Where AI actually pays off for small businesses in 2026
Skip the hype. Here are the five places AI reliably saves time in a small business, where it doesn't, and a simple 30-day plan to get started safely.
Spelling mistakes and clumsy grammar used to give phishing away. AI has removed those clues. Here's how to protect your business when attacks look perfect.
For years, security training taught people to spot phishing by its mistakes: poor spelling, awkward grammar, generic greetings and strange formatting.
That advice is now out of date. Generative AI lets attackers produce fluent, well-written, personalised messages in any language, in seconds. The obvious clues have largely gone — so businesses need a different approach.
Attackers can now generate convincing emails that match the tone of a real supplier, a bank or your own managing director. They can create hundreds of variations to get past filters, and translate them flawlessly for any market.
Company websites, LinkedIn profiles, press releases and social media reveal who works where, who reports to whom, which suppliers you use and when people are travelling. AI makes it quick to turn that information into a message that references real names, real projects and real timing.
Voice cloning and deepfake video mean a phone call or voice note that sounds like a senior colleague is no longer proof that it is that colleague. “I’m about to board a flight — can you get this payment out urgently?” is far more convincing in a familiar voice.
Attackers can hold realistic back-and-forth email conversations, responding naturally to questions that used to trip them up.
If you can’t rely on spotting mistakes, focus on what the message is asking you to do. Be suspicious of any message — however polished — that involves:
Training helps, but the strongest defences don’t depend on people spotting a fake at all.
Make it a firm rule: any new payee or change of bank details is confirmed by phoning a number you already hold — never one from the email or invoice itself. Require two people to approve new payees and large payments. This one process stops a large share of invoice fraud, whether the request is AI-written or not.
Standard MFA is far better than passwords alone, but attackers can trick users into approving prompts or handing over codes through fake login pages. Passkeys and FIDO2 security keys are resistant to this because they only work on the genuine website. Prioritise them for admins, finance and leadership.
Set up SPF, DKIM and DMARC on your domain, and move DMARC towards enforcement. This makes it much harder for attackers to send email that appears to come from your exact domain — protecting your customers and suppliers as well as your staff.
Apply least-privilege access: people should only access the data and systems their role needs. Separate admin accounts from everyday accounts. If one account is compromised, the damage is contained.
Monitoring for suspicious sign-ins, new inbox forwarding rules and unusual activity means a compromised account can be spotted and locked down before it’s used to attack others.
In the UK, the government-backed Cyber Essentials scheme sets out core technical controls — secure configuration, access control, malware protection, patching and firewalls — that protect against the most common attacks. It’s a practical baseline for any business.
Training still matters, but its focus should shift:
In the UK, suspicious emails can also be forwarded to the National Cyber Security Centre’s reporting service at report@phishing.gov.uk.
NX Cyber combines the controls above — email security, phishing-resistant identity, monitoring, practical staff training and Cyber Essentials readiness — into one managed service. If you’d like to know how well your business would stand up to a modern phishing attack, book a call.
Keep reading
Skip the hype. Here are the five places AI reliably saves time in a small business, where it doesn't, and a simple 30-day plan to get started safely.
AI assistants can find anything a user has access to — including files overshared years ago. Here's how to clean up permissions and data before rolling out Copilot.
Let’s talk
Book a call with our team and discover how NXAPP can help your business grow, innovate and stay protected.