Цифровая безопасность · 1 апреля 2025 · 3 мин чтения

Rising cyber risks for SMEs

In April, the WEF released the Global30 Cybersecurity Outlook 2025, highlighting 3 cybersecurity challenges: (1) growing cyber risks for SMEs, (2) growing interest of organized crime groups in the cybercrime “marketplace” and the declining cost of AI attacks, and (3) differences in how countries approach cybersecurity regulation and the resulting increased cost of compliance.

Из выпуска мониторинга No. 4 (16), April 2025 · выпуск целиком, PDF · на сайте Института Гайдара

In April, the WEF released the Global1 Cybersecurity Outlook 2025, highlighting 3 cybersecurity challenges: (1) growing cyber risks for SMEs, (2) growing interest of organized crime groups in the cybercrime “marketplace” and the declining cost of AI attacks, and (3) differences in how countries approach cybersecurity regulation and the resulting increased cost of compliance.

The cyber resilience risks of large organizations are linked to the vulnerabilities of SME suppliers. This is the opinion of 54% of surveyed CEOs of large companies. By attacking the security system of an SME supplier, an attacker can gain access to the entire ecosystem of a large organization.

Another trend is the development of cooperation between cybercriminals and traditional criminal groups. For example, more than 220,000 people have been sold into slavery in online fraud “factories” in Southeast Asia. Such “factories” collect personal data, launch disinformation campaigns, and conduct social engineering (psychological manipulation of people to commit certain actions).

The development of generative AI reduces the cost of conducting a “successful” attack. In this case, criminals do not even try to hack into the IT infrastructure of organizations but use deepfakes and techniques to convince employees of organizations to make transactions in their favor. Last year alone, losses to individuals and companies from cyber fraud totaled $1 trillion, and some economies lost more than 3% of GDP.

Countries differ in their approaches to cybersecurity regulation, creating barriers to business. For example, OECD countries have different requirements for the timeframe for critical infrastructure operators to report cyber incidents, different requirements for software2 products to have SBOM, and so on.

It is worth noting that the cybersecurity risks highlighted in 2025 echo the challenges that the WEF has been highlighting since 2022 (when the first Global Cybersecurity Outlook appeared). However, a retrospective analysis of WEF documents since 2006 shows that some risks have faded into the background over almost 20 years. For example, the threat of DDoS attacks was one of the most significant in 2013, but in 2025, it faded into the background. According to WEF surveys, only 6% of respondents consider this problem significant.

Russia’s experience

The Russian market echoes the international trends and challenges listed in the WEF report. According to Solar Group (a major company in the cybersecurity market), in 2024 the company repelled more than 1.8 bn cyberattacks on clients' information systems, which is 2.4 times more than in 2023. The majority of cyberattacks in Russia are on SMEs - 81% (38% - small and 43% - medium-sized3 businesses).

Russia is developing cybersecurity regulation. In April 2025, amendments were adopted establishing the obligation of critical infrastructure entities to use only domestic software, information about which is included in the Unified Register of Russian Computer Programs and Databases, and which complies4 with information protection requirements. Such critical information infrastructure includes information systems and networks operating in the healthcare, transportation, communications,5 energy, banking, and industrial sectors. Unlike OECD countries, Russia has not introduced horizontal requirements for all software developers, such as SBOM - such requirements are still in force only for organizations that receive a license from the FSTEC (primarily for critical information infrastructure operators). The requirement for software products to have SBOM allows for a better assessment of software hacking risks.

  1. https://digital.gov.ru/activity/it-obrazovanie/kod-budushhego-ii
  2. https://www.weforum.org/publications/global-cybersecurity-outlook-2025/
  3. Software Bill of Materials, a machine-readable list of all the libraries, frameworks, drivers, and other components from which the software is built - similar to the composition label on a food product.
  4. https://rt-solar.ru/analytics/reports/5335/
  5. https://rt-solar.ru/events/news/4991/?utm_source=chatgpt.com
  6. https://innostage-group.ru/press/news/eksperty-innostage-kiberatak-na-sredniy-i-malyy-biznes-v-2024-godu-stanet-sushchestvenno-bolshe/?utm_source=chatgpt.com
  7. Federal Law No. 58-FZ of 07.04.2025 “On Amendments to the Federal Law ‘On the Security of Critical Information Infrastructure of the Russian Federation’”.
  8. P. 8 Art. 2 Federal Law of 26.07.2017 No. 187-FZ “On the Security of Critical Information Infrastructure of the Russian Federation”.

From the monitoring issue No. 4 (16), April 2025. Download the full issue (PDF) · issue page at the Gaidar Institute

Читайте также