South African small companies, beware of cyber crooks who are after your password
When a small business owner is also responsible for production economics, financial reporting, and marketing, cybersecurity might look difficult and, at times, superfluous. However, cyber thieves are taking advantage of this disrespect for IT security. Kaspersky researchers examined the dynamics of assaults on small and medium-sized firms between January and April 2022, as well as

South African small companies, beware of cyber crooks who are after your password

When a small business owner is also responsible for production economics, financial reporting, and marketing, cybersecurity might look difficult and, at times, superfluous. However, cyber thieves are taking advantage of this disrespect for IT security.
Kaspersky researchers examined the dynamics of assaults on small and medium-sized firms between January and April 2022, as well as the same time in 2021, to determine which risks offer a growing threat to entrepreneurs.
When compared to the same time in 2021, the number of Trojan-PSW (Password Stealing Ware) detections in South Africa grew by 69% in 2022 – 20 922 detections in 2022 compared to 12 344 in 2021.
Trojan-PSW is malware that collects passwords and other account information, allowing attackers to gain access to business networks and steal sensitive data.
Internet assaults, notably web pages with redirects to vulnerabilities, sites with exploits and other harmful applications, botnet C&C centres, and so on, are another frequent attack method used against small enterprises.
While the number of these assaults in South Africa reduced by 13% in the first four months of 2022 (419 506 infections in 2022 compared to 483 846 infections in 2021), the number of Internet attacks remained high.
Many firms have implemented the Remote Desktop Protocol (RDP) with the trend toward remote working, a technology that allows PCs on the same corporate network to be linked together and accessed remotely, even while employees are at home.
While the aggregate number of RDP assaults has dropped in South Africa, this issue remains a global concern. For example, in the first trimester of 2021, there were around 47.5 million attacks in the United States, but the number for the same time in 2022 had climbed to 51 million.
A specialised security solution allows for the visualisation of attacks and offers IT managers with a simple tool for event investigation.
The earlier they can figure out where and how a leak happened, the better they’ll be able to deal with any bad implications.
Even small firms with minimal IT resources must safeguard all of their working equipment against cyber attacks, including PCs and mobile phones.
“With the shift to remote working and the introduction of numerous advanced technologies in the daily operations of even small companies, security measures need to evolve to support these sophisticated setups. Cybercriminals are already way ahead of the curve, so much so that virtually every organisation will experience a breach attempt at some point.
“For small companies today, it’s not a matter of whether a cybersecurity incident will happen but when. Having trained staff and an educated IT-specialist is no longer a luxury but a must-have part of your business development,” said Denis Parinov, a security researcher at Kaspersky.
To protect your business, Kaspersky recommends:
- Providing your staff with basic cybersecurity hygiene training as many targeted attacks start with phishing or other social engineering techniques.
- Using a protection solution for endpoints and mail servers with anti-phishing capabilities to decrease the chance of infection through phishing emails.
- Taking key data protection measures. Always safeguard corporate data and devices, including by using password protection, encrypting work devices and ensuring data is backed up.
- Keeping work devices physically safe – do not leave them unattended in public, always lock them and use strong passwords and encryption software.



