Small and medium-sized enterprises (SMEs) are the backbone of most economies, including Kenya’s, yet they’ve also become the preferred target for cybercriminals. Roughly four in ten cyberattacks worldwide are now aimed at small and mid-sized businesses, and the fallout from even one incident can run into hundreds of thousands of dollars. Here’s what every SME owner should know.
Why does this matter now?
As more businesses move payments, records, and operations online, they open up more digital doors for attackers. SMEs hold the same valuable data as large corporations, customer details, financial records, banking credentials, but with far weaker defenses. Around 43% of all cyberattacks now target small and medium-sized businesses specifically (Verizon/Accenture data).
Phishing and business email compromise is the single most common cause of SME breaches. Ransomware now features in a majority of small-business breaches and can demand payouts well beyond a typical SME’s annual security budget. Other frequent threats include malware, social engineering fraud (fake invoices, impersonated executives), and weak or stolen credentials, which can sit undetected in a network for months.
Many owners assume they’re “too small to be a target,” when attackers often prefer SMEs for exactly that reason. Add limited budgets, little or no dedicated security staff, competing day-to-day priorities, and low employee awareness, and the result is a dangerous mismatch: SMEs are attacked at rates comparable to or higher than large enterprises, while investing a fraction of the resources in defense.
What to protect first
Priority assets include customer data, financial and banking records, employee records, intellectual property, and the operational systems (POS, inventory, cloud tools) the business runs on daily. A useful test: if this system or dataset leaked tomorrow, how much would it cost us?
The most effective protections are often the most affordable: multi-factor authentication (MFA), which blocks the vast majority of automated account-takeover attempts; strong, unique passwords via a password manager; regular software updates; antivirus protection; a firewall; tested backups; and a basic written security policy.
Apply the principle of least privilege so staff only access what their role needs, review access when people join or leave, enforce MFA everywhere possible, and segment sensitive systems like finance from the general network. Access control is a governance issue as much as an IT one.
Employees at small businesses face disproportionately high rates of social engineering attempts. Regular, practical training, even quarterly, helps staff spot phishing, verify unusual payment requests through a second channel, and know who to notify if something looks wrong. It’s far cheaper than recovering from one successful attack.
Guarding against phishing and fraud
Set up email authentication (SPF, DKIM, DMARC) to prevent domain spoofing, require verbal confirmation for any change to supplier payment details, use spam filters, keep reporting channels blame-free, and vet third-party vendors carefully.
Follow the 3-2-1 rule: three copies of data, on two media types, with one stored off-site. Test backups regularly, since an untested backup isn’t a reliable one, and keep at least one copy offline or immutable so ransomware can’t reach it too. Many SMEs hit by an attack take a full day or more to get back online, and every hour carries a direct cost.
Build data protection questions into procurement, favor reputable providers with strong built-in security, pilot new tools (especially AI platforms) carefully, and train staff before rolling anything out. Good security is increasingly a competitive advantage, not just a cost.
As an SME grows, informal security stops being enough. A written policy, real-time monitoring tools, periodic risk assessments, and a rehearsed incident response plan give the business the structure it needs. Only a minority of SMEs currently have these in place, which is often what separates a quick recovery from a lasting one.
How Ndakala Advisory can help
Cybersecurity for an SME is rarely just a technology problem, it’s a governance, risk, and compliance problem. As a professional services firm offering audit, tax, legal, and advisory expertise across Kenya and the wider African market, Ndakala Advisory LLP helps SMEs assess risk and governance gaps, strengthen regulatory compliance, build practical policies sized to the business, and make sounder decisions around technology adoption as they grow.
Conclusion
Cybersecurity isn’t optional for SMEs anymore, it’s part of the cost of doing business in a digital economy. The businesses that come out ahead get the basics right: MFA, trained employees, tested backups, and a clear response plan, layered with good governance and regular risk assessment. Start small, stay consistent, and treat every step today as protection for the business you’re building tomorrow.
This article was prepared by Melany Mutheu, Cyber Security Specialist at Ndakala Advisory LLP. For advice on cybersecurity matters, contact our team or visit ndakalaadvisory.co.ke.







