Indonesia's MSMEs form the backbone of the national economy, contributing significantly to employment and economic growth. Millions of small businesses have adopted e-commerce platforms, social media, and digital payment systems to reach broader markets and improve operational efficiency. While digitalization creates new business opportunities, it also expands the attack surface for cybercriminals seeking to exploit organizations with limited security capabilities.
According to the authors, cybercriminals increasingly target MSMEs because they often possess valuable customer and financial data but lack dedicated cybersecurity personnel, sufficient budgets, and comprehensive digital protection systems. Unlike large corporations with specialized IT security teams, many small businesses rely on business owners or general employees to manage digital operations, making them easier targets for cyberattacks.
Reviewing Global Research on MSME Cybersecurity
Instead of conducting field surveys, the researchers analyzed findings from previously published scientific studies using a qualitative literature review approach. Articles were collected from Google Scholar, Portal Garuda, and the Directory of Open Access Journals (DOAJ). Only peer-reviewed studies published between 2021 and 2026 and focusing specifically on MSME cybersecurity, digital threats, or digital literacy were included in the review. The selected studies were then synthesized using content analysis to identify recurring attack patterns, common vulnerabilities, and practical mitigation strategies.
Phishing and Ransomware Dominate the Threat Landscape
The review consistently identified three cyber threats that pose the greatest risk to MSMEs:
- Phishing, where attackers impersonate trusted organizations to steal passwords, banking credentials, or One-Time Passwords (OTPs).
- Ransomware, malicious software that encrypts business data and demands payment before restoring access.
- Account hijacking, often caused by weak passwords or the absence of Two-Factor Authentication (2FA).
Among these threats, phishing emerged as the most successful attack method. Rather than exploiting sophisticated technical vulnerabilities, cybercriminals frequently manipulate human behavior through deceptive emails, text messages, or fake online platforms. Business owners and employees are persuaded to voluntarily reveal sensitive information, making people—not technology—the weakest point in many MSME security systems.
Ransomware was identified as another major concern because many MSMEs lack secure data backup systems. Once business files or digital point-of-sale systems become encrypted, daily operations may stop completely. The researchers note that some business owners feel compelled to pay ransom demands despite having no guarantee that their data will be restored.
Limited Resources Increase Cybersecurity Risks
The review found that financial and human resource limitations remain the primary drivers of cybersecurity vulnerability among MSMEs.
Because many small businesses operate with limited profit margins, investments in licensed antivirus software, firewalls, security audits, or dedicated IT personnel are often postponed. As a result, cybersecurity receives less attention than production, marketing, or business expansion.
The lack of digital security awareness further increases exposure to cyber threats. Common practices identified in the reviewed literature include:
- Reusing identical passwords across multiple accounts.
- Mixing personal and business devices.
- Accessing business systems through unsecured public Wi-Fi.
- Downloading software from unofficial sources.
- Operating without Two-Factor Authentication (2FA).
The researchers emphasize that these everyday habits create opportunities for attackers to gain unauthorized access without requiring advanced hacking techniques.
Cyberattacks Can Damage Businesses Beyond Financial Losses
The consequences of cyber incidents extend well beyond immediate financial costs.
The reviewed studies show that successful cyberattacks can halt business operations, interrupt sales activities, increase recovery expenses, and cause permanent data loss. For micro-businesses that rely on daily transactions, even a short operational disruption may threaten business continuity.
The review also highlights a longer-term consequence that is often underestimated: the loss of customer trust. Data breaches involving customer names, contact information, or transaction histories may severely damage a company's reputation. Rebuilding public confidence can require substantial time, marketing efforts, and financial resources, making reputational damage one of the most expensive outcomes of a cyberattack.
Practical Cybersecurity Can Be Affordable
Rather than recommending enterprise-level security systems, the authors advocate a more practical approach tailored to the realities of MSMEs.
The literature review recommends that small businesses prioritize affordable cybersecurity practices, including:
- Activating Two-Factor Authentication (2FA) on all business accounts.
- Performing routine operating system and software updates.
- Separating personal devices from business devices.
- Maintaining regular offline or isolated data backups.
- Improving digital literacy and cybersecurity awareness among employees.
According to Herwan Triason, Bisyron Wahyudi, and Frado Sibarani of the Indonesian Defense University, cybersecurity for MSMEs should no longer be viewed solely as a technology issue. Their synthesis indicates that sustainable protection depends equally on organizational awareness, employee behavior, and collaboration among business owners, technology providers, and government institutions. They argue that strengthening digital literacy and adopting basic cyber hygiene practices can significantly improve cyber resilience even for businesses with limited financial resources.
The researchers also recommend stronger cooperation between policymakers, cybersecurity practitioners, and digital platform providers to develop simple, affordable, and user-friendly security solutions specifically designed for MSMEs. Expanding national digital literacy programs could further strengthen the resilience of Indonesia's rapidly growing digital economy.
Author Profile
Herwan Triason is a researcher in the Cyber Defense Engineering Study Program, Faculty of Defense Engineering and Technology, Indonesian Defense University, specializing in cybersecurity, cyber defense, and digital risk management.
Bisyron Wahyudi is a lecturer and researcher at the Indonesian Defense University, with expertise in information security, cyber defense engineering, and digital infrastructure protection.
Frado Sibarani is a researcher from the Indonesian Defense University whose academic interests include cybersecurity, digital transformation, and information systems resilience.
Research Source
Article Title: Literature Review: Cybersecurity Threat Trends in Micro, Small, and Medium Enterprises (MSMEs) in the Digital Era
Authors: Herwan Triason, Bisyron Wahyudi, Frado Sibarani
Affiliation: Cyber Defense Engineering Study Program, Faculty of Defense Engineering and Technology, Indonesian Defense University
Journal: International Journal of Sustainable Applied Sciences (IJSAS)
Publication Year: 2026
DOI: https://doi.org/10.59890/ijsas.v4i7.25
Official Journal: http://ijsasjournal.my.id/index.php/ijsas
0 Komentar