AI is Now Writing the Attacks. Is Your Business Ready?

Organizations can reduce risk with practical security measures to make sure AI cyberattacks don't target them.

Running a small or mid-sized business is hard enough without worrying that the threat landscape just changed underneath you. Most of the business and IT leaders I talk to are already stretched thin managing day-to-day operations, keeping the lights on, and trying to do more with less. Security is important, but it competes with everything else. I get it. I’ve been in this field for a while and I’m not here to add to the pile of things keeping you up at night. But something shifted in 2025 that I think is worth understanding, because it changes the math on some decisions you may have been putting off. Attacks that used to require real skill and real resources are now being automated with AI. And that means the bar to target your organization just got a lot lower.
 
In September 2025, a Chinese state-sponsored group used Claude to autonomously attempt intrusions against roughly thirty organizations. Financial institutions. Tech companies. Government agencies. The AI wasn’t just helping, it was executing the attack with minimal human involvement. Anthropic caught it and published what happened. Around the same time, another group of attackers generated over forty thousand personalized spear-phishing emails targeting US financial institutions. Every one was unique and convincing. That used to take a team of people weeks or months to pull off. Now it’s an afternoon. Then, in early 2026, one threat actor compromised more than six hundred firewalls across fifty-five countries in five weeks. They used AI to automate the exploitation of known vulnerabilities.
Small and medium businesses tend to operate under the assumption that attackers want bigger fish. But automated attacks don’t have a minimum revenue threshold. They scan for vulnerable systems, unpatched software, and weak authentication. And they don’t care whether you have fifty employees or five thousand. You’re running the same firewalls, the same email platforms, and the same cloud services as the enterprise down the street. When a vulnerability exists, it exists for you too. What’s different is that you probably have fewer people watching for it. That’s not a criticism, it’s just the reality of running a lean operation. And it’s exactly what makes smaller organizations attractive targets.
 
The frustrating truth is that most of these attacks succeed because of problems that aren’t new. AI made the attacks faster and cheaper. It didn’t change the entry points. So, what can you do to help stop and respond to these attacks? Here’s a few thoughts to get you started:
 
Enforce MFA everywhere. Not just email, but on your VPN, cloud apps, and critical infrastructure. AI-generated phishing is getting good enough to steal credentials from careful people. But it can’t steal the second factor from their phone. This is the single highest-leverage thing you can do right now.
 
Ensure critical patches are being applied. Those six hundred firewalls weren’t breached through a zero-day. They were breached through known vulnerabilities that had patches available. If you don’t have a formal process for pushing critical patches to internet-facing systems, you’re leaving doors open that attackers have keys to.
 
Educate your users. Phishing today looks better than the phishing from three years ago. Better grammar, better context, and sometimes pulled directly from your company’s own public content. Regular phishing simulations and security awareness training aren’t a compliance checkbox, they’re how you keep your people as a detection layer instead of an entry point.
 
Are you logging anything useful and is anyone actually looking at it? Most tools you’re already paying for can generate alerts. But alerts sitting in a dashboard nobody checks aren’t a security control, they’re a false sense of security. If you don’t have someone dedicated to reviewing them, the logs don’t matter. This is where managed detection and response (MDR) changes the conversation for SMBs. MDR used to be enterprise-only line items. That’s not true anymore. The cost of entry has dropped to the point where most small and mid-sized businesses can get 24/7 threat monitoring, detection, and response coverage for less than you’d expect. You get eyes on your environment around the clock without building a SOC from scratch.
 
Document and test your Disaster Recovery Process. You need to know which systems are critical, how long you can survive without them, and whether your backups will actually restore when it counts. Write it all down and test it before you need it.
One thing I’ve noticed over my career is that big organizations are slow. They have change control processes, approval chains, and legacy systems nobody wants to touch. When a new threat emerges, they can take weeks to months to respond. But small and mid-sized organizations can be nimble. If you decide today that MFA is mandatory for every user by the end of week, you can make that happen. If you want to tighten your patch schedule, you’re not waiting on a change approval committee. That speed is a genuine security advantage and most small businesses don’t use it. The organizations that handle these threats well aren’t the ones with the biggest security budgets. They’re the ones that moved fast when it mattered and had the basics locked down before they needed them.
 
Attackers now have access to AI tools that make them faster, more convincing, and more scalable than ever before. The attacks are real, they’re documented, and they’re hitting organizations that thought they weren’t targets. Your defense doesn’t have to be complicated. It has to be consistent. If you’re not sure where your biggest gaps are, that’s where we start. Reach out to your Keller Schroeder account manager to take action now.
2026 KS Headshots - Day 2-284
Tyler Carlisle
Director of Security Operations

Share:

Join Our Mailing List

More Posts