AI-Powered Cyberattacks: 2026 Small Business Defense Guide
A practical 2026 guide to AI-enhanced phishing, impersonation, and malware risks, with layered defenses, an incident-response procedure, and a 90-day implementation plan for small businesses.

Affiliate Disclosure: This article contains affiliate links. If you make a purchase through these links, we may earn a small commission at no extra cost to you.
Artificial intelligence is changing cybersecurity on both sides. Attackers use AI to write more convincing phishing emails, clone voices, generate polymorphic malware, and accelerate vulnerability research. Defenders use AI-powered behavioral analysis, automated patching, and anomaly detection that were once enterprise-only.
This guide is an operational playbook for U.S. small businesses with 10–50 employees. It covers what has genuinely changed in 2026, which threats are common versus emerging, free first steps you can take today, product-selection criteria with verified pricing, an incident-response procedure, and a 30/60/90-day implementation plan.
What You'll Learn
- What has actually changed in AI-assisted attacks in 2026—and what has not
- A ten-minute exposure check for email, banking, websites, and cloud accounts
- Five free or low-cost actions you can take today
- Layered controls with verified product pricing and selection criteria
- An incident-response procedure for BEC, deepfake, and malware events
- A 30/60/90-day plan with owners, evidence, and success measures
- Insurance and CIRCIA preparation
2026 Threat Snapshot
The FBI's 2025 Internet Crime Report recorded 22,364 complaints containing AI-related information and more than $893 million in adjusted losses. Businesses reported more than $30 million in losses from business-email-compromise (BEC) complaints involving AI. These figures reflect reported complaints—not a clean count of confirmed AI attacks—but they show why independent verification of payment and account-change requests now belongs in routine operations.
In May 2026, Google Threat Intelligence reported that threat actors are using AI for polymorphic malware development, autonomous runtime commands (PROMPTSPY), and novel vulnerability discovery—including what Google assessed was the first AI-assisted zero-day exploit attempt. The Australian Signals Directorate issued SMB-specific guidance in July 2026 highlighting websites, supported software, and rapid patching as priorities for small businesses.
What Has Changed in 2026—and What Has Not
AI does not invent new attack categories. Phishing, BEC, malware, and vulnerability exploitation predate generative AI by decades. What AI changes is the speed, scale, and polish of attacks—and the accessibility of tools that produce them.
Common Now: AI-Enhanced Phishing and BEC
AI analyzes publicly available information from LinkedIn, social media, and company websites to create contextually relevant messages. These messages reference real projects, colleagues, and business processes in correct grammar and appropriate tone. BEC variants include invoice-payment redirection, payroll-change fraud, and executive-impersonation wire requests.
Likelihood: common. BEC remains a costly business threat; the FBI recorded more than $3 billion in reported BEC losses and more than $30 million from BEC complaints involving AI during 2025. AI lowers the skill barrier and increases message volume.
What this means for your business: Grammar and tone are no longer reliable phishing indicators. Verification procedures for unusual financial requests—especially through a separate, previously confirmed channel—are the primary defense. Modern email-security platforms use behavioral analysis rather than pattern matching alone, but no filter catches everything.
Documented and Growing: Voice and Video Synthesis
Voice synthesis can generate realistic speech from short audio samples. The FTC has confirmed that a brief online audio clip can be enough to clone a voice. Video deepfakes are increasingly used in real-time video calls. The FBI warned in 2025 that criminals were using AI-generated voice messages in impersonation campaigns and recommended verifying a caller through independently confirmed contact information.
Likelihood: documented and growing. AI voice-clone fraud is documented in the IC3 report and FBI alerts. Real-time video deepfakes in business calls are reported but less frequent than voice-only attacks.
What this means for your business: Do not rely on voice, video, or caller ID alone for sensitive approvals. Callback verification using an independently obtained number substantially reduces the risk, though it is not foolproof if the number itself, the account, or the forwarding route has been compromised. Verbal codes or pre-shared verification questions add another layer. For a separate early-2026 malware case study, see our analysis of the Slopoly backdoor.
Growing: AI-Assisted Vulnerability Discovery and Exploitation
The important 2026 development is not ordinary automated scanning against known vulnerability databases—that has existed for years. The change is AI assistance with novel vulnerability discovery and exploit generation. Google Threat Intelligence reported in May 2026 what it assessed was an AI-assisted zero-day, and a criminal group appeared close to using it in a mass-exploitation campaign before Google's counter-discovery. The July 2026 Australian government SMB guidance specifically prioritizes keeping websites patched, running supported software, and applying updates promptly.
