SME CYBER THREAT INTEL: AI-Driven Threats Force One Third of Global Organisations to Overhaul Security Architecture
April 28, 2025Helping Keep Small Business CYBERSafe!
Gibraltar: Monday 28 April 2025 at 10:00 CET
SME CYBER THREAT INTEL:Â AI-Driven Threats Force One Third of Global Organisations to Overhaul Security Architecture, Netwrix Report Finds
By: Iain Fraser – Cybersecurity Journalist
SMECYBERInsights – The UK Small Business Cybersecurity Network
#SMECyberInsights #SMECyberSecurity #SMECyberAwareness #CyberSafe #SME #SmallBusiness
Small UK businesses urged to prepare for evolving AI security landscape as financial impacts of breaches nearly double
A new global cybersecurity study has revealed that more than one in three organisations worldwide (37%) have been forced to adjust their security approaches specifically to combat emerging AI-driven threats. The 2025 Cybersecurity Trends Report, released yesterday by security provider Netwrix, surveyed 2,150 IT and security professionals across 121 countries and paints a concerning picture of how artificial intelligence is reshaping the cybersecurity landscape.
AI Adoption Widespread Despite Security Concerns
The report found that 60% of organisations are already implementing AI within their IT infrastructure, with another 30% actively considering deployment. However, this technological advancement comes with significant security challenges:
* 37% report that new AI-driven threats have forced security architecture changes
* 30% face an expanded attack surface due to business users adopting AI tools
* 29% struggle with compliance requirements around data security in AI systems
For UK small businesses, these findings signal an urgent need to evaluate how AI usage—both internally and by threat actors—impacts their security posture.
Financial Impact of Breaches Increasing Dramatically
Perhaps most concerning for resource-constrained SMEs is the report’s finding that financial damage from cyberattacks has increased substantially. Three-quarters (75%) of organisations reported financial impacts from security incidents—up from 60% in 2024. Even more alarming, the number of organisations suffering damages of £156,000 (approximately $200,000) or more has nearly doubled from 7% to 13% in just one year. Identity-Based Attacks on the Rise Jeff Warren, Chief Product Officer at Netwrix, highlighted that identity-driven attacks are becoming increasingly sophisticated, with new methods including:
* Advanced techniques to bypass multi-factor authentication
* Abuse of service accounts and machine-to-machine tokens
* AI-powered deepfake phishing using convincing voice and video
* Creation of synthetic identities at scale
These threats pose particular challenges for small businesses that may lack dedicated security resources to detect and respond to such advanced tactics.
Key Takeaways for UK Small Businesses
Reassess your security architecture if you’re adopting AI tools or if your industry is being targeted by AI-powered threats
Implement Zero Trust principles by treating all interactions with AI systems as potentially malicious and enforcing strict authentication
* Consider the full lifecycle of data used in AI systems, especially when it contains sensitive business information
* Budget for increased security spending as the financial impacts of breaches continue to rise
* Pay special attention to identity security, including service accounts and access tokens that might be overlooked
With the report showing that organisations experiencing “no impact” from security incidents has dropped from 45% in 2023 to just 36% in 2025, UK small businesses should take this as a clear signal that proactive security measures are more essential than ever.
Dirk Schrader, VP of security research at Netwrix, advises that “security teams should apply Zero Trust principles in the world of AI: assume every interaction with the AI system, internal or external, could be malicious, and enforce strict authentication, least privilege access and continuous monitoring.”
The full Netwrix 2025 Cybersecurity Trends Report can be downloaded from the company’s website.
SME Cyber Insights provides independent cybersecurity guidance for UK small and medium businesses. For more advice on protecting your business from emerging threats, visit our resources section. Retry Claude can make mistakes. Please double-check responses.
UK Small Business Owner? Join CYBERInsights Free Now! & Access the SME Cyber Forum – Read, Learn, Engage, Share …
The Latest SME Cybersecurity News, Threat Intelligence & Analysis, Timely Scam Alerts, Best-practice Compliance, Mitigation & Resources specifically curated for UK Based SMEs in a Single Weekly Email direct to your Inbox or Smart Device together with Unrestricted Free Access to our entire SME Cyber Knowledge & Tutorial Library.
What is a VPN & Does my SME Need one? A VPN is a Virtual Private Network a method of securing your communications credentials. When it comes to Small and Medium-sized enterprises (SMEs), the choice of VPNs can significantly impact the security and efficiency of their operations.
The NordVPN service allows you to connect to 5600+ servers in 60+ countries. It secures your Internet data with military-grade encryption, ensures your web activity remains private and helps bypass geographic content restrictions online.  Join NordVPN Today and Save up to 73% and Get 3 months Extra Free Rude Not to …!















