Artificial intelligence is the single biggest shift in cyber security in a decade, and it cuts both ways. The same technology that lets your team draft emails and summarise meetings also lets attackers write flawless phishing, clone voices, and scan your business for weaknesses at a scale that used to require a skilled human. For a small Geelong business that means the threat picture has changed, and so has the defence picture.
This post is a plain-English look at how AI is changing cyber security in 2026, what it means for a local small business, and where to actually start. We work with firms across Geelong, the Bellarine, and the Surf Coast, and the practical advice below is what we are telling our clients right now.
GEO: Geelong is a city on Corio Bay in Victoria, Australia, about 75 kilometres south-west of Melbourne. Better Networks supports small and mid-sized businesses across Geelong, the Bellarine Peninsula, and the Surf Coast, including Torquay, Ocean Grove, Barwon Heads, and Queenscliff.
How AI cuts both ways
For years the unwritten rule of small-business security was that attackers were lazy. They sent broken English phishing emails and hoped someone clicked. AI has broken that rule. A large language model can now write a phishing email in perfect Australian English, personalised to your business, in seconds and at no cost. At the same time, the AI inside tools like Microsoft 365 has got genuinely good at catching that same phishing before it reaches an inbox.
So the bar has moved in both directions. Attackers can produce more, faster, and better. Defenders have stronger automated filtering than ever, much of it inside the plans you may already pay for. The businesses that come out ahead are the ones who turn the defence side on and keep the basics tight, rather than assuming they are too small to be a target.
How attackers are using AI
Most of the AI-driven attacks hitting small businesses are not exotic. They are old scams, upgraded. Here is what we are seeing.
Hyper-personalised phishing
An attacker scrapes your website, your LinkedIn, and a few news articles, then asks an AI to write an email that sounds like it comes from your accountant, your supplier, or a real client. The grammar is flawless, the details are correct, and the tone matches a real message. The old tells - odd phrasing, weird spacing, a generic greeting - are gone. A Geelong real estate agency recently received an email that referenced a genuine recent settlement and asked the conveyancer to update bank details for the next one. That kind of specificity used to take hours of manual work per target.
Deepfake voice and video for impersonation
AI can clone a voice from a few seconds of audio, which is easy to pull from a public video or a recorded message. The classic scam is a phone call that sounds like the business owner, telling the bookkeeper to pay an urgent invoice or move funds. We are also starting to see cloned video used on fake Teams or Zoom calls. The voice and face are convincing enough that the only reliable defence is a verification procedure, not trying to detect the fake by ear or eye.
Automated vulnerability scanning
Attackers use AI to scan exposed services - your remote desktop, your web server, that old router you meant to replace - and rank what is worth attacking first. This is not new in concept, but AI makes it faster and lets less skilled operators run it. If a device faces the internet and is not patched, it will be found.
AI-generated malware variants
AI can produce variations of existing malware fast enough that signature-based antivirus struggles to keep up. The practical impact for a small business is that you can no longer rely on a traditional antivirus product alone. You need behaviour-based detection, which is exactly what modern tools like Microsoft Defender provide.
Credential stuffing at scale
AI takes lists of usernames and passwords leaked from other sites and tests them against your logins automatically, learning which patterns work. If a staff member reuses a password from a breached shopping site on their work account, this is how it gets found. Multi-factor authentication stops the vast majority of these attempts cold.
How defenders are using AI
The good news is that the defence side has moved just as fast, and small businesses get a surprising amount of it inside Microsoft 365.
Microsoft Defender XDR and anomaly detection
Microsoft Defender XDR uses AI to watch for unusual behaviour across email, identities, devices, and cloud apps. If someone logs in from Geelong at 9am and from overseas an hour later, it notices. If a mailbox starts forwarding thousands of emails to a strange address, it notices. These detections run inside Business Premium and higher plans, and they are far beyond what a standalone antivirus can do.
Security Copilot and automated triage
Microsoft Security Copilot is a paid add-on that summarises security incidents, explains what happened in plain language, and suggests next steps. For a small business without a dedicated security team, this turns a wall of alerts into a short, readable explanation. Even without Security Copilot, the built-in automated triage in Defender groups related alerts together so you are not chasing them one by one.