Likelihood: growing. AI-assisted zero-day research is documented but not yet routine for commodity attacks against SMBs.
What this means for your business: Rapid patching, supported operating systems, and removing abandoned websites or plugins are higher priority than before. If your business runs a public-facing website, CMS, or web application, treat it as an attack surface that must be patched and monitored.
Emerging: Adaptive and Autonomous Malware
Google documented AI-augmented coding for polymorphic malware—code that modifies its appearance while retaining malicious functionality—and autonomous malware families like PROMPTSPY that generate runtime commands from model outputs. These capabilities exist in the wild but should be understood as emerging rather than routine SMB malware today.
Likelihood: emerging. Documented by Google Threat Intelligence, but the bulk of SMB malware still uses conventional techniques enhanced by better evasion.
What this means for your business: Behavioral detection (monitoring what software does, not what it looks like) is important alongside signature matching. Modern endpoint protection from vendors like Bitdefender, Malwarebytes, and ESET includes these capabilities. Our EDR comparison guide covers which platforms offer the strongest behavioral detection at SMB pricing.
| Threat | Status | Primary Defense |
|---|---|---|
| AI-personalized phishing and BEC | Common now | Callback verification, behavioral email filtering, financial-change procedures |
| Voice/video synthesis | Documented and growing | Independent-number callback, verbal codes, multi-person approval |
| AI-assisted vulnerability exploitation | Growing | Rapid patching, supported software, website maintenance |
| Adaptive/autonomous malware | Emerging | Behavioral endpoint detection, application control |
Ten-Minute Exposure Check
Before buying any product, spend ten minutes checking what you already have exposed.
Quick Exposure Checklist
Email and identity
- Is MFA enabled on every email account? (Check Microsoft 365 / Google Workspace admin)
- Is legacy authentication (POP, IMAP without modern auth) disabled?
- Do you have SPF, DKIM, and DMARC records published? (Use a free checker like MXToolbox)
- Are there separate admin accounts (not the same account used for daily email)?
Banking and payments
- Is MFA enabled on every banking portal and payment platform?
- Who can change bank details for vendors or payroll? Is there a second-person sign-off?
- Does anyone approve payments solely over email without a phone or in-person check?
Websites and web applications
- Are CMS (WordPress, Shopify, etc.) and plugins on supported, patched versions?
- Are there abandoned staging sites, old domains, or test environments still running?
- Who has hosting-panel and FTP/SSH access? When were credentials last rotated?
Remote access and cloud accounts
- Is remote-desktop (RDP) exposed to the internet without a VPN or zero-trust gateway?
- Do all cloud apps (file storage, CRM, accounting) require MFA?
- When did someone last review which employees still have active accounts?
Backups
- Do you have at least one backup copy stored offsite or in a separate cloud account?
- When was the last time someone tested restoring a file—or an entire system?
- Are backup credentials separate from your main domain credentials?
Five Immediate Free or Low-Cost Actions
These cost nothing beyond staff time and address the most common attack paths.
1. Enable MFA on all email, banking, and admin accounts. Software authenticators (Microsoft Authenticator, Google Authenticator) are free. MFA prevents a stolen password alone from being sufficient to access an account.
2. Verify your patching status. Check that operating systems, browsers, email clients, CMS platforms, and plugins are on current supported versions. Remove software and sites you no longer maintain.
3. Establish a financial-change verification procedure. Any request to change bank details, redirect a payment, alter payroll, or authorize an unusual purchase must be confirmed through a separate channel—a phone call to a known number, or in-person confirmation. Post this as a written policy. See the Financial Verification Procedure below.
4. Review admin accounts and offboarding. Disable accounts for former employees. Ensure admin access uses separate credentials from daily email. Remove unnecessary global-admin roles.
5. Test a backup restore. If you have backups, restore a file today. If you cannot, you do not have working backups.
Layered Defense: Product Selection and Verified Pricing
The worked example below estimates between $243 and $459 monthly (recurring) for a 10–20 employee business using direct-retail pricing checked in July 2026, plus a one-time hardware-key investment. It is a planning model, not a quote. Prices, promotions, and packaging change; confirm live pricing before purchasing. If your business already licenses Microsoft 365 Business Premium or a similar suite, check what endpoint, identity, and device-management features you already have before paying twice.
All prices checked on the vendor's public pricing page on July 21, 2026, unless otherwise noted. Promotional, volume, and reseller pricing may differ.
