Why the AI cyber threat will hit small business the hardest
Small businesses carry the least security resourcing — and face the fastest-moving AI threat.
First published by In AI Today. Republished with permission.
This week the cyber security agencies of the Five Eyes alliance, Australia among them, did something they rarely do. They issued a joint, public warning that **Artificial Intelligence (AI)** is transforming cyber risk, and that the danger is arriving fast. Their language was unusually blunt. The timeline, they wrote, ‘is not years, it is months’.
This was not the usual advisory. For months the conversation in AI has been about how powerful the frontier models have become. Anthropic’s Mythos was talked about as so capable that it posed a security risk in its own right, which is why the company quietly gave banks and governments early access, so they could use it to harden their defences before anyone else got hold of it.
What changed is that the open models have caught up. GLM5.2, built by a Chinese developer, has now beaten Anthropic’s own Opus 4.8 on some benchmarks, and it costs a fraction of the price. This is not a one-off. Across the field the gap between the best open models and the best closed ones narrowed from 8 per cent to 1.7 per cent in the space of a year. When capability like that becomes open and cheap, it does not only reach the defenders. It reaches anyone with a laptop and bad intentions. That, I suspect, is what has the agencies so worried. The tools to attack at scale are now in everyone’s hands.
The statement was addressed to business leaders. But the businesses least able to answer the call are the smaller ones, and they make up 98 per cent of Australian businesses. When we picture a small business we tend to think of the local cafe. The reality is broader and far more sensitive than that. Small businesses are the medical clinics holding our health records. They are the brokers, accountants and financial advisers holding our financial lives. They handle some of the most private information in the country, very often with the least protection around it.
Large corporations, governments and institutions can respond to a warning like this. They have the budgets to stand up security teams, engage consultants and put AI engineers on the problem. A small business has none of that. It is already around three times more likely to be targeted than a large company, and a single incident costs a small business roughly $46,000 on average, according to the Australian Cyber Security Centre. For many, that is the difference between trading on and closing the doors.
From our work with SMEs, the picture on the ground is sobering. There are switched-on operators who take security seriously, but they are the minority. Most are out of their depth, and fewer than half have any kind of security plan at all. The harder problem is willingness. More than half of small business owners say cyber security is simply too expensive, so the risk goes unmanaged rather than addressed. The result is a sector that is both heavily targeted and lightly defended.
The AI industry has not helped. Much of the marketing has told business owners that AI now writes the code, and that manual programmers are a thing of the past. Plenty of SMEs have taken the hint and started building their own apps, a practice now known as ‘vibe coding’. Our experience, and the data, tell a different story. A recent study by the security firm Veracode found that 45 per cent of AI-generated code contained security vulnerabilities, and that the newer, larger models were no better. In other words, the very businesses being encouraged to build their own software are quietly building their own weaknesses.
Put it together and small business is caught in a pincer. They are the most attractive target for bad actors now armed with cheap, advanced AI, and they are the least equipped to defend themselves, whether in money, knowledge or simple willingness to act. The Five Eyes leaders are right that this can no longer be treated as a technical issue for someone in IT to handle. For most small businesses there is no one in IT. It is a business risk, and it lands squarely on the owner.
The encouraging part of the agencies’ message is that part of the answer is to address security with straightforward measures. It is to get the basics right, such as strong passwords and multi-factor authentication, regular updates, reliable backups, tight access controls and a simple plan for when something goes wrong will stop the large majority of attacks.
None of that requires a frontier model or a six-figure budget. What it does require is for owners to treat this as the priority it has now become, and to get independent help where they need it. In my work with SMEs through SMEC AI, the federally funded adoption centre I lead, the question of using AI safely is moving to the centre of the conversation.
Time is running out for SMEs to address cybersecurity. The tools to attack are now cheap and everywhere. The will to defend can no longer be a luxury that only big business can afford.