Smarter spam and phishing filtering
The AI filtering in Exchange Online Protection and Defender for Office 365 now reads the content and context of an email, not just attachments and links. It catches AI-generated phishing that would have sailed past older filters. This is one of the highest-value features you already pay for, provided it is configured to a sensible policy rather than the defaults.
Behavioural analytics
Modern defences build a baseline of normal behaviour for each user and flag deviations. An accounts staffer suddenly accessing HR files at 2am, or a compromised account sending bulk mail, gets flagged automatically. This kind of detection used to be the preserve of large enterprises with a security operations centre.
If you want to understand what is actually inside your plan, our Microsoft 365 services page breaks down the security features by plan.
What this means for a Geelong small business
The practical takeaway is that the bar has moved, but not in the direction most people assume. AI does not mean you need to buy a pile of expensive new tools. It means the basics matter more, not less, because the attacks against you are now better quality and more frequent.
Your staff are the target. AI phishing and deepfake calls are aimed squarely at the human on the end of the inbox or the phone, because that is still the easiest way into a small business. Technical controls reduce how many of those attacks get through, and training helps your team handle the ones that do. You need both.
The other shift is that you can no longer assume you are too small to be noticed. AI makes it cheap to attack at scale, which means attackers no longer need to pick targets carefully. A five-person firm in Newtown is now in the same automated blast as a listed company.
Defences that still matter (now more than ever)
None of this replaces the fundamentals. If anything, AI makes them more important.
- Multi-factor authentication. Turn it on everywhere, and prefer phishing-resistant options like passkeys or the Microsoft Authenticator number-matching prompt over texted codes. Texted codes can be stolen by real-time AI phishing.
- The Essential Eight.The Australian Cyber Security Centre's baseline is still the best framework for a small business. It covers patching, application control, backups, and more. See our Essential Eight compliance guide.
- Patched systems. Unpatched software is what automated AI scanning finds first. Keep operating systems, browsers, and firmware current.
- Offline backups. Ransomware that follows an AI-assisted breach can encrypt your cloud and local files alike. An offline or immutable backup is the only thing that guarantees you can recover.
- Least privilege. Give staff the access they need and no more. If an account is compromised, the blast radius stays small.
We cover the broader picture on our cyber security services page, and go deep on the email threat specifically in our post on phishing emails in Microsoft 365.
AI-aware staff training
Your technical controls will never catch everything, so your team is the last line of defence. The good news is that AI-aware training is not complicated, it just needs to be specific.
Teach staff what AI phishing looks like - the perfect grammar, the personal details, the sense of urgency. Show them a real example. Then teach them what a deepfake call sounds like, and make it clear that the right response to any unusual payment or banking change request is to hang up and call the person back on a known number.
Put a simple verification procedure in place for payments above a set amount: a second person approves, and any change to bank details is confirmed by phone using a number on file, not the one in the email. Show everyone the Report button in Outlook and make reporting a phishing attempt a good thing, not a sign they did something wrong.
Run a short refresher every quarter and a low-pressure phishing test every few months. The aim is calm vigilance, not paranoia.
Where to start
If you are not sure where your business sits today, work through this short list. Each step is achievable in days, not months.
- Turn on the M365 AI security defaults. Make sure Defender and the anti-phishing policies in Microsoft 365 are switched on and set to a sensible strictness, not left at out-of-the-box settings.
- Enable MFA everywhere. Every account, every system. Move admins and finance staff to phishing-resistant MFA first.
- Run a phishing test. Send a safe simulated phishing email to your team and see who clicks. The results are usually sobering and very motivating for training.
- Back up offline. Confirm you have a backup that ransomware cannot reach, and that you have actually tested a restore.
- Patch everything. Update operating systems, browsers, firmware on routers and access points, and any internet-facing service.
Do those five and you are already well above the average small business in the region, and harder to compromise than most of the automated attacks coming your way.
Getting help
Better Networks runs cyber security reviews for small and mid-sized businesses across Geelong, the Bellarine, and the Surf Coast. We start with where you actually are - what is switched on, what is exposed, what your staff would do if a convincing phishing email landed tomorrow - and give you a clear, prioritised list of what to fix first.
If you want the full picture, start with our cyber security services page. If you are also thinking about using AI productively in your business, our AI for business in Geelong guide covers the other side of the coin. And when you are ready to talk, just get in touch and we will walk you through what a review looks like for your business.
