AI and Cybersecurity for Small Business: What Changed, and What to Do First

AI changed the economics of attacking a company your size, not the playbook. Fluent phishing at volume, cloned voices on payment calls, and a new leak channel opened by your own staff using AI tools. Here is what genuinely changed, what defends against it, and why the answer is rarely another product.

Short answer

AI made attacks cheaper and more fluent rather than fundamentally new. Three things changed for a company of your size: phishing is now well written and personalized at volume, voices can be cloned well enough to authorize a payment over the phone, and your own staff are pasting company data into consumer AI tools nobody sanctioned. The defenses are old and boring — phishing-resistant multi-factor authentication, a callback rule for payment changes, an approved AI tool with written rules, tested backups, and a response plan naming who does what in the first hour. Buy a product only after those exist.

What actually changed, and what did not

The attack techniques used against small companies are largely the same as five years ago: credential theft, invoice fraud, ransomware delivered through a compromised account. What generative tools changed is cost. Producing large volumes of fluent, personalized emails now costs almost nothing, which means targets that were previously not worth the attacker's time are now worth it.

That is the honest framing, and it matters because it points at the right defenses. If the techniques are unchanged, the controls that worked still work — they simply have to actually be in place, rather than on a list. The temptation with an AI-flavored threat is to buy an AI-flavored answer, and at small-business scale that ordering is usually backwards.

Phishing that reads perfectly

Awareness training for the last decade taught people to look for bad grammar, odd formatting, and generic greetings. Those signals are gone. A generated message can reference a real project, mirror a colleague's writing style from public posts, and arrive at a plausible moment.

Which means detection by eye is no longer the control it was. The durable answer is to make the stolen credential worthless: phishing-resistant multi-factor authentication, the kind based on hardware keys or passkeys rather than codes a convincing page can also collect. The distinction between the strong and weak forms is set out formally in NIST Special Publication 800-63B, revision 4, which defines phishing resistance as a property of the authenticator rather than of the user's vigilance — the whole point being that it does not depend on anyone spotting the fake.

  • Move the highest-value accounts first — email, finance, and whatever holds customer data.
  • Retire codes over text messages where you can; they are the form most easily relayed by a convincing fake page.
  • Change what training teaches — from spotting bad English to verifying unexpected requests through a second channel, because that habit survives fluent text.

Cloned voices and the payment call

A short sample of someone's voice — a webinar, a podcast, a voicemail greeting — is enough to produce a convincing imitation. The scenario that costs companies money is narrow and repeatable: an urgent call, a familiar voice, a change of bank details or a transfer that must happen before end of day.

The control is procedural, not technical. Any change to payment details, and any unscheduled transfer above a threshold you set, requires a callback to a number already on file — never a number provided during the call. Write it down, tell suppliers it exists, and apply it when the caller sounds irritated by the delay. The pressure to skip it is the attack.

The same logic extends to video and to messaging apps. Treat urgency plus a channel change as the signal, rather than trying to judge whether a voice sounds real — by the time a person is judging that, the attacker has already won the framing.

The leak your own team opened

The most common new exposure has nothing to do with attackers. It is a member of staff pasting a customer list, a contract, or a support thread into a personal account of a consumer AI tool to get a job done faster. Nothing malicious happened, and yet company data left your systems into an account you cannot audit, revoke, or include in a breach notification.

Banning the category does not work; it just moves the behavior onto phones. What works is providing a sanctioned option and being specific about its rules.

  • Approve one tool, on a business plan whose terms you have read on the point that matters: whether your content is used for training.
  • Write down what may and may not go in — in examples, not categories. "A customer's full invoice, no" is usable guidance; "confidential data, no" is not.
  • Say why, briefly. People follow a rule they understand and route around one they do not.
  • Make the sanctioned path faster than the unsanctioned one, or the rule will lose on convenience.

Securing the AI you deploy yourself

Once you run your own agents and workflows, they become part of the attack surface — and they are unusual in one respect: they read untrusted content and can take actions. That risk is prompt injection — the first entry in the OWASP Top 10 for LLM applications — and how it works, plus what actually mitigates it, is covered in our guide to prompt engineering for business.

  • Grant the minimum tools. An agent that reads inbound mail should not also be able to send payments or delete records.
  • Keep consequential actions behind human approval until the agent has earned wider authority, level by level — the progression is set out in our guide to building agents without code.
  • Log every run — what it saw, what it chose. Without that, an agent misbehaving looks exactly like an agent working.
  • Know what leaves. Which fields reach a third-party model, where they are processed, and whether the contract says they are not trained on. Silence is not a no.

