24.03.2026
Blog
Cyber Security

Cyber resilience in small and medium-sized enterprises: Why cyber security today determines the future

Cyber resilience in small and medium-sized enterprises is no longer merely an optional IT issue, but a strategic necessity. Whilst large corporations have been investing heavily in their information security for years, small and medium-sized enterprises are increasingly becoming the targets of cybercriminals. Ransomware, phishing, data theft and targeted espionage now affect almost every sector. 

Robert Stricker
Vice President Security Consulting

Key Takeaways

  • Cyberattacks are a key business risk: €289 billion in losses per year → small and medium-sized enterprises are particularly affected
  • Cyber resilience = multi-layered security: IAM, network segmentation, asset visibility and contingency plans must work together
  • The pressure to act is mounting: regulatory requirements (e.g. NIS2) make IT security a clear management responsibility 

289 billion euros in losses: cybercrime as a business risk

The economic impact is significant: according to the latest Bitkom study on economic security, the annual cost of cyberattacks in Germany amounts to around 289 billion euros. The majority of the organisations affected are small and medium-sized enterprises. This figure illustrates that cybercrime is no longer a marginal phenomenon, but a key business risk. At the same time, regulatory requirements such as the NIS 2 Directive are significantly raising the bar for IT security, risk management and reporting processes. For many SMEs, therefore, the question is no longer whether they need to take action – but how strategically and systematically they can build their cyber resilience. 

Understanding cyber resilience: the castle as a security model 

Cyber resilience can be usefully compared to a medieval castle. A castle did not merely have high walls, but featured multiple layers of defence: a drawbridge, a gate, guards, inner courtyards and refuge areas. Even if an attacker managed to breach the outer wall, the heart of the castle remained protected. Applied to a business, this means that IT security does not consist of a single measure such as a firewall or antivirus software. It is an interplay of access control, network structure, monitoring, contingency planning and clearly defined responsibilities. And the castle analogy highlights something else: a castle was designed to withstand an attack. It was intended not only to prevent attacks, but also to remain functional in the event of an emergency. This is precisely what cyber resilience describes – resilience rather than mere defence. 

Identity & Access Management: Who is allowed through the castle gate? 

The castle gate determines who is granted access. In the digital world, this role is fulfilled by Identity & Access Management (IAM). A significant proportion of successful cyberattacks begin with compromised user accounts – in other words, with a ‘stolen key’. In small and medium-sized enterprises, authorisation structures have often evolved over time. Employees change roles or leave the company, yet their access rights sometimes remain in place. Highly privileged accounts pose a particular risk in this regard. Multi-factor authentication, role-based access models and the principle of least privilege ensure that only authorised individuals can access critical systems. Consistent integration into existing processes is crucial here – because even the strongest gate offers no protection if it is left open. 

Network segmentation: inner courtyards instead of an open-plan castle 

In a well-secured castle, not everything was freely accessible. Courtyards, concentric walls and separate areas prevented attackers from spreading unhindered. Modern IT architectures follow the same principle: network segmentation restricts freedom of movement within the infrastructure. If cybercriminals do manage to gain access to the corporate network, the internal structure determines the extent of the damage. The so-called zero-trust principle goes one step further: no device and no user is automatically considered trustworthy – not even within the organisation’s own network. This structured protection is crucial, particularly in small and medium-sized enterprises, where hybrid working models, cloud services and mobile devices are part of everyday life. Transparency and clear governance prevent unsecured ‘back doors’ from emerging. 

IT asset management: knowing what needs protecting 

A castle could only be defended if its vulnerabilities were known. Applied to IT, this means that without complete transparency regarding systems, applications and end devices, no effective security strategy is possible. Undocumented servers, outdated clients or unpatched software act like hidden access points in the walls. Structured IT asset management provides the necessary overview here. Inventory management, patch management and continuous monitoring form the basis for a robust cyber resilience strategy in SMEs. 

Business Continuity Management: The castle’s refuge 

Even the strongest castle had to expect to come under pressure from time to time. That is why there were refuge rooms, storerooms and contingency plans. Applied to businesses, this role is fulfil by Business Continuity Management (BCM). If central systems fail due to an attack or technical fault, preparedness determines the organisation’s ability to act. Clear responsibilities, defined escalation procedures and prioritised recovery plans ensure that business-critical processes are up and running again as quickly as possible. Cyber resilience therefore does not mean absolute security, but rather the ability to overcome disruptions without consequences that threaten the company’s very existence. 

Regulatory requirements under NIS 2 

With the implementation of the NIS 2 Directive, regulatory pressure on many small and medium-sized enterprises is increasing significantly. The Directive obliges affected organisations to introduce structured risk management, to implement technical and organisational security measures, and to establish clear reporting processes. Security incidents must be reported within strict time limits – in Germany, this is usually via the Federal Office for Information Security. IT security thus becomes a clear management responsibility. 

Conclusion: A strong fortress needs more than just high walls 

SMEs form the economic foundation of Germany. At the same time, the annually rising cost of damage caused by cyberattacks shows that digital threats are among the greatest business risks of our time. Cyber resilience in SMEs means building a digital fortress with multiple layers of protection: controlled access, segmented networks, complete transparency regarding assets, and prepared contingency plans. Companies that strategically integrate these layers not only strengthen their IT security – but also their long-term competitiveness. 

Find out how you can further strengthen your cyber resilience in our webcast

Further information on the Materna SME Initiative is available here: SME Initiative 

Robert Stricker
Vice President Security Consulting

Robert Stricker ist Vice President Security Consulting bei Materna.