
When addressing AI cybersecurity, we often discuss the threat of machine speed attacks and the necessity of machine speed defense. However, this is only possible for large corporations capable of affording such deployments. We asked HAL9000 about the risk for small businesses and what they can do to stay safe given their limited resources.
AI Speeds Up Scale, Not Magic
The good news is buried in how these attacks actually work: AI speeds up scale, not magic. Machine-speed attacks still exploit the same old weaknesses — unpatched software, reused passwords, phishing, exposed services.
That means the defenses that worked before still work; you just have less margin for sloppiness. Your protection is mostly preparation, not real-time response, because machine-speed attacks exploit gaps that exist before the attack starts.
Why Small Targets Are Partly Protected by Economics
Attackers at scale are opportunistic, not personal. AI lets criminals scan the entire internet for vulnerable systems and send millions of convincing phishing emails cheaply. You’re rarely “targeted” — you’re caught in a trawling net.
This matters because trawling nets catch the easiest fish. If your defenses are even modestly better than average, automated attacks usually move on to softer targets. You don’t need to outrun the bear; you need to not be the slowest camper.
What Actually Protects Individuals
The high-leverage moves for individuals:
- A password manager with unique passwords everywhere. Credential-stuffing attacks are fully automated and only work on reused passwords.
- Phishing-resistant multi-factor authentication. Ideally passkeys or hardware keys rather than SMS codes.
- Automatic updates turned on for everything. OS, browser, phone, and router.
- Skepticism toward urgency. AI-generated phishing and voice cloning are eroding the old “look for typos” advice. The new rule: verify unexpected requests through a separate channel, especially anything involving money or credentials.
- A family code word for “emergency” calls. Voice-clone scams impersonating relatives are real and growing.
What Actually Protects Small Businesses
Everything from the individual checklist applies, plus:
- Offline or immutable backups, tested regularly. Ransomware’s leverage disappears if you can restore.
- Cloud services instead of self-hosting where possible. Google Workspace or Microsoft 365 gives you the machine-speed defense of a trillion-dollar security team for a monthly fee.
- Least-privilege access. One compromised account shouldn’t own everything.
- A written procedure requiring out-of-band verification for any payment or banking change. Business email compromise causes more losses than ransomware, and a phone call defeats it.
The cloud point deserves emphasis: the premise that machine-speed defense is only for big corporations is partly wrong. Small entities can rent it. Managed email filtering, endpoint protection like Microsoft Defender for Business, and automatic cloud patching are exactly the AI-vs-AI defense layer, priced per seat.
When Should You Worry About Being Deliberately Targeted?
Deliberate targeting is expensive in attacker attention, so it correlates with what you have or what you can access. You warrant genuine concern if:
- You hold cryptocurrency in meaningful amounts — irreversible transfers make you uniquely attractive.
- You’re a journalist, activist, dissident, or researcher of interest to a government. Spyware like Pegasus is real but almost exclusively state-deployed against such profiles.
- You’re an executive, finance employee, or IT admin whose credentials unlock an organization — attackers target you to get to your employer.
- You’re going through a hostile divorce or have a stalker — stalkerware is the common person’s targeted threat.
- You’re publicly wealthy or recently, visibly came into money.
- You’re a public figure with harassment exposure.
If none of those apply, your realistic threat model is automated and opportunistic, and baseline hygiene handles the overwhelming majority of it. Worrying about nation-state attacks while reusing passwords is getting the priorities backwards.
Key Takeaways
- AI scales attacks but exploits the same old gaps; good hygiene still works, with less forgiveness for lapses.
- Most people are caught in automated nets, not targeted — being modestly harder than average deflects most attacks.
- Highest-impact defenses: password manager, passkeys or hardware MFA, auto-updates, tested offline backups, and out-of-band verification for money requests.
- Small businesses can rent machine-speed defense via cloud providers rather than build it.
- Deliberate targeting mainly follows crypto holdings, sensitive professions, privileged work access, personal conflicts, or visible wealth.
