(And Why the Stakes Are Higher Than You Think)
There's a question we hear from business owners more and more: "We've trained our staff to spot dodgy emails. Aren't we covered?"
The honest answer is no. Not anymore.
AI-powered phishing is harder to detect because attackers can now generate convincing, personalised messages at scale, without the spelling mistakes, odd phrasing or generic requests that staff were trained to spot.
For UK businesses, that means old awareness advice is no longer enough on its own.
According to the UK Government's Cyber Security Breaches Survey 2025, phishing remains the most common and disruptive type of attack experienced by UK businesses, affecting 85% of those who reported a breach. The issue is not just volume. It is believability.
This post explains what AI has changed, why it matters for UK SMEs, and the practical controls that reduce risk right now.
Key takeaways
- AI phishing removes many of the old warning signs staff were trained to spot.
- UK SMEs are attractive targets because they often have lean teams, valuable data, and weaker verification processes.
- Staff awareness still matters, but it should support stronger controls, not replace them.
- Multi-factor authentication, better email security, and out-of-band verification are the highest-priority steps.
- A baseline such as Cyber Essentials Plus helps, but layered protection matters more.
Why Is AI-Powered Phishing Harder to Detect?
Old-school phishing was a numbers game. Criminals sent millions of generic emails and waited for someone to click. The emails were often riddled with typos, used clunky language and made vague threats about your account being suspended. Spotting them was a skill, but not a particularly difficult one.
AI has fundamentally changed the economics and the quality of these attacks.
It now costs almost nothing to run a sophisticated campaign
AI-based phishing tools are available on criminal marketplaces for as little as £60. For that, an attacker gets access to tools that can scrape your company's LinkedIn page, your website, your team's social media profiles and any previous data breaches that exposed email addresses or internal information. It then uses all of that to generate highly personalised, contextually accurate messages at scale.
The result is an email that might reference your actual job title, mention a real colleague by name, mirror the writing style of someone you trust, and arrive at exactly the right moment to seem plausible.
The click rates tell the whole story
Research shows that AI-generated phishing emails have a 60% higher click rate than traditionally crafted attacks. Some estimates put the click-through rate for AI-crafted messages at five to ten times higher than conventional phishing.
That's not a marginal improvement for attackers. That's a transformation.
Deepfakes are now part of the toolkit
It doesn't stop at email. Voice cloning technology can now replicate the voice of your CEO or finance director convincingly enough to instruct a member of staff to make an urgent payment. Video deepfakes, while still emerging, are already being used in investment fraud. The NCSC has flagged AI-enabled attacks as one of the most significant evolving threats facing UK organisations.
The uncomfortable truth is that your staff cannot be expected to catch what they cannot see. A perfectly written email from what appears to be your managing director, referencing a real project, asking for a real action, is not something a human can reliably detect through vigilance alone.
Why Are UK SMEs a Prime Target for AI Phishing?
There's a common misconception that cybercriminals are primarily after large enterprises. The reality is more uncomfortable for smaller businesses.
SMEs are attractive targets precisely because they tend to have less robust security than larger organisations, smaller IT teams (or none at all) and fewer formal processes around things like payment verification. At the same time, they often hold valuable data, process financial transactions and have connections to larger supply chains that attackers want to exploit.
The numbers back this up. According to the UK Government's Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cyber breach or attack in the past year. That equates to approximately 612,000 businesses. Of those affected, phishing was the most common entry point by a significant margin.
The financial impact is real and immediate. The average cost of the most disruptive breach for a UK business was £1,600, but that figure masks far higher costs for businesses that suffer ransomware deployment, data theft or regulatory penalties following a breach. Significant incidents frequently run into six figures.
And here's the part that should concern every business owner: AI has eliminated the skills barrier for attackers. You no longer need technical expertise to run a sophisticated phishing campaign. You need less than £60 and an internet connection. That means the volume of attacks targeting SMEs is only going to increase.
What Warning Signs No Longer Work Against AI Phishing?