Component 1: Endpoint Protection
Endpoint protection is the primary defense against malware, ransomware, and other threats. Look for behavioral analysis (monitors what software does, not just its file signature), centralized management, and coverage for every operating system your business uses.
Bitdefender GravityZone Business Security
Price: From approximately $77.69/year for 3 devices (list price as configured in the Bitdefender online store, July 2026). Per-device cost decreases at higher device counts; a 10-device, 1-year license was approximately $258 ($2.15/device/month) at the time of checking, though this reflects a promotional rate that may not persist at renewal. Best for: Businesses wanting comprehensive features and a centralized console without dedicated IT staff. Get Bitdefender Business →
GravityZone Business Security combines multi-layered anti-malware with machine-learning behavioral analysis, network attack defense, web-traffic scanning, firewall management, application/device control, and a centralized cloud console. Email security is an add-on (GravityZone Email Security), not included in the base plan. HyperDetect and sandbox analysis require the Premium tier.
Strengths: Bitdefender GravityZone Business Security scored 18/18 in AV-TEST's February 2025 business evaluation (6/6 protection, performance, and usability). AV-Comparatives certified the Enterprise edition—a higher tier—in its May 2026 EDR validation; because that test covered a different product tier, we do not treat it as direct validation of the base Business Security package. Granular policy control with low performance overhead. The centralized console is manageable for businesses without dedicated security staff. Limitations: The add-on structure means email filtering, patch management, and full-disk encryption each add cost. Promotional pricing may not match renewal pricing.
Malwarebytes for Teams
Price: Sold in device packs—3 devices (Sole Proprietor), 10 devices (Boutique Business), and 20 devices (Small Office)—at malwarebytes.com/pricing/teams. Per-device cost is approximately $40–$60/device/year depending on pack size and current promotions (July 2026). Pricing is dynamic; the site did not display a fixed per-device list price at time of checking. Best for: Small teams wanting straightforward malware protection without complex management. Get Malwarebytes Teams →
Teams provides real-time malware protection with behavioral analysis, web protection, brute-force protection for Windows, monthly security reports, a personal VPN, and Browser Guard.
Strengths: Simple deployment with no IT skills required. In our client deployments, detection has been effective with low performance impact. SOC 2 Type 2 certified. Limitations: Teams does not include ransomware rollback, EDR, or managed detection and response. Those capabilities belong to ThreatDown Advanced and higher tiers, which are priced separately and require minimum seat counts. Teams also does not include centralized patch management. Do not confuse Teams with ThreatDown when comparing features.
ESET Small Business Security
Price: Managed through ESET HOME, pricing is configurable by device count (up to 25 devices). Checkout pricing is dynamic; configure your device count at the ESET store for a current quote. For the ESET PROTECT console with Linux support and centralized management, evaluate ESET PROTECT tiers separately. Best for: Very small offices (under 25 devices) wanting lightweight protection managed through a simple home-style console. Get ESET Small Business Security →
Protects Windows, macOS, and Android endpoints. On iOS, ESET provides VPN and ESET HOME management but not antivirus protection. The subscription also includes ESET Safe Server for supported Windows Server file servers. Management is through the ESET HOME app—not the enterprise ESET PROTECT console.
Strengths: In our experience, minimal system impact—suitable for older hardware. Simple management for non-technical users. Includes Safe Server for Windows Server file protection. Limitations: 25-device cap. No Linux endpoint coverage. No ESET PROTECT console (centralized policy, reporting, and deployment tools require ESET PROTECT Entry or higher). No antivirus on iOS. Businesses needing Linux endpoints, more than 25 devices, or centralized management should evaluate the ESET PROTECT business tiers, beginning with Entry; higher tiers add capabilities such as cloud application protection, advanced threat defense, encryption, and patch management.
Endpoint Protection Comparison:
| Solution | Approx. Annual Cost (10 devices) | Approx. Annual Cost (20 devices) | Key Strengths | Key Limitations |
|---|---|---|---|---|
| Bitdefender GravityZone Business | ~$258 (promo) | ~$516 (promo) | Strong detection, centralized console | Email security is an add-on; promo pricing may not persist |
| Malwarebytes Teams | ~$400–$600 (pack-dependent) | ~$800–$1,000 (pack-dependent) | Simple deployment, no IT required | No ransomware rollback, no EDR, no patch management |
| ESET Small Business Security | Configurable | Configurable (up to 25 devices) | Low system impact, Safe Server included | No Linux, no iOS antivirus, no ESET PROTECT console, 25-device limit |
Note: "Approx." denotes pricing that varies by promotion, pack, and configuration. Check vendor pages for current pricing before purchasing.
