency through hyper-automated neutralization.
- easy integration.
The key strengths of our solution include offering a personalized, easy-to-deploy, hyper-automated, and flexible service. This solution is designed for large corporations, government agencies, local authorities, and SMEs alike.
Smaller organizations should not be passive targets for attacks; they must react and anticipate. Their survival depends on it. TEHTRIS has planned for this. For those with fewer than 100 workstations, our TEHTRIS Store offering allows you to equip Windows devices with TEHTRIS technology EDR , adapted and configured for companies aware of the risk of ransomware.
Additionally, feel free to read our article on the challenges of IT security and the solutions to implement.
[1] Tribune de Lyon, March 3, 2020
[2] European Digital Sovereignty - Oliver Wyman – October 2020
[3] IFOP, Mid-sized company leaders facing the cyber threat - status report, 2018


