The New Reality of Cybersecurity for SMEs: Why Resilience Matters More Than Ever

How AI, preparedness and cyber resilience are reshaping the way small and medium-sized enterprises defend against cyber threats. 

Artificial Intelligence is transforming cybersecurity faster than ever before. It is enabling cybercriminals to launch more convincing, more sophisticated and increasingly automated attacks, while simultaneously equipping defenders with powerful new tools for threat detection and incident response. 

Yet, during the latest SOC4SME webinar, Evgenia Tsaprali, Head of the Business Continuity Directorate at Greece’s National Cybersecurity Authority (NCSA), Dimitris Koupatsiaris, Project Manager at CyberSafe, George Andrianopoulos, Security Operations Center Manager at Sphynx, and Vasileios Pergioudakis, Head of Public Bids and Research Programs at Obrela, in a discussion moderated by Stergios Asteriou, Head of Cyber Insurance at Karavias Underwriting Agency, made one thing clear: Artificial Intelligence is only one part of the equation. 

Throughout the discussion, one message became increasingly clear: the future of cybersecurity for small and medium-sized enterprises is not about preventing every cyberattack. It is about becoming resilient enough to anticipate, detect, respond to and recover from them. 

Rather than focusing solely on new technologies or emerging threats, the discussion explored what cybersecurity now demands from SMEs and why resilience is becoming a business capability rather than simply an IT responsibility. 

Artificial Intelligence is changing both sides of the battlefield 

Opening the discussion, Evgenia Tsaprali, Head of the Business Continuity Directorate at Greece’s National Cybersecurity Authority (NCSA), highlighted the growing importance of SMEs in Europe’s economy. Representing 99% of European businesses and employing around 100 million people, SMEs are also becoming increasingly attractive targets for cybercriminals due to limited resources and lower cybersecurity maturity. 

She explained that Artificial Intelligence is reshaping the threat landscape by enabling faster, more sophisticated attacks. Phishing campaigns have become increasingly convincing, while deepfake technology now allows attackers to impersonate trusted colleagues or senior executives with alarming realism. 

As she explained: 

“Should Artificial Intelligence frighten us? The answer is that we should be careful, but it should not frighten us. Artificial Intelligence also gives us powerful tools. We can use it to automate threat detection and we have already seen significant improvements in incident response through AI and machine learning.”  

Tsaprali also stressed that AI must be adopted responsibly. Organisations need clear policies governing its use, employees should avoid sharing sensitive information with AI platforms, and strategic decisions should always remain under human oversight. 

Preparedness requires more than awareness 

The discussion soon shifted from technology to people. 

According to Dimitris Koupatsiaris, Project Manager at CyberSafe, many organisations overestimate their level of preparedness. Raising awareness is important, but awareness alone does not ensure that employees will respond effectively during a cyber incident. As he noted, many business owners confuse cybersecurity awareness with the actual readiness of their staff. They often believe that periodically sharing security guidelines or delivering presentations on topics such as password management is enough to secure their organisation. In reality, these activities are only the first step. 

Instead, he argued: 

“Real preparedness requires clear operating procedures, realistic training scenarios and continuous evaluation of how employees respond to cyber threats. Before organisations can strengthen their resilience, they first need to understand their human baseline and identify where behavioural weaknesses exist.”  

Continuous monitoring in an evolving threat landscape 

Building on the human dimension of cybersecurity, George Andrianopoulos, Security Operations Center Manager at Sphynx, explained how Artificial Intelligence is transforming security operations. 

Modern organisations generate enormous amounts of security data, making manual analysis increasingly impossible. Rather than replacing cybersecurity professionals, AI enables analysts to process information more efficiently, identify suspicious activity and focus their attention on the incidents that matter most. 

However, Andrianopoulos emphasised that technology alone is not enough. Cyber threats evolve continuously, meaning Security Operations Centres must constantly adapt the way they detect and respond to attacks. 

As he explained: 

“A Security Operations Center can no longer rely only on static rules. Detection mechanisms, threat intelligence and response procedures must be updated continuously, learning from new attacks and adapting to emerging threats. Cybersecurity is no longer about being protected today. It is about being prepared for the threats of tomorrow. ”  

For SMEs, maintaining this level of continuous monitoring and adaptation is rarely feasible in-house. Managed Security Operations Centre services provide access to specialised expertise, real-time monitoring and continuously updated threat intelligence, allowing smaller organisations to strengthen their security without maintaining a dedicated SOC of their own. 

The first hours determine the outcome 

Drawing on his experience managing cyber incidents, Vasileios Pergioudakis, Head of Public Bids and Research Programs at Obrela, focused on what happens after an attack begins. 

He explained that many SMEs lack the visibility needed to detect threats early, allowing attackers to remain inside their networks for weeks or even months. Weak passwords, inactive user accounts and the absence of multi-factor authentication continue to create opportunities for compromise. 

Yet, according to Pergioudakis, the greatest challenges often emerge once an incident is underway. Under pressure, organisations may shut down systems too quickly, erase valuable forensic evidence, delay contacting cybersecurity specialists or attempt to manage the situation without expert support. 

Instead, he stressed the importance of following a structured incident response process. Isolating affected systems, preserving evidence, documenting every action and engaging specialised response teams early can significantly improve both recovery and investigation. 

As he concluded: 

“Effective incident response begins long before an incident occurs. A business with even a simple incident response plan and someone monitoring its environment is in a completely different position. The right decisions during the first hours of a cyber incident are not made during those first hours. They have already been made beforehand.” 

Supporting SMEs on their resilience journey 

As the webinar drew to a close, one message united all the speakers: organisations can no longer assume they will prevent every cyberattack. The real challenge is ensuring they can detect, respond to and recover quickly when one occurs. 

For many SMEs, building this level of resilience can be difficult due to limited resources and the lack of dedicated cybersecurity teams. This is where SOC4SME comes in. By providing managed Security Operations Centre (SOC) services, continuous monitoring, incident response support and cybersecurity awareness activities, the project helps SMEs strengthen their cyber resilience without having to build these capabilities internally. 

Ultimately, the webinar made one thing clear: while Artificial Intelligence is reshaping the threat landscape, resilience still depends on people, preparation and the ability to respond effectively when incidents occur. 

Scroll to Top