Component 2: Password Management with MFA
A centralized password manager combined with multi-factor authentication protects business accounts from credential theft. If your team currently shares credentials in spreadsheets or documents, see our analysis of the true cost of that practice. Hardware security keys provide phishing-resistant authentication for the password manager itself; deploying phishing-resistant MFA to every external service depends on each service's support. For a deeper look at how password managers address AI-specific threats, see our password managers and AI threat protection comparison.
1Password Business
Price: $8.99/user/month, billed annually (1password.com/pricing, July 2026). Get 1Password Business →
Includes Watchtower security alerts, Travel Mode, hardware security key support (YubiKey, FIDO2), team sharing, service-account management, granular admin controls, audit logs, and SSO integration.
Strengths: Comprehensive feature set with service-account management useful for IT teams. Limitations: Higher per-user cost than alternatives. Hardware-key support protects the 1Password vault; deploying phishing-resistant MFA to each external service depends on that service's own FIDO2/WebAuthn support.
NordPass Business
Price: Teams plan (up to 10 users) starts at $1.79/user/month on a 2-year term; Business plan starts at $3.59/user/month billed annually. Pricing varies by term length and promotion (nordpass.com/plans/business, July 2026). Business plans require a 5-user minimum. Get NordPass Business →
Includes password health monitoring, breach scanning, secure sharing, hardware-key MFA, admin dashboard, and activity logging.
Strengths: Lower per-user cost, especially on longer terms. Limitations: Emergency Access is a personal Premium/Family feature—not available for business-vault continuity. Fewer enterprise integrations than 1Password. Feature set varies between Teams and Business plans; verify which plan includes what you need.
Component 3: Backup and Recovery
Backups protect against ransomware, hardware failure, accidental deletion, and cloud-service data loss. The architecture matters as much as the product: aim for at least one immutable or offline copy with credentials separated from your main domain, and a documented restore test.
Key Backup Architecture Principles
- 3-2-1 rule: Three copies of data, two different media or storage types, one stored offsite or in a separate cloud account.
- Separated credentials: Backup admin accounts should use different passwords and MFA from your primary domain. If an attacker compromises your email admin, they should not automatically gain access to delete backups.
- Immutable or offline copies: At least one backup copy should be immutable (cannot be altered or deleted for a retention period) or stored offline. This protects against ransomware that encrypts or deletes accessible backups.
- SaaS data: Microsoft 365 and Google Workspace provide limited retention and recovery. If your business depends on cloud email, files, or databases, verify what happens if data is deleted or encrypted, and consider a dedicated SaaS backup product. Our Google Workspace backup guide covers this in detail.
- RPO/RTO: Define how much data loss is tolerable (Recovery Point Objective) and how quickly you need to be operational (Recovery Time Objective). These drive your backup frequency and restore testing.
- Documented restore test: An untested backup is an unverified recovery plan. Schedule a quarterly test restore and document the results.
Acronis Cyber Protect
Price: Acronis Cyber Protect Standard starts at $85/year per workstation license (acronis.com, July 2026). Pricing varies by edition (Standard, Advanced, Backup Advanced), number of workloads (workstations, servers, VMs), and included cloud storage. A 10-workstation deployment at the Standard tier would cost approximately $850/year (~$71/month) before additional storage, server licenses, or Advanced-tier features. Confirm your edition, workload count, and storage allocation before purchasing. Get Acronis Cyber Protect →
Combines backup with anti-malware: ransomware-detection monitoring, malware scanning of backups before restoration, universal restore to different hardware, and remote management. MSP pricing may differ from direct retail.
Strengths: Integrated backup and security reduces complexity. Ransomware detection adds a layer beyond standalone backup. Limitations: Pricing escalates with server licenses, additional storage, and Advanced-tier features. The integrated anti-malware should not replace a dedicated endpoint-protection product.
IDrive for Business
Price: IDrive Business starts at $59.99/month for 1.25 TB of storage with unlimited users and devices (idrive.com/pricing, July 2026). A 500 GB Business plan is also available at a lower price ($19.99/month, or ~$13.99/month with promotional annual billing); standard renewal pricing differs. IDrive 360 is a separate product with device-based licensing. Get iDrive Business →
Cloud backup with unlimited devices and users per plan, real-time and scheduled backup, multiple version retention, and cross-platform support.
