Cyber readiness for SMBs: Getting the basics right
Cybersecurity Classified by Officially
AI is changing attackers’ toolkits. It can help criminals write better lures, scale social engineering and speed up reconnaissance, all while generally lowering the barrier to entry for less skilled attackers. Organizations are right to pay attention, especially because malicious use of AI makes old gaps a more urgent test of an organization’s cyber readiness.
Meanwhile, the first points of failure remain strikingly familiar and typically involve the usual suspects, such as a phishing link that an employee clicks on or a vulnerability that isn’t patched in time. Unlike truly AI-powered malware (which remains a rare sight), these are not the flashiest risks in cybersecurity, but they remain among the most important ones for businesses trying to improve their readiness.
Fortunately, the threats that are still causing the majority of incidents also have tried-and-tested mitigations that should help to keep your business safe.
“AI-powered malware” is cited as the top concern of global SMBs for the year ahead, according to the ESET SMB Cyber Readiness Index 2026. It’s even higher (33%) in North America. However, if we’re taking the definition to mean malware that uses AI in an automated and real-time way, it’s more of a topic for the research community than it is for cybersecurity practitioners.
ESET discovered the first example of AI-written ransomware in 2025. However, even this is likely to have been a proof-of-concept (PoC). Meanwhile, PromptSpy, which ESET discovered earlier this year, was the first-known Android malware to abuse generative AI (GenAI) in its execution flow to achieve persistence.
There have been relatively few, if any, similar discoveries by threat researchers. It’s also true that ESET’s MDR service has no evidence of incidents in which GenAI played a significant role. Threat actors do benefit from AI support, but few are operationalizing the technology in real time for truly automated tasks.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/
Officially imported this from ESET’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- ESET — imported from official source
- Official source
- https://www.welivesecurity.com/en/rss/feed/ RSS
- Imported
- September 18, 2026 11:35
- Versions
- 1 recorded
- Identity
https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics...