AI is changing cyber crime, but strong cyber security still starts with the fundamentals.

I've spent most of my career around IT operations, managed services and cyber security, and one thing I've learned is this:
The stories change, but the problems often don't.
Right now, everyone's talking about AI, deepfakes, voice cloning, sophisticated ransomware gangs and the latest threat that's supposedly going to change everything.
Those threats are real. But after reading the latest cyber threat reports, I couldn't help thinking that many businesses are worrying about tomorrow's problems while still struggling with today's.
Most organisations aren't being compromised because a cyber-criminal used a cutting-edge AI attack. They're being compromised because someone clicked something they shouldn't, a password was reused, MFA wasn't enabled, or a system hadn't been patched for months.
Sound familiar? If it does, you're not alone.
"We're too small to be targeted"
I still hear this occasionally.
It's one of the most dangerous assumptions a business can make.
Cyber criminals no longer pick victims based on company size. They use automation, phishing kits, stolen credentials and ransomware toolkits to cast a wide net.
They're looking for the easiest route to money, not the biggest company logo. Smaller organisations often have fewer resources dedicated to security, making them attractive targets.
Think of it like home security. A burglar doesn't necessarily want the biggest house on the street. They want the easiest one to get into.
Your Microsoft 365 account is probably more important than your firewall
That sounds controversial, but hear me out.
Ten years ago, security conversations revolved around network boundaries: firewalls, VPNs and office locations.
Today, most businesses live in Microsoft 365, Teams, SharePoint, OneDrive, Azure, Google Workspace and countless cloud applications.
That's why identity has become the new perimeter.
If an attacker gets hold of a user's credentials, they don't care where the office is or what firewall you've bought.
They're already inside.
It's one reason I continue to be surprised when I see organisations without MFA enabled everywhere, or users sitting with administrator access they don't need.
Those are often the quickest security wins available.
AI is making attackers better salespeople
The 2026 N-able Annual Threat Report spends a lot of time discussing AI-powered threats, and rightly so. Deepfakes, synthetic voices and highly convincing phishing emails are becoming easier to create.
But what struck me is that AI isn't really changing the goal.
Attackers still want you to trust something you shouldn't.
They want someone in finance to approve a payment, a user to enter their Microsoft 365 password, or an employee to open an attachment.
The difference is that the email is written better, the fake phone call sounds more convincing and the scam looks more professional.
In many ways, AI has simply made social engineering scalable.
The boring stuff still matters
I know "keep systems patched" isn't as exciting as talking about AI-generated cyber attacks.
Neither is "enable MFA everywhere", "review privileged accounts" or "test your backups".
But if you look at the incidents causing real damage, the boring stuff appears again and again.
I've yet to meet a client who regretted having good backups.
I've met plenty who regretted not having them.
Having a policy doesn't mean it's being followed.
Owning a security tool doesn't mean it's configured properly. The organisations that tend to do well are the ones asking practical questions:
- Would we detect suspicious activity?
- Could we recover from an incident tomorrow?
- Do we know who has access to our core systems?
- Are we confident a fraudulent payment request would be challenged?
Those conversations usually tell you far more than a compliance report.
My takeaway
The biggest lesson I took from this report is surprisingly simple.
Cyber security doesn't always fail because we're missing cutting-edge technology.
It often fails because small gaps are allowed to build up over time:
- An account that's never reviewed
- A security policy that's slowly drifted
- A Microsoft 365 tenant that hasn't had a proper health check in years
- A backup that nobody has tested
One small issue rarely causes a breach.
A collection of small issues often does.
So while the industry talks about AI, quantum computing and the next generation of threats, I'll keep encouraging organisations to focus on the fundamentals.
Because in my experience, the businesses that consistently get cyber security right aren't necessarily the ones spending the most money.
They're usually the ones doing the basics consistently, month after month, year after year.
And honestly, that's still where the biggest security wins are found.



