Connect with us

Hi, what are you looking for?

HEADLINES

Only half of SMB leaders are confident that ex-employees can’t access company’s digital assets

Other popular cost-cutting steps include a decrease in spending for advertising and promotion (36%) and vehicles (34%). Cybersecurity, on the other hand, appeared not to be an area of the business where leaders would prefer to save budget.

A recent Kaspersky study on the behavior of small and medium businesses during crises shows staff reductions may cause additional cybersecurity risks. Yet only 51% of organizations’ leaders are confident that their ex-employees don’t have access to company data stored in cloud services, and just 53% are sure that former workers can’t use corporate accounts. 

While, according to studies team retention was the top priority for almost half of organizations throughout the pandemic, many businesses still might have to resort to job cuts in order to reduce costs during hard times. Kaspersky surveyed more than 1.300 business leaders in small and medium-sized organizations to learn what tactics they chose to keep their business afloat, and what cybersecurity risks anti-crisis measures could bring.

Given that almost half of respondents couldn’t confidently claim that their ex-employees didn’t have access to their company’s digital assets, reductions in staffing may put the safety of data and company livelihood at additional risks. 

Ex-employees misuse of data in new jobs or to drum up business for themselves were major concerns for bosses. The survey results suggest that most business leaders are worried that former employees will share the company’s internal data with new employers (63%) or use corporate data such as previous client databases, to launch their own business (60%). Overall, 31% of respondents consider reductions in employment as a possible measure to cut costs in case of a crisis. 

Other popular cost-cutting steps include a decrease in spending for advertising and promotion (36%) and vehicles (34%). Cybersecurity, on the other hand, appeared not to be an area of the business where leaders would prefer to save budget.

Advertisement. Scroll to continue reading.

Where would SMBs business leaders cut costs in case of a crisis?

“Unauthorized access can become a huge problem for any business, affecting the competitiveness of a company when corporate data is transferred to a competitor, sold off, or deleted,” explains Alexey Vovk, Head of Information Security at Kaspersky. 

“This problem becomes more complicated when employees actively use non-corporate or ‘shadow IT’ services which are not deployed or controlled by corporate IT departments. If the usage of these services is not managed after an employee is dismissed, there is little chance that access to information shared via these applications will be shut off for a former worker,” adds Vovk. 

To make sure that uncontrolled accesses and shadow IT won’t affect your company’s efficiency and security, Kaspersky recommends the following steps:  

  • Keep control of the number of people with access to crucial corporate data, reducing the amount of data available to all employees.  Breaches are more likely to occur in organizations where too many employees work with confidential valuable information that can be sold or somehow used. 
  • Set up a policy for access to corporate assets, including email boxes, shared folders, and online documents. Keep it up to date and remove access if an employee leaves the company. Use cloud access security broker software that helps manage and monitor employee activity within cloud services and enforces security policies;
  • Make regular backups of essential data to ensure corporate information stays safe in case of emergency;  
  • Provide clear guidelines on the usage of external services and resources. Employees should know which tools they should or shouldn’t use and why. When switching to any new software for work, there should be a clear procedure of approval with IT and other responsible roles; 
  • Encourage employees to have strong passwords for all digital services they use and to change passwords regularly;
  • Regularly remind staff about the importance of following basic cybersecurity rules relating to safe account and password management, email security, and web browsing. A comprehensive training program will allow your workers not only gain the necessary knowledge but also to apply it in practice; 
  • Employ dedicated cybersecurity services which provide visibility over cloud services, such as Kaspersky Endpoint Security Cloud.  

For more actionable recommendations on how to protect your business without additional expenses please visit Kaspersky Cybersecurity on a Budget Hub

The full report and more insights on small and medium businesses crisis attitude and tactics are available via the link.

Advertisement. Scroll to continue reading.
Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

Maya has already integrated National ID eVerify, the Philippine Statistics Authority’s identity-verification service, into its onboarding process. Since early this year, eligible customers have been...

HEADLINES

In 2025 alone, Converge denied nearly 12 billion entry requests to websites hosting dangerous, inappropriate, and harmful content that attempted to pass through its...

HEADLINES

The announcement represents one of the first major third-party technology integrations following the launch of Sophos Fusion, demonstrating Sophos' commitment to an open ecosystem...

HEADLINES

APAC consumers are more concerned about digital tech usage for crime than consumers globally (35% vs 32%). The awareness is highest in Thailand (39%),...

HEADLINES

“It is the time for Radenta to demonstrate that it is strongly committed to protecting client data,” remarks Nereo Bolante, Co-Director, Radenta Ethics, Compliance, and Governance Team...

HEADLINES

Attackers are operationalizing artificial intelligence (AI) to collapse attack workflows from weeks to days. The report finds that AI’s most immediate impact on cybercrime...

HEADLINES

In July 2026, researchers from the Kaspersky Global Research and Analysis Team (GReAT) team identified a new campaign, dubbed GoSerpent, representing a sophisticated and...

HEADLINES

The prominence of identity attacks in ransomware indicates a shift in method, as attackers increasingly recognize identity as a key component in ransomware delivery....

Advertisement