SMB Cyber ​​Readiness: Getting the Basics Right

AI Basics


AI is changing cybercrime, but small businesses’ cyber readiness still relies heavily on filling common gaps.

SMB Cyber ​​Readiness: Getting the Basics Right

AI is changing attackers’ toolkits. This can help criminals create better decoys, scale social engineering, and speed up reconnaissance, while lowering the barrier to entry for less skilled attackers. It makes sense for organizations to take note. Especially as the malicious use of AI turns old gaps into a more urgent test of an organization’s cyber readiness.

The first point of failure, on the other hand, is very familiar and usually involves the usual suspects, such as a phishing link that an employee clicked or a vulnerability that wasn’t patched in time. Unlike true AI-powered malware (which remains rare), these are not the flashiest risks in cybersecurity, but they remain one of the most important for businesses looking to improve their responsiveness.

Fortunately, the threats that still cause the majority of incidents also have proven mitigations that can help keep your business safe.

AI and its basics

According to the ESET SMB Cyber ​​Readiness Index 2026, ‘AI-powered malware’ is cited as the top concern for global small and medium-sized businesses in the year ahead. It’s even higher in North America (33%). However, if we adopt the definition to mean malware that uses AI in an automated, real-time manner, this becomes a topic for the research community more than cybersecurity experts.

ESET discovered the first example of AI-written ransomware in 2025. But even this may have been a proof of concept (PoC). Meanwhile, PromptSpy, discovered by ESET earlier this year, was the first known Android malware to exploit generative AI (GenAI) in its execution flow to achieve persistence.

There are relatively few, if any, similar findings by threat researchers. It is also true that ESET’s MDR service has no evidence of incidents in which GenAI played a significant role. Threat actors are benefiting from AI support, but few are operating the technology in real time for truly automated tasks.

The real cyber threat to your business

A more useful approach for small business leaders is to pay more attention to the real causes of incidents. For many SMBs, the first point of failure remains familiar. It could be a phishing message that works, a vulnerability that goes unpatched, an alert that no one sees, or a password that should never be reused. While these are not the flashiest risks in cybersecurity, they are still among the most important for businesses looking to improve their responsiveness.

For this purpose, ESET data is useful. The following have been identified as the biggest threats facing small and medium-sized businesses:

  • Phishing (26%): According to ESET Telemetry, the top threat detected in the second half of 2025 is phishing (30.8%), and the volume continues to increase. Social engineering has always been a favorite tactic of threat actors, and phishing texts (smishing) and voice calls (vishing) are also growing in popularity. Technology can play a role in protection, but it also requires staff training and awareness, which can be difficult to get right.
  • Unpatched security vulnerabilities (23%): Even small organizations may be running a variety of software, and simply turning on automatic updates may not be enough to patch all software. The first challenge is understanding what you are doing and what sensitive data and systems may be exposed. The sheer volume and frequency of recent vulnerability discoveries, as well as limited expertise in testing and applying critical updates, can also be obstacles.
  • Lack of security oversight (22%): You may have many security tools, but is there one central location to collect, correlate, and flag alerts? Effective monitoring is critical to speeding threat detection and response. But even companies with monitoring in place can be bombarded with alerts, making it difficult to distinguish between false positives and true positives.
  • Weak password (20%): An age-old security challenge. Although the industry is moving towards phishing-resistant multi-factor authentication (MFA) and passkeys, many organizations still rely on static passwords to protect their core assets. Employees also tend to reuse them, further increasing the risk of a breach. Creating a robust password policy is the first step. Enforcing it is next.
email threats-h1-h2-2025
Malicious email detection trends in 2025 (Source: ESET Threat Report H2 2025)

Proven solutions to age-old threats

This is not to say that small businesses should ignore the threat posed by AI. It is important to recognize that many of the risks listed above are being exacerbated by AI rather than the technology being used to create entirely new threats. For example, attackers are using AI to:

  • Improve the quality of phishing messages (including the use of deepfakes) and scale and manage campaigns
  • Collapse the window of exploitation by rapidly discovering and weaponizing new flaws.
  • Analyze large datasets to discover commonly used passwords
  • Perform target reconnaissance to uncover attack vectors faster.

It could also reduce the amount of time companies have to respond. If cybercriminals can identify vulnerable systems faster, write exploit code more easily, and automate parts of their workflows, the window between disclosure, weaponization, and exploitation could narrow even further. That’s important for SMBs that already struggle with asset inventory and patch prioritization. One lesson is that this increases the cost of leaving the basics unfinished.

So what’s the answer? Fortunately, best practices can still help improve your security posture. Vulnerability and patch management is a good place to start. Continuously scan operating systems and applications for known CVEs that have surfaced and automatically deploy updates according to policy and risk.

Identity security is becoming increasingly important. Password managers can create and store strong, unique credentials for their employees, but MFA is still a non-negotiable line of defense today. Use privileged account management (PAM) tools to reduce your attack surface and protect high-risk accounts.

Address security skills shortages and strengthen monitoring by outsourcing detection and response to trusted third parties. Managed detection and response (MDR) services can also reduce the complexity and integration challenges that one-fifth (21%) of SMBs cite as the top barrier to improving their security posture.

Destination: Preparedness and Resilience

The bottom line is that no organization is too small to be immune from attack, so a proactive approach to cybersecurity is essential. True cyber readiness means being able to prevent, detect, and respond to threats. This is an important milestone on the journey to business resilience.

Having a clear understanding of the threats your organization faces will help you reach your goals faster. It’s not what makes a good story, it’s what has real impact.



Source link