Top Banner BackgroundTop Banner Background

Updated: May 3, 2026 / 5 min read

Cybersecurity for Small Business: The Minimum You Need to Do Today

In 2025, over 16,000 digital crimes were registered in Tashkent alone — with total damages of around 2 trillion soums. Detection rate: 8%. Small business is the primary target.
avatar
Muin Gulov
Project Manager

Contents

  1. Why Small Businesses in Uzbekistan Are in the Crosshairs
  2. Three Reasons Small Businesses Ignore Security
  3. Checklist: 9 Steps That Cover 80% of Risks
  4. What Changed in Legislation: April 2026
  5. If You Get Hacked Anyway: Action Plan
  6. When the Basic Minimum Isn't Enough
  7. Conclusion

Rate this article

Why Small Businesses in Uzbekistan Are in the Crosshairs

According to Kaspersky Lab, Uzbekistan has become one of the most targeted countries since the beginning of 2023. The reason is simple: the market is growing fast, digitalization is moving quickly, and data protection culture is still lagging behind.

Threat / FactFigureSource
Private sector vs governmentattacked 3× more oftenUZCERT / CCC UZ
Cause of attacks: outdated software72% of breachesCybersecurity Center of Uzbekistan
Cause of attacks: weak passwords25% of breachesCybersecurity Center of Uzbekistan
Attack origin — from abroad97% of incidentsCybersecurity Center of Uzbekistan
SMBs attacked more than large businessesnearly 3× morePTNL.Moscow, 2025
Password compromise — #1 breach vector22% of all breachesInfoSec Research, 2025
Cyberattacks in UZ: damage in 2025 (Tashkent)~2 trillion soumsPresident of Uzbekistan, January 2026

Important context: In March 2026, the President of Uzbekistan signed the Cybersecurity Strategy for 2026–2030. From April 1, 2026, government agencies are required to establish cybersecurity departments. Businesses are not yet required to — but businesses bear the majority of the damage.



Three Reasons Small Businesses Ignore Security

"We're too small to be attacked"

Wrong. Hackers don't attack by size — they attack by vulnerability. Automated scripts simultaneously scan thousands of websites for common vulnerabilities — and find them at small companies precisely because they don't update or change passwords.

"We have nothing worth stealing"

Every business has customer data, access to bank accounts, partner correspondence, and financial documents. This is worth money on the dark market. Moreover, through an infected computer at a small company, hackers can attack its larger partners.

"It's expensive and complicated"

Basic protection — no. Most actions in this article are either free or cost under $10 per month. The expensive and complex story only begins when corporate infrastructure is being built — that's not what we're talking about here.




Checklist: 9 Steps That Cover 80% of Risks

This is the priority minimum — actions with the highest "protection / time spent" ratio. Start with the first five if you don't have time for everything at once.

#What to DoSpecific ActionCost
1Two-Factor Authentication (2FA)Enable 2FA on email, Telegram, bank accounts, and all work services. Use Google Authenticator or Telegram.Free
2Strong Unique PasswordsUse a password manager: Bitwarden (free) or 1Password. No "123456", names, or birth dates.Free / from $3/mo
3Software Updates — Always and ImmediatelyEnable automatic updates on all devices. 72% of breaches happen through vulnerabilities in outdated software.Free
4Backup Using the 3-2-1 Rule3 copies of data, 2 different media, 1 offsite (cloud). Google Drive / Yandex.Disk / Dropbox.From $2/mo
5Antivirus With Up-to-Date DatabasesFor Windows: Microsoft Defender is sufficient. For business: Kaspersky Endpoint Security or ESET. Update weekly.Free / from $15/yr
6Separate Passwords for EmployeesNo shared passwords "for everyone". Each employee gets their own account. When someone leaves — change access immediately.Free
7HTTPS and Updated Website EngineMake sure your website runs on HTTPS (padlock in browser). Update your CMS (WordPress, Tilda, etc.) to the latest version.Free
8Employee Phishing TrainingHold a 30-minute meeting: show examples of phishing emails and links. Rule: don't click links in suspicious messages.Free
9Restrict Access by RoleAn accountant shouldn't have access to code. A manager shouldn't have access to financial documents. Minimum privileges — minimum risk.Free


What Changed in Legislation: April 2026



From April 1, 2026, government agencies in Uzbekistan are required to have cybersecurity departments. Private businesses are not yet required — but:

  • If your business handles personal customer data — you are responsible for its safety
  • If you work with government agencies as a contractor — cybersecurity requirements for you will tighten
  • The Cybersecurity Strategy 2026–2030 plans to extend requirements to critical information infrastructure entities — including fintech, telecom, healthcare, and retail

If You Get Hacked Anyway: Action Plan

Even with basic protection, incidents happen. It's important to know what to do in the first few hours — that's what determines the scale of the damage.

  1. Isolate the infected device — disconnect from the network, do not turn off (data may be needed for investigation)
  2. Change passwords — from a clean device, starting with email and bank accounts
  3. Notify your bank — if financial data was on the compromised device
  4. Restore from backup — this is exactly why backup is item #4 on the checklist
  5. Contact the Cybersecurity Center of Uzbekistan — UZCERT accepts incident reports
  6. Analyze the cause — weak password? Clicked a link? Outdated plugin? Eliminate the entry point

When the Basic Minimum Isn't Enough

The checklist above covers typical risks for a company of up to 20 people without complex IT infrastructure. You need a professional security audit if:

  • You store personal client data — passport details, medical records, financial information
  • You have a corporate server or your own database
  • Your product is an IT system: an app, web service, or SaaS
  • You integrate with banks or payment systems (Click, Payme, Humo)
  • You work with government agencies as a contractor or data provider

In these cases, you don't need a checklist — you need a full penetration test and architecture audit.


Conclusion

In Uzbekistan in 2025, cyberattacks caused 2 trillion soums in damage to businesses. Detection rate — 8%. Most of these losses could have been prevented with basic measures.

No IT department needed. No big budget needed. Three things are required: enable two-factor authentication, stop using one password for everything, and set up automatic backups. This can be done today — literally in an hour.

Everything else — follow the checklist above. Step by step.

<Get in Touch>

Let’s Build the Next Big Thing in EdTech

Let us help you achieve top rankings and sustainable growth

Contacts
GetInTouchImage