Security and data protection are asked as one question and answered by different rulebooks. Which obligations attach to the data itself, across the EU, the UK and US states, is in AI and data protection.

Where AI genuinely helps the defender

It is not all one-directional. The same capability that writes convincing phishing also reads volumes of log data no small team ever had time to review. Where it helps at this scale is triage: flagging the unusual login, summarizing what happened across systems during an incident, and drafting the policies and response steps most small companies never write because nobody has an afternoon.

What it does not do is replace the fundamentals, and vendors selling detection to a company without multi-factor authentication are selling the roof before the walls.

The order that beats buying a product

For a company of ten to a hundred people, the sequence below prevents more incidents than any added layer, and each step is cheap relative to what it avoids.

  • Phishing-resistant multi-factor authentication on email, finance and admin accounts.
  • Backups you have actually restored from, at least once, on purpose. An untested backup is a belief, not a control.
  • Patching that happens on a schedule rather than when someone remembers.
  • The payment callback rule, written and known by everyone who can move money.
  • An approved AI tool with written rules, so the shadow path has nothing to offer.
  • A one-page response plan naming who decides, who calls the insurer, and who talks to customers.

The first hour, written down in advance

Cost in a security incident is driven less by the sophistication of the attack than by whether anyone knew what to do while it was happening. Contain first: isolate the account or machine. Preserve rather than wipe, because reimaging immediately destroys the evidence you will need for the insurer and the notification. Then escalate to a named decision-maker who can authorize disconnecting things that matter.

Write those three steps on one page, with phone numbers, and store it somewhere reachable when the network is not. The discipline is the same one that makes any deployment survivable — decide before the pressure arrives, which is also the argument running through our AI implementation checklist.

Frequently asked questions

Has AI made attacks on small businesses worse?

It has mostly made them cheaper and better written. The phishing email with clumsy grammar that staff were trained to spot is gone; generated messages are fluent, personalized from public information, and produced at volume. The techniques are not new — the cost of running them at scale against small targets has collapsed, which changes who gets targeted rather than how.

What is the single most effective defense against AI-generated phishing?

Removing the value of the credential rather than trying to spot the message. Phishing-resistant multi-factor authentication means a convincing email that harvests a password still gets the attacker nothing. Training people to detect fakes is a losing race against generated text; making the stolen thing useless is not.

Are voice deepfakes a realistic threat to a company our size?

Yes, and specifically against payment instructions. A short sample of a public voice is enough to produce a convincing call, and the classic scenario is an urgent transfer request that sounds like a director. The defense is procedural rather than technical: a callback rule on a known number for any payment change, applied without exception including when the caller is annoyed by it.

Does using AI tools create new security exposure?

It creates one significant new class: data that leaves your systems in ways nobody recorded. Staff pasting customer information into personal accounts of consumer AI tools is the most common version, and it usually happens because no sanctioned tool exists. The fix is providing an approved option and writing down what may be pasted into it, not banning the category and hoping.

Should we buy an AI security product?

Only after the basics are in place, because most AI security products assume them. Multi-factor authentication, patched systems, tested backups and a written response plan prevent more incidents at a small-business scale than any detection layer added on top. An AI-powered tool bought instead of those fundamentals is an expensive way to watch an avoidable breach happen.

What should we do first if we think an incident has started?

Contain before you investigate: isolate the affected account or machine, preserve the logs rather than wiping and reimaging immediately, and get to a decision-maker fast. A written plan naming who does what in the first hour is what most consistently separates a contained incident from an expensive one — decide that before an attack forces the decision under pressure.

If you are deploying AI internally and want the data path and the agent permissions decided before anything reaches production, that is part of every build we run. Book a call.

LYVIA

LYVIA Team

AI automation and SEO/GEO visibility

LYVIA builds custom AI tools for companies of 10 to 100 people, and gets them found on Google and inside AI answers.

Free offer

Get your free AI audit
in 30 minutes

A LYVIA expert reviews your workflows, pinpoints the 3 highest-ROI AI opportunities, and hands you a concrete roadmap. No commitment, no jargon.

  • Full diagnostic of your business processes
  • Automatable quick wins, identified
  • A personalized roadmap you keep
Book my free audit

30 min · Free · No commitment