

Updated: May 3, 2026 / 5 min read
Contents
Rate this article
According to Kaspersky Lab, Uzbekistan has become one of the most targeted countries since the beginning of 2023. The reason is simple: the market is growing fast, digitalization is moving quickly, and data protection culture is still lagging behind.
| Threat / Fact | Figure | Source |
|---|---|---|
| Private sector vs government | attacked 3× more often | UZCERT / CCC UZ |
| Cause of attacks: outdated software | 72% of breaches | Cybersecurity Center of Uzbekistan |
| Cause of attacks: weak passwords | 25% of breaches | Cybersecurity Center of Uzbekistan |
| Attack origin — from abroad | 97% of incidents | Cybersecurity Center of Uzbekistan |
| SMBs attacked more than large businesses | nearly 3× more | PTNL.Moscow, 2025 |
| Password compromise — #1 breach vector | 22% of all breaches | InfoSec Research, 2025 |
| Cyberattacks in UZ: damage in 2025 (Tashkent) | ~2 trillion soums | President of Uzbekistan, January 2026 |
Important context: In March 2026, the President of Uzbekistan signed the Cybersecurity Strategy for 2026–2030. From April 1, 2026, government agencies are required to establish cybersecurity departments. Businesses are not yet required to — but businesses bear the majority of the damage.
Wrong. Hackers don't attack by size — they attack by vulnerability. Automated scripts simultaneously scan thousands of websites for common vulnerabilities — and find them at small companies precisely because they don't update or change passwords.
Every business has customer data, access to bank accounts, partner correspondence, and financial documents. This is worth money on the dark market. Moreover, through an infected computer at a small company, hackers can attack its larger partners.
Basic protection — no. Most actions in this article are either free or cost under $10 per month. The expensive and complex story only begins when corporate infrastructure is being built — that's not what we're talking about here.
This is the priority minimum — actions with the highest "protection / time spent" ratio. Start with the first five if you don't have time for everything at once.
| # | What to Do | Specific Action | Cost |
|---|---|---|---|
| 1 | Two-Factor Authentication (2FA) | Enable 2FA on email, Telegram, bank accounts, and all work services. Use Google Authenticator or Telegram. | Free |
| 2 | Strong Unique Passwords | Use a password manager: Bitwarden (free) or 1Password. No "123456", names, or birth dates. | Free / from $3/mo |
| 3 | Software Updates — Always and Immediately | Enable automatic updates on all devices. 72% of breaches happen through vulnerabilities in outdated software. | Free |
| 4 | Backup Using the 3-2-1 Rule | 3 copies of data, 2 different media, 1 offsite (cloud). Google Drive / Yandex.Disk / Dropbox. | From $2/mo |
| 5 | Antivirus With Up-to-Date Databases | For Windows: Microsoft Defender is sufficient. For business: Kaspersky Endpoint Security or ESET. Update weekly. | Free / from $15/yr |
| 6 | Separate Passwords for Employees | No shared passwords "for everyone". Each employee gets their own account. When someone leaves — change access immediately. | Free |
| 7 | HTTPS and Updated Website Engine | Make sure your website runs on HTTPS (padlock in browser). Update your CMS (WordPress, Tilda, etc.) to the latest version. | Free |
| 8 | Employee Phishing Training | Hold a 30-minute meeting: show examples of phishing emails and links. Rule: don't click links in suspicious messages. | Free |
| 9 | Restrict Access by Role | An accountant shouldn't have access to code. A manager shouldn't have access to financial documents. Minimum privileges — minimum risk. | Free |
From April 1, 2026, government agencies in Uzbekistan are required to have cybersecurity departments. Private businesses are not yet required — but:
Even with basic protection, incidents happen. It's important to know what to do in the first few hours — that's what determines the scale of the damage.
The checklist above covers typical risks for a company of up to 20 people without complex IT infrastructure. You need a professional security audit if:
In these cases, you don't need a checklist — you need a full penetration test and architecture audit.
In Uzbekistan in 2025, cyberattacks caused 2 trillion soums in damage to businesses. Detection rate — 8%. Most of these losses could have been prevented with basic measures.
No IT department needed. No big budget needed. Three things are required: enable two-factor authentication, stop using one password for everything, and set up automatic backups. This can be done today — literally in an hour.
Everything else — follow the checklist above. Step by step.
<Get in Touch>
Let us help you achieve top rankings and sustainable growth
