A survey has shown that 84% of small and medium enterprises (SMEs) in Malaysia have been victims of cyber incidents in the past year. According to the survey, 67% of local SMEs mistakenly believe that large businesses are at greater risk from cyber attacks than small businesses.
“In reality, smaller businesses face a greater degree of exposure to cyberattacks due to their size and resources , as well as a lack of capital to invest in cyber management tools,” Andrew Taylor said in Kuala Lumpur yesterday.

The report was prepared based on a survey of 1,400 respondents from 400 SMEs in Malaysia, Australia (400), Hong Kong (300) and Singapore (300). The respondents included 82% managers and 18% senior managers or directors below the board of directors from companies with two to 249 employees. The survey revealed that there was a difference between different sizes of SMEs in terms of cyber readiness.
Of companies with 100-249 employees, 70% had data breach contingency plans compared to 53% of smaller SMEs with fewer than 50 employees.
Malaysian small and medium enterprises (SMEs) responded faster to cyberattacks than in other markets surveyed, with 67% resuming operations within 12 hours of a incident . Two-thirds (66%) said everyone involved was aware of the appropriate protocol and the crisis response proceeded as planned, the report said.
The survey also found that 48% of cyber incidents were due to human error with customer records being the most commonly breached, with 40% of businesses experiencing a breach of customer records in the past year.
Other types of cyber incidents that were common among SMEs were computer network outages, which were experienced by 44% of businesses, and 35% were affected by ransomware attacks and phishing, where employees clicked on a malicious link sent to them via email.
He said any industry that uses computers to conduct business transactions is exposed to digital threats. “Most small and medium-sized businesses are more heavily dependent on technology for their transactions. “This is a real issue, particularly for small and medium-sized businesses. They should be concerned as it affects their cash flow and livelihoods,” Taylor said.
He added that it is important to note that when recovering files from a data breach, 16% of SMEs did not take steps to prevent recurring cyber incidents. About 14% of businesses reviewed security and processing procedures after a cyber incident ,but took no further action.
"Sometimes, these companies don't know exactly how to help themselves. There should be support through training to make sure they are aware of exactly what to do in such cases," he said.
With human error being the most common type of cyber incident, the study reports that 37% of SMEsaid their employees' poor perception of potential cyber threats is challenging their ability to protect their businesses from the risks they face.
Adding to this, 20% of SMEs believed that their employees were the weakest link in cyber defense and 41% believed that employees were neglecting their responsibilities around data protection.
Taylor said Malaysia had the highest number of cyber incidents out of the four countries studied.
However, 63% of companies increased security protection and processed data after a data breach, and 55% notified affected parties of the data breach after a cyber incident.
The survey also found that 70% of SMEs believe that insurance companies play an important role in helping businesses protect themselves from cyber risks.
Despite this, 60% also believe the industry is not moving fast enough to keep up with the rapidly evolving cyber landscape. Steve Crouch said he expects a large number of small and medium-sized businesses to fall victim to cyberattacks this year.
“Unfortunately, it appears that many SMEs in Malaysia mistakenly believed that their general insurance policies covered cyber, when in fact they probably did not. Given the large percentage of the economy that SMEs make up in the country, this is a critical issue to address,” he said.
