Site navigation

Cyber Skills Shortage a Top Security Threat to SMBs

Elizabeth Greenberg

,

cyber skills shortage
“A shortage of in-house cybersecurity skills is one of the biggest cyber risks for businesses today,” Aaron Bugal, field CTO of Sophos, said.

The cybersecurity skills shortage is damaging small and medium sized businesses (SMBs), as talent shortages cause chronic burnout to flare, creating more vulnerabilities for threat actors to exploit.

This is according to Sophos, the security vendor, which surveyed 5,000 IT and security professionals in 14 different countries, who work in organisations with 100 to 500 employees.

The report, titled Addressing the cybersecurity skills shortage in SMBs, reveled that the ongoing skills shortage is ranked as the second biggest risk to SMBs, topped only by zero-day threats.

SMBs were more likely (96%) to find basic security tasks, such as identifying and prioritising signals to investigate and getting enough data to identify if a signal is harmful, more difficult than larger enterprises.

Further, SMBs struggle to have the resources to battle some of the most commonly exploited vulnerabilities.

For instance, about 91% of ransomware attacks begin outside of standard business hours, but SMBs have no one monitoring or investigating security alerts a third of the time, including during business hours.

This can result in more devastating attacks. For SMBs, 74% of ransomwre attacks resulted in data encryption. While this figure remained high (72%) for businesses with 501-1000 employees, it dropped (to 66%) for larger enterprises with 1001-5000 employees.

A smaller team will also mean that burnout, already a scourage among the cybersecurity community, can become chronic.

85% of organisations in Asia stated that they experience fatigue and burnout among their cyber and IT professionals, Sophos cited a past report.

90% of those organisations already experienced burnout says the problem has only increased in the last year, with nearly a third (30%) saying burnout increased significantly.


Recommended


This can lengthen response times to malicious activities, prolonging risks and increasing damage.

Three quarters (75%) of SMBs find remediating malicious alerts or incidents in a timely way challenges, likely due to having a smaller team suffering from burnout.

“A shortage of in-house cybersecurity skills is one of the biggest cyber risks for businesses today,” Aaron Bugal, field CTO of Sophos, said.

“When you couple this mounting skills gap with a major burnout crisis among cybersecurity professionals, small businesses are more vulnerable to attacks.

“With 91% of ransomware attacks occurring outside of standard business hours, SMBs need to monitor their networks 24/7 to identify malicious activity before an attacker can exfiltrate or encrypt data.

“Businesses should take stock of their security capabilities and look for opportunities to improve their overall cyber resilience. It’s a delicate balance between people, processes and technology. Understand your team’s strengths and limitations and balance them with external expertise to enhance the security posture.”

Elizabeth Greenberg

Staff Writer

Latest News

AI Infrastructure

Scottish Parliament Votes to Pause All AI Data Centre Applications

Cybersecurity Editor's Picks Security

Cyber Essentials Certifications Rise as SME Uptake Remains Limited

AI Editor's Picks Funding

Edinburgh Graduates’ AI Infrastructure Firm Expanse Raises $5.3m

Featured Finance

Fintech Summit 2026 Countdown Enters Final Three Weeks