Strengths: Flat-rate pricing per storage tier with unlimited devices simplifies budgeting. Limitations: Backup only—no integrated security. Verify your data volume fits within the chosen tier; costs increase at higher storage levels.
Component 4: Security Awareness Training
Employee training reduces the effectiveness of social engineering attacks. Modern training platforms provide simulated phishing campaigns and ongoing education.
Price range: KnowBe4, one of the larger training platforms, lists pricing from approximately $2.40–$3.75/user/month for 25–50 seats on a three-year term (KnowBe4 pricing page, July 2026). Note the 25-seat minimum—a 10-person company would pay for 25 seats (~$60–$94/month). SMB-focused platforms may offer lower minimums; quote from at least two vendors for your actual seat count and required features before budgeting.
For comprehensive training, look for regular content updates focused on current threats, simulated phishing campaigns with reporting, and customizable training paths.
Example Budget Summary
The table below uses a single illustrative configuration. Your actual costs will depend on the specific products, tiers, device counts, and promotions at the time of purchase.
The example assumes one workstation per employee. If your device count differs (e.g., shared workstations, servers, or multiple devices per person), adjust endpoint and backup quantities accordingly.
| Component | Example Product | ~10 Devices/Month | ~20 Devices/Month | Notes |
|---|---|---|---|---|
| Endpoint Protection | Bitdefender GravityZone Business | ~$22 | ~$43 | Promo rate; verify renewal price |
| Password Manager + MFA | 1Password Business | $90 | $180 | $8.99/user/month, annual billing |
| Backup & Recovery | Acronis Cyber Protect Standard | ~$71 | ~$142 | $85/workstation/year; servers extra |
| Security Training | Platform varies (25-seat minimum common) | ~$60–$94 | ~$60–$94 | KnowBe4 quotes from $2.40/user/month at 25 seats |
| Hardware Keys | YubiKey 5 NFC or Security Key NFC | $580–$1,160 one-time | $1,160–$2,320 one-time | 2 keys per employee ($29–$58 each) |
| Estimated Monthly Total (recurring) | ~$243–$277 | ~$425–$459 | Planning estimate only |
Annual recurring estimate: ~$2,920–$3,320 (10 devices) to ~$5,100–$5,510 (20 devices), plus one-time hardware-key cost.
Hardware keys are a one-time purchase. Deploy to administrators, finance, and owners first if budget requires phasing. The recurring monthly total excludes hardware keys.
This is an illustrative budget. Prices, features, and packaging change. Confirm current quotes before purchasing. Managed-service pricing may differ. If your business already licenses a suite like Microsoft 365 Business Premium, review its included endpoint, identity, and device-management features to avoid duplicate spending.
Calculate Your Personalized Budget
Use this interactive calculator to estimate security costs for your specific business size:
Assumes one workstation per user. Endpoint and backup are licensed per device; password manager per user.
Your Security Budget
Planning estimate · verify prices before purchasing
Free security audit • Customize your protection
Financial Verification Procedure
Post this procedure (or your adapted version) where employees can reference it. It addresses bank-detail changes, invoice payments, payroll changes, and executive requests.
Financial Change Verification Policy
Scope: All requests to change bank details, redirect payments, alter payroll information, authorize unbudgeted purchases, or act on executive requests for gift cards, wire transfers, or cryptocurrency.
Procedure:
- Do not act on the request through the channel it arrived in. Do not reply to the email, return the call, or respond in the chat thread.
- Contact the requester through a separately confirmed channel. Call them at a phone number you already have on file (not one provided in the message). If possible, confirm in person.
- Require second-person approval. No single employee should be able to change payment details or authorize an unusual payment alone. A second person must verify and approve.
- Document the verification. Record who requested the change, who verified it, the channel used for verification, and the date. Keep this record for audit.
- Escalate if verification fails. If you cannot reach the requester through a known channel, or if anything feels unusual, escalate to a manager or owner before proceeding. A legitimate requester should tolerate a brief verification delay; fraudulent transfers can be difficult to recover.
The 5-minute rule: Any unusual financial request can wait five minutes for verification. This practice prevents many successful attacks while creating minimal business friction.
Incident Response: What to Do During a Suspected Attack
If you suspect a BEC, deepfake fraud, or malware infection, follow this procedure. Speed matters—especially for payment fraud, where banks can sometimes reverse transfers if notified within hours. For a broader prevention-oriented approach, see our 90-day breach prevention plan.
