AI Has Made Cybercrime a Growth Industry. Here’s What Your Business Should Do About It.

Aug 10, 2026
By Kevin Gilleard · 5 min read
Featured image for “AI Has Made Cybercrime a Growth Industry. Here’s What Your Business Should Do About It.”

We recently sat in on a webinar run by a major cyber insurer and their incident-response partner about AI and security risk. When the people who pay out breach claims start hosting seminars about a threat, that is not marketing. That is actuaries getting nervous. Here is what business owners actually need to take from it, translated out of security-speak, with our advice on what to do.

The uncomfortable premise: AI helps attackers at least as much as it helps you

Every efficiency you have gained from AI in the last two years, attackers have gained too. Phishing campaigns that once needed a team now need one person supervising an AI that does the reconnaissance, writes the lures, and works around the clock. Security researchers report intrusions progressing from first foothold to serious damage in under an hour. And when a new software vulnerability is disclosed, the gap between the announcement and working attacks has collapsed from weeks to days, sometimes hours.

That last point deserves to change your behaviour immediately. “We patch monthly” was a defensible policy in 2020. It is not one now. This is exactly why our hosting platform patches continuously and runs always-on malware defence rather than waiting for a maintenance window.

The scams got personal

Forget misspelled emails from fake princes. Modern AI-assisted phishing reads like it was written by someone who knows your industry, your vendors and your org chart, because in a sense it was: attackers feed public information about your company into a model and get flawless, personalised lures in any language. Voice cloning and deepfake video have already been used to impersonate executives and authorise transfers. There are literally subscription kits that package all of this for people with no technical skill.

The defence is procedural, not technical, and it is free: no request involving money, credentials or sensitive data gets actioned on the strength of a message alone. Verify on a second channel you already trust — call the known number, walk down the hall. Make that a written rule, tell the whole team, and make it socially safe to “slow down” even when the request looks like it came from the boss.

If you get breached, your files will actually get read now

Something genuinely new: ransomware crews used to steal data faster than they could examine it. Now they run stolen files through language models that instantly surface the most damaging material — contracts, HR complaints, financials, anything that maximises extortion pressure. Some groups even run AI chatbots to negotiate with victims at scale.

The practical lesson is about what you keep. Every old file on your server is a liability with no expiry date. Decide what you genuinely need, archive it somewhere cold, and delete the rest. Data you no longer hold cannot be weaponised against you.

Your own AI tools are now part of your attack surface

This is the section most owners have not thought about at all. Three things to watch:

  • Shadow AI. Staff are pasting company data into free AI tools you have never approved, and software you already own keeps switching AI features on by default. You cannot secure what you do not know is happening.
  • Over-permissioned assistants. An AI chatbot or agent wired into your systems typically gets broad access, and it can be manipulated. Malicious instructions can be hidden in content the AI reads — an email, a web page, a document — and a helpful assistant with access to everything becomes a very efficient data-leak machine. Give AI tools the same least-privilege treatment you would give a new hire, and remember its chat logs are themselves a trove of sensitive data.
  • Stolen AI credentials. Attackers now steal API keys and quietly run their own workloads on your account. If you use AI APIs, set spending caps and alerts — the first symptom is usually a shocking bill.

And if your developers lean on AI to write code: AI models sometimes invent package names that do not exist, and attackers register those names with malicious code so the next person to install one gets owned. AI-written code ships to production only after a human who understands it has reviewed it — a rule we hold ourselves to, hard, in our own development work.

What a small business should actually do

You do not need an enterprise security programme. You need a short list, done properly:

  • Write a one-page AI policy: which tools are approved, what data may never be pasted into them, who approves new ones.
  • Inventory where AI is already in use — including features that switched themselves on inside software you already own.
  • Verification rule for money, credentials and data requests: always a second, known channel.
  • Patch fast — days, not months — or host somewhere that does it for you.
  • Least privilege for AI assistants and agents; cap and monitor AI API spending.
  • Delete data you no longer need; back up what you keep, and test the restore.
  • Human review for AI-generated code before it ships.
  • Check your cyber insurance: coverage, exclusions, and what the policy requires of you — insurers increasingly expect exactly the basics above.

The same lesson as always, with higher stakes

None of this is a reason to avoid AI — we use it daily and wrote recently about how it has made owning your own tech stack more practical than ever. The through-line is the same: AI does the labour, but somebody accountable has to do the judgment. Attackers have fully embraced the labour half. The businesses that stay out of trouble will be the ones with an adult in the room on the judgment half.

If nobody at your company owns that job, that is fixable for a lot less than an incident costs. We will review your stack, your exposure and your AI use, and give you the short list that actually matters. Book a 15-minute call


Share: