AI is both a friend and foe for business owners: unlocking huge potential for efficiency and growth, while simultaneously handing cyber criminals powerful new tools. The 2025 Hiscox Cyber Readiness Report (CRR) found that over half of small businesses (57%) experienced at least one cyber-attack due to AI vulnerabilities.
Given the high stakes, the vast majority of small- and medium-sized enterprises (SMEs) are taking proactive steps to step up their cyber defences: 91% conduct cyber vulnerability checks such as simulations or penetration tests, at least once a quarter, while 94% have planned to increase their investment in cyber security and data protection. 71% have cyber insurance coverage.
As AI increases in both power and prevalence, business leaders need to understand and mitigate cyber risk in all its forms.
1. Ransomware, data theft and reputational damage
Company leaders surveyed for the CRR ranked AI malware and phishing attacks among the top three emerging AI-driven threats in the next five years, while 27% reported they had experienced a ransomware attack in the previous 12 months.
AI is supercharging malware - programmes designed to hack into or disrupt networks and, in the case of ransomware, extort money from those who’ve been hacked. In such cases, AI’s iterative abilities can be especially damaging, because attackers can train AI models to gradually improve their own ability to avoid detection and cause harm.
The research also provides insight into the impact of such attacks. Of all companies affected by ransomware, 80% paid a ransom to protect or recover critical data. However, only 60% of these companies did successfully recover some or all of their data. For another 31%, the attackers simply demanded more money.
As the threats evolve, security software is rising to the challenge, with the latest generation of programmes powered by AI. They combine antiviruses, firewalls and password managers - as well as regular, secure data back-ups - to protect against threats such as ransomware. Regularly installing updates across all software used by the company also ensures the best protection.
2. AI poisoning and data extraction
As well as harnessing the speed of AI to accelerate well-known cyber-crime methods, hackers are also targeting the data that all AI systems rely on. “AI poisoning” describes attacks in which malicious actors manipulate or corrupt the data being used to train or feed AI models in order to influence the responses they provide.
For SMEs, this risk is heightened when integrating AI-assisted tools into key processes, such as financial modelling, shared drives or planning assistants. By inserting even a single malicious file into these shared spaces, cyber criminals can manipulate the AI systems that run them.
In practical terms, this could mean anything from AI breaking access codes and disclosing sensitive data, to a corrupted spreadsheet that returns subtly wrong calculations to influence business decisions. Sophisticated AI poisoning can be highly stealthy: designed to corrupt data gradually, its effects can be dismissed at first, then only investigated once serious damage has already been done.
Companies can take steps to protect themselves from AI poisoning by limiting access to sensitive data to those who strictly need it, and providing ongoing awareness training for employees as risks evolve - a measure already taken by 60% of businesses in the Cyber Readiness Report. Other recommended steps include investing in tailored software, as well as cyber insurance policies that explicitly cover AI risks.
3. Systemic and aggregated loss risk
AI isn’t just creating new individual risks or speeding up traditional attacks. It is fundamentally reshaping the risk landscape, by enabling malicious groups to replicate attacks across thousands of targets simultaneously.
This means that, even as new technologies enable small businesses to increase their footprint in the global digital economy, they must build resilience to cyber threats that exploit our interconnected world. As businesses across entire sectors embed the same AI models, platforms and agents into their processes, a single compromised platform could affect thousands of organisations at once, crippling an entire supply chain or a whole industry.
The Cyber Readiness Report suggests that for close to a third of SMEs (28%), vulnerabilities in supply chains such as vendor websites were the most common point of entry for cyber attacks in the previous year. In response, businesses are stepping up their vigilance: as many as 88% are already conducting assessments at least once a quarter to determine the cyber security risks of their suppliers and partners. As with AI poisoning, limiting access to sensitive data and providing regular training or guidance to both employees and partners can help reduce exposure to systems-level risks.
4. AI-enabled fraud and deepfakes
AI-enabled social engineering has emerged as one of the most acute areas of cyber risk: among the more than 5,700 companies participating in our cyber readiness research, 60% identified social engineering attacks as a top emerging AI-driven threat for the coming five years. Although these techniques - which rely on taking advantage of human psychology to exploit digital vulnerabilities - have been around as long as humans have had computers, AI amplifies the risk by making the attacks easier, faster and cheaper to carry out.
In practice, this often means more convincing and more targeted fraud attempts: hackers harness the power of AI to create highly personalised, credible communication. In the past, employees might receive poorly crafted phishing emails or anonymous phone calls. Today, social engineering could be a highly sophisticated AI voice clone of a colleague, designed to trick employees into revealing confidential information; personalised, multi-channel messaging that follows team members across email, messaging apps and work chat platforms; or even a deepfaked multi-person video call, impersonating executives to secure approval for a fraudulent payment.
To protect against these threats, comprehensive and regular training and support for staff is vital. The Cyber Readiness Report data makes this clear: 96% of SMEs who experienced an attack agreed that greater awareness or understanding of cyber attacks and procedures is key to better response times in the case of a breach. For nearly half of respondents (49%), a better understanding of who to report an attack to would also be helpful. 70% reported they were hiring additional staff members to boost cyber resilience and 33% employ AI security consultants.
Although the rapid adoption of AI opens up extraordinary opportunities for businesses, the pace of change presents significant challenges for leaders, who must balance innovation against risk management.
From up-to-date software, security programmes and password management protocols, to regular data back-ups and robust access requirements, today’s cyber security measures must keep pace with fast-evolving risks.
Proactive companies that take steps to understand the risks they face and build resilience into their operations will be best placed to seize the opportunities to come.