Incident Response Steps
For suspected BEC or payment fraud:
- Stop the payment. Contact your bank immediately to request a hold or reversal. If the payment was a wire, request a recall.
- Preserve evidence. Do not delete the fraudulent email, message, or call record. Save the full email with headers (in Outlook: File → Save As; in Gmail: Show Original). Screenshot any chat or call logs.
- Contact the real person. Call the executive, vendor, or colleague who was allegedly requesting the payment—using a known number—and confirm they did not make the request.
- Reset compromised credentials. If the attacker accessed or may have accessed any account, change the password and revoke active sessions immediately. Enable MFA if it was not already active.
- Report to IC3. File a complaint at ic3.gov immediately regardless of amount. Your bank and the FBI may be able to initiate a Financial Fraud Kill Chain when the applicable criteria are met.
For suspected malware or ransomware:
- Isolate affected systems. Disconnect affected devices from Ethernet and Wi-Fi immediately. Avoid powering them down if successful isolation is possible, because volatile forensic evidence may be lost. If you cannot isolate a device from the network, power it down to limit further spread.
- Do not pay the ransom without legal and professional guidance. Payment does not guarantee data recovery and may violate sanctions.
- Notify your endpoint-protection vendor or MSP. They can assist with containment and forensic investigation.
- Restore from clean backups after the infection vector is identified and closed. Scan backups for malware before restoring.
- Report and notify. File with IC3. Notify your cyber insurer and qualified breach counsel promptly. Notification duties depend on the data involved, affected individuals' locations, contracts, industry rules, and applicable state or federal law.
For all incidents:
- Document a timeline: when the incident was detected, what actions were taken, and by whom.
- Preserve logs from email, endpoint protection, cloud admin consoles, and backups.
- After resolution, conduct a post-incident review to close the gap that allowed the incident.
Email, Identity, and Website Controls
These controls address gaps that products alone do not fill.
Email Authentication
- SPF, DKIM, and DMARC: Publish these DNS records to reduce the chance of attackers spoofing your domain. Free to configure; most email providers (Microsoft 365, Google Workspace) document the setup process. A
p=noneDMARC record only monitors—it does not block spoofed messages. Plan a path towardp=quarantineand ultimatelyp=rejectenforcement once you confirm all legitimate sending sources are aligned. - Disable legacy authentication: Turn off POP, IMAP without modern auth, and SMTP AUTH if not needed. These protocols bypass MFA.
- Phishing-resistant MFA: Where supported, use FIDO2 security keys or passkeys instead of SMS or push notifications.
Admin Account Hygiene
- Separate admin accounts: Do not use the same account for daily email and global administration. A compromised daily-use account should not grant admin access.
- Conditional access: In Microsoft 365 or Google Workspace, restrict admin sign-in to managed devices or known locations.
- Offboarding: Disable accounts for departing employees the same day. Revoke app passwords, OAuth tokens, and shared-vault access.
Website and Web-Application Security
The July 2026 Australian government guidance specifically highlights websites as a primary AI-accelerated target. Small businesses often run WordPress, Shopify, or custom web applications with forgotten plugins, unpatched themes, or abandoned staging sites.
- Patch CMS and plugins promptly. Remove plugins and themes you do not use.
- Remove abandoned sites (staging environments, old microsites, retired domains). Each one is an attack surface.
- Use HTTPS everywhere and ensure SSL certificates are current.
- Restrict hosting-panel access (cPanel, Plesk, SSH) to named individuals with separate credentials and MFA.
- Back up your website independently from your hosting provider, with a tested restore procedure.
AI Tools Used by Employees
Employees may use ChatGPT, Copilot, Claude, or other AI services for work. This creates exposure if they enter confidential data, grant connectors access to business systems, or install unvetted AI-service browser extensions.
- Publish an acceptable-use policy for AI tools that specifies what data can and cannot be entered.
- Inventory AI service accounts and connectors. Review which services have OAuth access to your email, calendar, or file storage.
- Watch for shadow AI: Employees installing AI browser extensions or desktop agents that request broad permissions.
- Prompt-injection exposure: AI agents with access to email, calendars, or documents can be manipulated through crafted content in those sources. Limit agent permissions to the minimum necessary scope.