Most staff awareness training is built around a set of red flags that made sense five years ago. The problem is that AI has systematically eliminated every one of them.
|
Old Warning Sign |
Why It No Longer Applies |
|
Poor spelling and grammar |
AI generates flawless, natural-sounding prose |
|
Generic greeting ("Dear Customer") |
AI personalises with your name, role, and company |
|
Suspicious sender address |
Attackers spoof legitimate domains convincingly |
|
Vague, implausible requests |
AI researches your business to make requests contextually accurate |
|
Odd tone or phrasing |
AI mirrors the writing style of real colleagues |
|
Unexpected urgency |
Still present, but now wrapped in plausible context |
This doesn't mean staff training is worthless. It means training alone is no longer sufficient as a primary defence. Relying on your team to catch AI-generated phishing is like asking someone to spot a counterfeit banknote without any equipment. Even experts get it wrong.
What this means in practice: a member of your finance team receives an email that appears to come from your MD, references a real supplier, uses the right tone and asks them to approve a payment before end of business. There is no obvious red flag. Without the right processes and technology in place, that payment gets made.
This is not a hypothetical. It is happening to UK businesses right now.
What Should UK Businesses Do Right Now?
The good news is that this is a solvable problem. You don't need a large IT department or an enterprise security budget. You need the right approach, applied consistently.
If you only do four things this quarter, do these first:
- Enforce MFA across email, cloud platforms, and admin accounts
- Introduce a call-back process for payments and sensitive requests
- Upgrade email protection beyond basic spam filtering
- Review whether your current tools actually give you visibility into suspicious activity
Stop treating staff training as your primary defence
Training still has a role, but it needs to shift from "how to spot a phishing email" to "what to do when you're not sure." The focus should be on building verification habits: a process for confirming unusual requests through a second channel (a phone call, not a reply to the same email), clear escalation paths, and a culture where people feel comfortable questioning something that seems off.
Implement multi-factor authentication everywhere
MFA is one of the most effective controls available and one of the most underused. Enable it on every business account: email, cloud storage, financial platforms, remote access tools. Even if an attacker successfully harvests login credentials through phishing, MFA prevents them from using those credentials to access your systems. The NCSC's guidance on MFA is a useful starting point if you haven't already deployed it.
Deploy email security that uses behavioural analysis
Standard email filters look for known malicious links and attachments. AI-generated phishing often contains neither. What you need is email security that analyses behavioural signals: does this email match the sender's usual patterns? Is the request consistent with previous communications? Does the sending infrastructure match the claimed domain?
This type of analysis catches what human eyes miss.
Build verification processes for financial requests
Any request involving money, data transfers, or access to sensitive systems should require out-of-band verification above a defined threshold. This is the single most effective defence against business email compromise. That means picking up the phone and calling the person directly (using a number you already have, not one in the email) before acting. This single process prevents the majority of business email compromise attacks.
Get visibility across your security posture
One of the most common problems we see with SMEs is that they have security tools in place but no visibility into whether those tools are actually working. You need to know what's happening across your systems, where your vulnerabilities are, and whether your existing controls are doing their job.
This is where having a unified security operations platform makes a genuine difference. Rather than relying on disconnected tools that don't talk to each other, a single platform gives you a clear picture of your security posture and flags issues before they become incidents.
Consider Cyber Essentials Plus certification
Cyber Essentials Plus is the UK government-backed scheme that verifies your organisation has the fundamental controls in place to defend against common cyber threats. It's not a silver bullet, but it establishes a verified baseline and demonstrates to clients, partners, and insurers that you take security seriously. For many SMEs, it's the most practical starting point.
The Bottom Line for UK Businesses
AI has not just made phishing more frequent. It has made it fundamentally harder to detect, cheaper to execute and more targeted than ever before. The defences that worked in 2019 are not adequate for 2026.
The businesses that will come through this period without a costly incident are not necessarily the ones with the biggest budgets. They're the ones that have moved beyond relying on human vigilance and put the right technology and processes in place to catch what people can't.
If you're not sure whether your current security setup is equipped to handle AI-powered threats, that uncertainty is worth addressing. The cost of a review is a fraction of the cost of a breach.
We work with UK businesses to improve visibility, reduce response gaps, and put practical controls in place before phishing turns into a larger incident.
If you want a clearer view of where your exposure sits today, speak to the CybaVerse team and we'll show you what protection should look like for a business your size.