Malaysian non-IT SMEs that are subject to cyberattacks are still vulnerable and lack a strong cybersecurity infrastructure. This study explores the cybersecurity barriers among Malaysian non-IT SMEs, assesses their organizational cybersecurity readiness, and provides insights for strengthening their cybersecurity readiness posture. It uses a qualitative approach to examine the barriers to cybersecurity readiness of Malaysian non-IT SMEs and identifies the factors impacting it. Data were gathered by adopting purposive sampling, using self-administered, open-ended questionnaires, and thematic analysis was performed to find themes and produce insights about organizational, infrastructural, and human factors influencing cybersecurity readiness. The findings identified that the main obstacles Malaysian SMEs face include security exposure due to infrastructure and knowledge gaps, awareness and policy gaps, limited preventative measures and recovery plans, financial restrictions, and inadequate cybersecurity awareness and strategic oversight. The actionable guidelines include government initiatives for SMEs, outsourced security solutions, security assessment, and cybersecurity skill development; these are some practical recommendations. Overall, by highlighting the significance of organizational perception among Malaysian non-IT SMEs, this study adds to the body of literature on cybersecurity readiness. It also offers practical recommendations for SME owners, policymakers, and non-technical staff to identify cybersecurity-related vulnerabilities and implement efficient cybersecurity measures.