90-Day Implementation Plan
Days 1–30: Foundation
| Week | Action | Owner | Evidence | Success Measure |
|---|---|---|---|---|
| 1 | Enable software MFA on all email, banking, cloud, and admin accounts | Business owner or IT lead | Screenshot of MFA status per account | 100% of critical accounts MFA-enabled |
| 1 | Conduct device inventory (computers, phones, tablets, servers, OS versions) | IT lead | Spreadsheet of devices and OS versions | Complete inventory documented |
| 1 | Publish financial-verification procedure (see above) | Business owner | Signed policy document | All employees acknowledge receipt |
| 2 | Select and deploy endpoint protection to all devices | IT lead | Console showing all devices enrolled | All inventoried devices protected |
| 2 | Remove conflicting or outdated security software | IT lead | Uninstall logs | No conflicting software remains |
| 3 | Enroll team in password manager; import existing credentials | IT lead | Admin dashboard showing enrolled users | All employees enrolled |
| 3 | Create shared vaults for team credentials; retire insecure sharing | IT lead | Vault audit log | No passwords shared via email or messaging |
| 4 | Deploy backup solution; configure schedules based on data-change frequency | IT lead | Backup console showing schedule and first successful run | Initial backup completed |
| 4 | Perform first test restore | IT lead | Documented restore test with date and result | Restore verified working |
Days 31–60: Hardening
| Week | Action | Owner | Evidence | Success Measure |
|---|---|---|---|---|
| 5–6 | Order and deploy hardware security keys (YubiKey 5 NFC at $58 or Security Key NFC at $29, from yubico.com/store). Budget for a spare/recovery key per employee. | IT lead | Key distribution log | All employees have primary + backup key |
| 5–6 | Migrate critical accounts from software MFA to hardware keys | IT lead | Account MFA settings | Admin and financial accounts on hardware MFA |
| 5–6 | Document emergency-access procedures (lost key, account lockout) | IT lead | Written procedure | Procedure tested with one employee |
| 7–8 | Conduct first team security training session (phishing recognition, verification procedures, reporting) | IT lead or external trainer | Training attendance record | All employees completed training |
| 7–8 | Launch first phishing simulation campaign (if training platform supports it) | IT lead | Simulation results report | Baseline click rate documented |
| 7–8 | Publish and test reporting channel for security concerns | Business owner | Documented channel (email alias, Slack channel, phone) | All employees know how to report |
Days 61–90: Verification and Sustainability
| Week | Action | Owner | Evidence | Success Measure |
|---|---|---|---|---|
| 9–10 | Perform full backup-recovery test (restore files and at least one full system) | IT lead | Documented restore with date, duration, and any issues | Recovery time meets your RTO target |
| 9–10 | Conduct tabletop incident-response exercise (walk through BEC or ransomware scenario) | Business owner + IT lead | Exercise notes and identified gaps | Gaps documented with remediation plan |
| 9–10 | Review and harden email controls: verify SPF and DKIM alignment, set DMARC to monitoring with a documented path toward p=reject enforcement, disable legacy auth, audit admin accounts | IT lead | DNS records, admin-console settings, DMARC aggregate reports | SPF/DKIM aligned; DMARC monitoring active; legacy auth disabled |
| 11–12 | Review 90 days of security-monitoring data; tune false positives | IT lead | Console report | Alert volume manageable; no ignored legitimate alerts |
| 11–12 | Compile security documentation for insurance or compliance review | Business owner | Documentation package | Controls, tests, training records organized |
| 11–12 | Schedule quarterly security reviews on calendar | Business owner | Calendar invitations | Recurring quarterly review scheduled |
90-Day Security Foundation Established
At the end of 90 days, you should have:
- ✓ MFA on all critical accounts, with hardware keys on admin and financial accounts
- ✓ Behavioral endpoint protection on all devices
- ✓ Team enrolled in password manager with shared vaults
- ✓ Tested backup and documented restore procedure
- ✓ Financial-verification procedure published and acknowledged
- ✓ First security training completed with baseline phishing-simulation results
- ✓ Incident-response procedure documented and tabletop-tested
- ✓ Email authentication (SPF/DKIM aligned, DMARC monitoring active with enforcement path documented)
- ✓ Core controls and evidence organized for insurer review
- ✓ Quarterly review schedule established
This is a security foundation, not a finished state. Threats, tools, and your business will continue to change. The quarterly review keeps your defenses current.
Insurance and CIRCIA Preparation
Cyber-Insurance Applications
Cyber-insurance applications vary by insurer, policy, industry, and risk profile. The controls in this guide support questions commonly asked during underwriting, but buying a product is not the same as configuring it correctly or satisfying an insurer's conditions. Requirements vary by policy, risk, industry, configuration, coverage percentage, and evidence.
