Cyberattacks Don’t Discriminate: Mastercard Explains Why Businesses Must Rethink Cybersecurity

Cyberattacks Don’t Discriminate: Why Businesses Must Rethink Cybersecurity

Just a few years ago, many business owners believed that cybercriminals primarily targeted large corporations. However, a recent Mastercard study reveals that the threat now impacts companies of all sizes. Differences in security levels stem not only from technology availability but, more importantly, from an organization’s maturity: regular risk assessment, well-prepared procedures, employee training, and the ability to react swiftly to incidents.

The study indicates that many companies are still unprepared for the evolving landscape of cyberattacks.

Cybercriminals No Longer Target Only Corporations

Cybersecurity has moved beyond being solely an IT department task. Today, it’s an integral part of business risk management, directly linked to operational continuity, reputation protection, and customer trust. Ransomware attacks, data extortion, phishing, and attempts to gain unauthorized system access are daily realities faced by businesses worldwide.

The findings from a Mastercard-commissioned study, involving 300 cybersecurity professionals across small, medium, and large enterprises, illustrate more than just the increasing scale of threats. It clearly shows that as organizations grow, so does their awareness of risk. Conversely, small businesses often still perceive cybersecurity as a secondary concern. For cybercriminals, vulnerabilities are paramount: weak procedures, insufficient safeguards, lack of monitoring, and low employee awareness are prime targets.

Awareness is Growing, But Not Universally

When asked about the most vulnerable assets, respondents from small businesses most frequently pointed to customer data and the company’s financial data. In medium and large organizations, the perspective shifts. Internal IT systems—servers, network infrastructure, or systems supporting critical business processes—take precedence.

This difference is not accidental. The larger the organization, the more extensive its IT environment, the greater the number of users, and the more attack vectors cybercriminals can exploit. Simultaneously, larger enterprises better understand that a successful attack doesn’t necessarily mean just a data breach. Equally devastating can be a halt in production, paralysis of sales systems, or loss of access to critical infrastructure.

A similar correlation is observed in risk assessment. Among small businesses, the prevailing belief was that the probability of a cyberattack is medium or low. In large organizations, assessments were significantly more cautious—almost one in five companies considered the risk high. This indicates that as business scale increases, so does the awareness of the consequences even a single security incident can trigger.

The Human Element Remains the Most Common Target

Data concerning the attacks themselves also provides interesting insights. Approximately a quarter of small businesses report having been victims of a cyberattack at least once. For large enterprises, this percentage rises to half of the surveyed organizations.

Simultaneously, an analysis of incident types shows that cybercriminals most often exploit the weakest link in security systems: the human element. Attacks predominantly use email and SMS messages designed to leverage social engineering to manipulate employees—coaxing them into revealing access credentials, downloading and opening infected files, and similar actions. This highlights the critical need for robust employee training and awareness, especially concerning sophisticated tactics like those that can be seen in the context of viral AI personality prompts and data privacy concerns.

This is a crucial signal for business owners. Even the most advanced technical safeguards won’t eliminate risk if employees cannot recognize an attempted data phishing scam or don’t know how to react to suspicious messages.

The training statistics confirm this. Sixty-four percent of large companies train their employees at least once a year. In small businesses, the situation is much worse—over half report conducting no such training at all.

Reactivity Versus Building Resilience

The study indicates that many companies still operate primarily reactively. After detecting an attack, they most often implement additional safeguards, change passwords, or seek support from external experts. Less frequently do they treat an incident as an impetus for lasting improvement: analyzing causes, updating procedures, testing response plans, and better preparing teams.

This element appears to be one of the biggest challenges for businesses. Cybersecurity is still often treated as a collection of IT tools, whereas in practice, it is a comprehensive process encompassing people, procedures, technology, and risk management.

Cyber Resilience Doesn’t Start with Another Tool Purchase

The study results show that as enterprise size increases, so do investments in cybersecurity. For small businesses, expenses typically do not exceed 10,000 currency units annually; medium-sized enterprises usually invest 10,000 to 50,000 currency units; while large organizations allocate significantly larger budgets for this purpose. However, the sheer scale of expenditure alone does not guarantee security.

What proves far more important is how an organization manages risk. Large enterprises more frequently conduct regular audits, possess formal security policies, perform employee training, and test the organization’s readiness to respond to incidents. This means that even if they are more often targets of cyberattacks than smaller entities, they are also better prepared for their rapid detection and mitigation of consequences. When considering the effectiveness of security solutions, it’s vital to evaluate whether Microsoft Defender is enough protection or if a more comprehensive, layered approach is necessary.

In small businesses, cybersecurity responsibility often falls to the owner or an employee who handles this area alongside other duties. This complicates systematic threat monitoring, risk assessment, procedure updates, and regular security testing. Meanwhile, smaller organizations are increasingly becoming attractive targets for cybercriminals—they possess valuable data but generally have less extensive protection mechanisms.

From Reaction to Resilience: Mastercard’s Recommendations

One of the most interesting conclusions from the study is that companies still more often react to incidents than prepare for them. This approach might have been sufficient a few years ago when cyber threats were smaller in scale and less complex. Today, however, the concept of cyber resilience—an organization’s ability not only to prevent attacks but also to maintain operational continuity and quickly return to normal functioning after an incident—is gaining increasing importance.

Building such resilience requires much more than implementing antivirus software or a firewall. It demands regular risk assessments, testing security under conditions resembling actual cybercriminal activities, vulnerability analysis, and preparing teams to make decisions under time pressure.

It is with this approach in mind that Mastercard is developing a portfolio of services to support organizations at various stages of building cyber resilience. The solutions are tailored to the needs of businesses of different sizes and address specific challenges identified in the study:

  • Threat Protection: A cloud-based solution supporting the protection of web applications and digital services against DDoS attacks, bot activity, and malicious network traffic. This reduces the risk of online service unavailability, which for businesses relying on digital channels for sales, customer service, or operational processes can quickly translate into financial losses, operational disruptions, and loss of customer trust.
  • Cyber Quant: Allows organizations to assess their cybersecurity maturity, estimate financial cyber risk, and prioritize actions that can yield the greatest risk reduction relative to expenditures.
  • Cyber Front: Enables the simulation of real attack techniques in a controlled manner, without impacting the production environment. This allows organizations to verify whether existing security mechanisms can detect, block, or handle a given attack technique and where remedial actions are required.
  • Cyber Crisis Exercise: These exercises aim to test how teams make decisions, communicate, and coordinate actions under time pressure, incomplete information, and a rapidly evolving incident. During simulated incidents, teams test information flow, decision-making roles, escalation procedures, and readiness to act under pressure. This preparation often determines whether an incident remains a controlled operational problem or escalates into a crisis affecting the entire organization.
  • RiskRecon: Increasingly important is the security of business partners. Modern enterprises operate within extensive ecosystems of suppliers, integrators, and subcontractors. Even a well-secured organization can be attacked through a less-protected partner. Solutions like RiskRecon support continuous monitoring of the external cybersecurity posture of suppliers, partners, and other third parties. This allows for early identification of weak points in an organization’s digital ecosystem and prioritization of actions where business risk is highest.

Cybersecurity as a Business Strategy Component

A few years ago, investments in cybersecurity were often viewed as a cost difficult to link to a company’s financial results. Today, it is increasingly clear that digital security is becoming a prerequisite for maintaining operational continuity, protecting reputation, and building customer trust.

The Mastercard study shows that businesses are at different stages of this journey. Large organizations increasingly treat cybersecurity as a comprehensive process encompassing technology, people, and risk management. Smaller companies are just beginning to build this awareness, yet they are often the ones who can most severely feel the impact of even a single incident.

The most important universal conclusion from the study is that cyber resilience depends not solely on budget size or organizational scale, but on consistent risk management—from employee awareness and robust procedures to security testing and readiness to act in a crisis situation.

Frequently Asked Questions (FAQ)

Why are small businesses increasingly targeted by cybercriminals?

While larger organizations might have more data, small businesses often possess valuable data while lacking sophisticated security measures and dedicated cybersecurity personnel. This makes them attractive and easier targets for cybercriminals seeking financial gain or entry points into larger supply chains.

What is “cyber resilience” and how does it differ from traditional cybersecurity?

Cyber resilience is an organization’s ability to not only prevent cyberattacks but also to maintain critical operations during an attack and recover quickly and effectively afterward. Traditional cybersecurity often focuses primarily on prevention and detection, whereas cyber resilience emphasizes an end-to-end approach that includes rapid response, recovery, and adaptation to evolving threats.

Beyond technology, what are the key components of a strong cybersecurity strategy?

A robust cybersecurity strategy goes beyond just tools and technology. It critically involves the “people” and “process” elements. This includes regular employee training on security best practices and social engineering, comprehensive risk assessments, documented incident response plans, and ongoing evaluation and updates of security procedures. Organizational maturity in these areas significantly enhances overall cyber resilience.

How can businesses effectively monitor the cybersecurity posture of their third-party partners and suppliers?

Many modern businesses rely on extensive networks of suppliers and partners, and a vulnerability in any one of them can expose the entire ecosystem. Tools like Mastercard’s RiskRecon offer continuous monitoring of the external cybersecurity posture of third parties, identifying weak points and allowing organizations to prioritize actions where the business risk is highest. This proactive approach helps secure the broader digital supply chain.

Source: Original analysis. Opening photo: Gemini

About Post Author