Serdar Aydemir, Komtera’s Ankara and Anatolian Channel Sales Manager, made assessments regarding the measures SMEs should take in the field of cybersecurity under the title “Are SMEs under threat? What approach should they take against cyberattacks?”
Aydemir stated the following:
“SMEs are actually one of the weakest links in terms of cybersecurity. When we compare large companies with SMEs, we see that SMEs, as small and medium-sized enterprises, do not fully invest in technological products. We observe that they make insufficient investments. Recently, when I visited a factory, they received a letter from the BTK (Information and Communication Technologies Authority) stating, ‘You have an open port. If you don’t take precautions regarding this, you will be fined.’ They immediately contacted us and requested a firewall. Just to avoid that law or the fine, we encounter a situation where, when SMEs are hacked, they come to us after the hacking and say, ‘Let us get whatever we need.'” They turn on the tap, they buy everything they need – firewall, antivirus, whatever – and there’s no budget constraint. But the usual approach is: “We’re a small company, what will hackers do to us, where do they find us?” Actually, hackers don’t target specific companies. Every company has an external IP address. When you type “what is an IP address?” into Google, you’ll see that it’s an external IP address. They scan that IP pool worldwide using artificial intelligence. They see that there are open ports. From there, they directly obtain the username and password using a brute-force attack. After obtaining the password, they encrypt the files inside and then demand a ransom. We encounter this in individual computers as well. In SMEs, managers and business owners need to have some knowledge about what and how to invest. Some have many IT managers, some have none at all. Some only seek out external consultants. SMEs really need reliable consultants, and some products are indispensable. This could be a firewall, an endpoint, hotspot software, or backup software. When a company that has already been hacked comes in, the first thing we ask is: “Sir, please calm down, restore from backups first.” The answer is: “Our backups are also encrypted.” Here, we actually see that SMEs don’t have a backup policy based on a 3-2-1-0 rule. Companies try to continue their operations by using cracked antivirus software or using modem features instead of firewalls, until they get hacked. If a company is hacked in a region, this spreads as a rumor, prompting other companies to make similar investments. I wish it weren’t like this, but unfortunately, some companies in Türkiye don’t understand this until it happens to them. Therefore, SME-sized companies absolutely need to have a check-up, something like a penetration test, to find out “What vulnerabilities do we have, what are our shortcomings?” We ask companies: “How valuable is your data?” Data is worth its weight in gold. Today, we hear about many companies that have lost their data and gone bankrupt. Because nothing happens without data. Company managers also need to understand the importance of this data and take measures to protect it with cybersecurity products. There are mandatory requirements. If you look at Law No. 5651, the Personal Data Protection Law, and ISO 27001, you’ll see that these are already required products. After investing in these products, the benefits need to be explained properly to company owners. When you present it like a report, saying, “We’ve bought you a firewall. Here are the benefits: You’ll log users, you’ll implement restrictions, and you’ll protect against cyberattacks. This is a threat that has emerged,” then SME and company owners will start making this investment.
Cybersecurity in SMEs: Why It Matters?
Small and medium-sized enterprises (SMEs) are generally in a weaker position regarding cybersecurity compared to large companies. The main reason for this is that SMEs do not give enough importance to technological investments and are deficient in this area. However, cyberattacks do not only target large companies; businesses of all sizes can face such threats. Therefore, it is of great importance for SMEs to increase their awareness of cybersecurity and take the necessary precautions.
Challenges Faced by SMEs in Cybersecurity
SMEs often neglect cybersecurity investments. One reason for this is the thought, “We are a small company, who would target us?” However, hackers carry out attacks via IP addresses, not company names. Therefore, every company needs to take cybersecurity measures.
Consequences of Insufficient Investments
SMEs often start taking security measures after they have been subjected to a cyberattack. This leads to even greater damage after the attack. For example, a company that doesn’t back up its data may lose it after an attack, and this could lead to bankruptcy.
Necessary Cybersecurity Measures
There are some basic cybersecurity measures that SMEs should take. These include firewalls, antivirus software, backup systems, and penetration testing. These measures make the company more resilient against cyberattacks.
Legal Obligations and Standards
SMEs are required to comply with legal regulations such as Law No. 5651, the Personal Data Protection Law (KVKK), and ISO 27001. These regulations determine which cybersecurity measures companies should take. Therefore, it is important for SMEs to fulfill these legal obligations.
Cybersecurity Awareness and Training
SMEs need to increase their awareness of cybersecurity and train their employees on this subject. This makes the company better prepared for cyberattacks and minimizes potential damage.
Conclusion and Recommendations
SMEs should be more conscious and proactive about cybersecurity. Without sufficient investment, cyberattacks can cause serious damage. Therefore, it is crucial for SMEs to take cybersecurity measures, comply with legal obligations, and train their employees. These steps both enhance the company’s security and help create a more sustainable business model in the long run.
About the Wise
Similar Videos from this Wise
What should companies do if they say, “We invested, yet we’re still being hacked”?
Serdar Aydemir, Komtera’s Ankara and Anatolian Channel Sales Manager, evaluated ways to increase the effectiveness of c...
What cybersecurity investments should companies with 5-10 employees make?
Serdar Aydemir, Komtera’s Ankara and Anatolian Channel Sales Manager, evaluated the cybersecurity measures that small b...
The story of the business that was hacked and then asked for a $1 million ransom.
Serdar Aydemir, Komtera’s Ankara and Anatolian Channel Sales Manager, evaluated the critical processes following a cybe...
Why are small businesses wrong when they say, “We won’t get hacked”?
Serdar Aydemir, Komtera’s Ankara and Anatolian Channel Sales Manager, evaluated the misconceptions of small businesses...
Are small businesses in Türkiye vulnerable to cyberattacks?
Komtera official Serdar Aydemir assessed the state of cybersecurity in small businesses in Turkey under the title, “Are...