Controls Commonly Assessed by Insurers
Be ready to document:
✓ Multi-factor authentication on email, admin, and financial accounts ✓ Endpoint detection with behavioral analysis (not just legacy antivirus) ✓ Regular, tested backups (3-2-1 rule with documented restore tests) ✓ Employee training records (completed sessions and phishing-simulation results) ✓ Incident response plan (documented, tested in a tabletop exercise) ✓ Patch management (documented update approach and supported OS versions) ✓ Third-party vendor security (access reviews)
Confirm the exact controls and evidence your insurer requires with your broker and carrier. No generic product configuration guarantees coverage.
CIRCIA: Proposed Reporting Rules (Not Yet in Effect)
The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) directs CISA to establish reporting requirements for certain covered critical-infrastructure entities. As of July 21, 2026, the final rule has not been published. CISA's Unified Agenda entry targets September 2026, but this is a target, not a guaranteed publication date.
CIRCIA Quick Reference (Proposed, Not Yet Effective)
- Covered cyber incidents: Report within 72 hours after reasonable belief that one occurred (proposed)
- Ransom payments: Report within 24 hours after payment (proposed)
- Coverage: Final sector-specific criteria and thresholds are pending the final rule
- Effective date: Pending publication; not yet enforceable
Whether or not the final rule covers your business, the detection, escalation, and evidence-preservation practices in this guide strengthen your incident-response capability. For detailed information, visit the CISA CIRCIA page.
Conclusion
AI raises the speed, scale, and polish of attacks—but proven controls still materially reduce the risk. MFA, behavioral endpoint protection, callback verification, tested backups, and informed employees remain effective when properly configured and maintained.
The three highest-value actions for most small businesses are: (1) enable MFA everywhere, (2) establish financial-verification procedures, and (3) ensure you have working, tested backups with separated credentials. Everything else builds on that foundation.
Start Today
Immediate actions (30 minutes):
- Enable software MFA on all email accounts (free)
- Post the financial-verification procedure for your team
- Test restoring a file from your backup
- Schedule a team meeting to kick off the 90-day plan
Resources for next steps:
For professional implementation assistance or security assessments, visit our cybersecurity services page. Related guides:
- Small business cybersecurity software guide — comprehensive product coverage
- Business password manager comparison — detailed feature-by-feature analysis
- What happens when a business gets hacked — a real-world incident timeline
- ClickFix attacks guide — another current social engineering technique
- Passkeys implementation guide — deploying phishing-resistant authentication
- NIST CSF 2.0 for SMBs — aligning with a recognized cybersecurity framework
- New employee IT onboarding checklist — security-first setup for new hires
Sources and Verification Date
All product prices, features, and plan details were checked on vendor websites on July 21, 2026. Promotional pricing may have changed since that date. Primary sources cited in this article:
- FBI 2025 Internet Crime Report (IC3)
- FBI AI-voice impersonation alert (2025)
- FTC voice-cloning guidance
- Google Threat Intelligence: AI vulnerability exploitation (May 2026)
- Australian Signals Directorate: Defending against AI-enabled cyber attacks – SMB guidance (July 2026)
- CIRCIA Unified Agenda entry
- AV-TEST: February 2025 Business Windows Security Test
- AV-Comparatives: 2026 Bitdefender EDR Detection Validation
- Bitdefender GravityZone Business Security
- Malwarebytes Teams pricing
- ESET Small Business Security
- ESET PROTECT Entry
- 1Password Business pricing
- NordPass Business plans
- NordPass Emergency Access documentation
- Acronis Cyber Protect
- IDrive Business pricing
- Yubico store
- KnowBe4 training pricing
Frequently Asked Questions
Related Articles
More from Cybersecurity

The True Cost of Employees Sharing Passwords in Spreadsheets
Password spreadsheets cost businesses millions in breaches. Learn the hidden financial risks of shared credentials and how to protect your company.
14 min read

Service Business Security: Protection for Companies Without Traditional Offices
Complete cybersecurity guide for contractors, consultants, and field service teams operating without traditional office infrastructure. Mobile-first security strategies with budget-conscious solutions.
16 min read

DMARC for Small Business: 2026 Google & Microsoft Requirements Guide
Complete DMARC implementation guide for 2026 Google, Yahoo, and Microsoft email requirements. Learn SPF, DKIM setup, policy phases, and PCI DSS v4.0 compliance to prevent email spoofing and ensure deliverability.
15 min read
