For many small and medium-sized businesses (SMEs), cybercrime refers to poorly written phishing emails, suspicious links and obvious scams, riddled with spelling mistakes. However, the truth is that modern cybercrime has changed dramatically, increasingly more convincing and nefarious.
A key factor in this development is that artificial intelligence (AI) is rapidly transforming the cyber threat landscape. This enables criminals to launch more targeted and scalable attacks than ever before, with one emerging concern being the risk of ‘deepfakes’. Research has found that ‘deepfake’ content grew by 550% from 2019 to 2023, highlighting the rapid acceleration of AI-generated, fake media.
For SMEs, this shift presents a growing challenge, particularly for those relying on outdated technology or assumptions about what a cyber threat looks like. But, as IT technology becomes more widespread, the gap between cyber risk and traditional SME protections is growing.
Businesses are no longer only defending themselves against opportunistic (and unrealistic) scams. Lately, it’s been increasingly sophisticated attacks designed specifically to exploit human behaviour, trust and publicly available information.
Why SMEs Still Believe ‘It Won’t Happen to Me’
One of the biggest barriers to cyber resistance among SMEs is mindset. For example, many smaller businesses believe they’re unlikely targets, lacking the size, visibility or financial resources, when compared to larger organisations, to be a viable target.
Unfortunately, The Cyber Security Breaches Survey 2025 found that 43% of UK businesses experienced a cyberattack or breach in the 12 months leading up to April 2025. The results additionally revealed that phishing continues to represent one of the most common means of attack.
The insurance ‘blind spot’ is particularly problematic in several areas. A survey of 2,000 UK SMEs revealed that in Newcastle, every SME questioned lacked cover specifically ‘because they were unsure of the correct requirements’. Meanwhile, those in Brighton and the South-East were eight times more likely than the average to say that they ‘wouldn’t know where to start’ when seeking protection for their business.
Capitalising on this knowledge gap, many cybercriminals actually view SMEs as attractive precisely due to their lack of security resources, formal training and weak internal processes. These smaller businesses can additionally act as gateways into larger supply chains, making them valuable entry points for attackers.
As a result, the assumption that cybercrime only affects major corporations has contributed to a dangerous sense of complacency. Simultaneously, many businesses rely on outdated perceptions of what threats look like, further increasing their exposure to risk.
While phishing emails were once historically easy to identify via poor grammar, unusual formatting and generic messaging, AI is rapidly removing these key red flags.
The End of The ‘Obvious Scam’ Era
Large language models (LLMs) and generative AI tools are now capable of producing highly convincing written communications in mere seconds. Notoriously obvious scam emails, once riddled with errors, are now polished, professional and contextually accurate.
Cybercriminals are also increasing the practice of relying on publicly available information from company websites, LinkedIn profiles and social media to personalise attacks. The growing use of publicly available business information has subsequently become a key concern in wider cybersecurity discussions, particularly as AI tools make targeted phishing campaigns both faster and scalable.
The result is a new generation of cyber threats which are incredibly difficult to detect using traditional awareness methods, perpetuated by attackers who craft highly targeted, authentic and trustworthy appearing campaigns. Faced by busy employees working across digital channels, distinguishing between legitimate and malicious communication is extremely difficult.
How AI is Reshaping Cybercrime
Artificial intelligence isn’t just improving phishing attacks – it’s also fundamentally changing the speed, scale and sophistication of cybercrime attacks, with aforementioned deepfakes a major issue.
AI-generated voice cloning and video technology can now imitate individuals with alarming accuracy, creating opportunities for fraud and impersonation. This is most evident in situations where finance teams receive what appears to be a voice message from a senior colleague authorising an urgent payment. They may also be subjected to video calls or audio clips that are impossible to differentiate from their employers’ real voice.
This means that while these technologies are still evolving, the risks they pose are rapidly growing, particularly for businesses that rely heavily on remote communication and fast turnarounds. The increase in automation means that SMEs can no longer hide behind obscurity for protection and that businesses of all sizes are becoming easier to target at scale.
Why Traditional Cyber Training is No Longer Enough
Many cyber awareness programmes still focus heavily on identifying suspicious links or spotting spelling mistakes in phishing emails – meaning they no longer reflect the reality of modern AI threats.
Instead, businesses need to rethink how cyber awareness training is delivered. Rather than focusing on identifying suspicious content, organisations are shifting towards verification-based approaches. This means employees feel empowered to pause, question and verify requests through second channels, before taking appropriate action. This is particularly important when dealing with requests involving payments, sensitive information, or changes to financial details.
Organisations are instead advised to implement layered security practices, including multi-factor authentication, to reduce the risk of any socially engineered attacks.
Cybersecurity is additionally more effective when it moves beyond annual compliance into everyday business culture. This means scenario-based learning, regular refreshers and open conversations are paramount to help employees build stronger instincts and confidence.
Building a Human Firewall
While technology plays a critical role in cyber protection, human behaviour is the most important line of defence. Creating a viable ‘human firewall’ requires businesses to move beyond simple awareness messaging and to develop clear and practical processes, which in turn reduce the likelihood of mistakes.
In addition to multi-factor authentication, restricting access permissions and regularly reviewing user privileges are essential to reduce exposure to unnecessary risk.
Businesses should additionally foster a culture where employees feel comfortable to report concerns, without fear of blame or embarrassment. Cybercriminals often rely on urgency and pressure to bypass critical thinking, so encouraging employees to slow down and question abnormal requests can make a significant difference.
Overall, cyber resilience is ultimately not just about preventing attacks altogether – rather, it is to ensure businesses are adequately prepared to respond when incidents occur.
The Shift Towards Active Risk Management
As cyber threats evolve, businesses are increasingly recognising that cybersecurity cannot sit solely with IT departments. Successful cyber resilience instead relies upon leadership teams, operational processes and employee behaviours.
Another fundamental consideration is that businesses need to consider how prepared they are to respond to a cyber incident in the event of one happening. In 2025 alone, cybercrime cost the UK economy an estimated £14.7 billion, with household names like Marks & Spencers, H&M and the Co-Operative group all impacted. The widespread operation and financial disruption caused should be of concern for any size of business, particularly for those without any clear response strategies in place.
This is why incident response planning, data backup procedures and communication protocols are essential to help reduce disruption and improve recovery times. While no organisation is capable of eliminating cyber risk entirely, those that take a proactive, layered approach are much more likely to be in a stronger position than those relying on outdated assumptions or reactive strategies.
Cyber Threats are Evolving Faster Than Many Businesses Realise
Alarmingly, AI is reshaping cybercrime at a pace that many SMEs are only just beginning to recognise – and are struggling to meet. Attacks are becoming more convincing, personalised and scalable, with traditional warning signs increasingly unreliable.
Businesses are entering a period in which human judgment, internal processes and organisational resilience are just as important as technical security. This means the challenge is no longer about teaching employees to avoid dodgy links, but rather to adapt to an environment in which fraudulent communications appear highly credible, and human judgement is stretched to the limit.
As cyber risks continue to evolve, SMEs need to shift from passive awareness to resolute cyber resilience. Those most equipped to survive will combine strong internal processes, employee education and ongoing risk management, enabling them to survive the next generation of digital threats.