According to Kaspersky's survey across 18 countries, more than half of small and medium-sized businesses in Türkiye faced at least one cyber incident last year. Attackers are after customer and employee data rather than direct payment.
On 8 September 2026, Kaspersky published the results of its global survey on small and medium-sized businesses. The study covered 1,800 respondents across 18 countries, with 616 representatives in the SME segment. The findings for Türkiye match what we see in the field.
One in two businesses was attacked
According to the survey, 58% of SMEs in Türkiye reported experiencing at least one cyber incident in the past year, matching the global average. The most damaging attack types included phishing, exploitation of vulnerabilities in software and web applications, malware, ransomware, and attacks through external remote access.
In Türkiye, 26% of respondents reported financial loss as the outcome of their most serious incident.
The target is data, not money
The most striking finding concerns attacker motivation. Among respondents in Türkiye, theft of customer personal data (35%) and theft of employee personal data (35%) tied for first place. Extortion attempts followed at 30%.
This makes an attack more than an IT problem. A business that leaks customer data is simultaneously in breach of its data security obligations under Turkish data protection law. For 2026, the administrative fine for this breach ranges from 427,000 TRY to 17 million TRY.
Attacks target the IT department
The data shows cybercriminals primarily target technical teams. In Türkiye, the most targeted departments were IT (61%), IT Security (39%), accounting and finance (24%), and R&D (22%). In the most serious incidents, an average of three departments were affected simultaneously.
The practical meaning is simple: attackers go after whoever holds the broadest access. Compromising a single administrator account means opening the entire network.
What measures did businesses take?
Following these breaches, the steps businesses in Türkiye prioritised were:
- Launching or updating mandatory IT security training for all employees (39%)
- Implementing multi-factor authentication (39%)
- Establishing or updating a password policy (35%)
It is telling that the list begins not with expensive hardware but with training and authentication. Most attacks start not with a technical vulnerability but with a link an employee clicked.
What we recommend at Kamer Bilişim
The three most common gaps we encounter across the businesses we serve on Istanbul's Anatolian side are:
- Backups that are never tested. It is not enough for a backup to appear successful; what matters is being able to restore. A backup without periodic restore testing is useless during a ransomware incident.
- Departed staff retaining access. A former employee's email account, VPN credentials, and shared folder access can remain open for months.
- Multi-factor authentication not being enabled. Even if a password is stolen, a second verification layer stops most attacks, and it costs nothing extra to set up.
These three items are achievable even on a limited budget and close off the bulk of the risk.
To review your current position, your backup setup, and your access controls, get in touch with us. ← "get in touch with us" seç, link, /en/contact
Source: Kaspersky SME Cybersecurity Survey, September 2026.