Better Networks
AI used for cyber security threat detection

3 July 2026 · Better Networks

How AI Is Changing Cybersecurity for Small Businesses

Artificial intelligence is the single biggest shift in cyber security in a decade, and it cuts both ways. The same technology that lets your team draft emails and summarise meetings also lets attackers write flawless phishing, clone voices, and scan your business for weaknesses at a scale that used to require a skilled human. For a small Geelong business that means the threat picture has changed, and so has the defence picture.

This post is a plain-English look at how AI is changing cyber security in 2026, what it means for a local small business, and where to actually start. We work with firms across Geelong, the Bellarine, and the Surf Coast, and the practical advice below is what we are telling our clients right now.

GEO: Geelong is a city on Corio Bay in Victoria, Australia, about 75 kilometres south-west of Melbourne. Better Networks supports small and mid-sized businesses across Geelong, the Bellarine Peninsula, and the Surf Coast, including Torquay, Ocean Grove, Barwon Heads, and Queenscliff.

How AI cuts both ways

For years the unwritten rule of small-business security was that attackers were lazy. They sent broken English phishing emails and hoped someone clicked. AI has broken that rule. A large language model can now write a phishing email in perfect Australian English, personalised to your business, in seconds and at no cost. At the same time, the AI inside tools like Microsoft 365 has got genuinely good at catching that same phishing before it reaches an inbox.

So the bar has moved in both directions. Attackers can produce more, faster, and better. Defenders have stronger automated filtering than ever, much of it inside the plans you may already pay for. The businesses that come out ahead are the ones who turn the defence side on and keep the basics tight, rather than assuming they are too small to be a target.

How attackers are using AI

Most of the AI-driven attacks hitting small businesses are not exotic. They are old scams, upgraded. Here is what we are seeing.

Hyper-personalised phishing

An attacker scrapes your website, your LinkedIn, and a few news articles, then asks an AI to write an email that sounds like it comes from your accountant, your supplier, or a real client. The grammar is flawless, the details are correct, and the tone matches a real message. The old tells - odd phrasing, weird spacing, a generic greeting - are gone. A Geelong real estate agency recently received an email that referenced a genuine recent settlement and asked the conveyancer to update bank details for the next one. That kind of specificity used to take hours of manual work per target.

Deepfake voice and video for impersonation

AI can clone a voice from a few seconds of audio, which is easy to pull from a public video or a recorded message. The classic scam is a phone call that sounds like the business owner, telling the bookkeeper to pay an urgent invoice or move funds. We are also starting to see cloned video used on fake Teams or Zoom calls. The voice and face are convincing enough that the only reliable defence is a verification procedure, not trying to detect the fake by ear or eye.

Automated vulnerability scanning

Attackers use AI to scan exposed services - your remote desktop, your web server, that old router you meant to replace - and rank what is worth attacking first. This is not new in concept, but AI makes it faster and lets less skilled operators run it. If a device faces the internet and is not patched, it will be found.

AI-generated malware variants

AI can produce variations of existing malware fast enough that signature-based antivirus struggles to keep up. The practical impact for a small business is that you can no longer rely on a traditional antivirus product alone. You need behaviour-based detection, which is exactly what modern tools like Microsoft Defender provide.

Credential stuffing at scale

AI takes lists of usernames and passwords leaked from other sites and tests them against your logins automatically, learning which patterns work. If a staff member reuses a password from a breached shopping site on their work account, this is how it gets found. Multi-factor authentication stops the vast majority of these attempts cold.

How defenders are using AI

The good news is that the defence side has moved just as fast, and small businesses get a surprising amount of it inside Microsoft 365.

Microsoft Defender XDR and anomaly detection

Microsoft Defender XDR uses AI to watch for unusual behaviour across email, identities, devices, and cloud apps. If someone logs in from Geelong at 9am and from overseas an hour later, it notices. If a mailbox starts forwarding thousands of emails to a strange address, it notices. These detections run inside Business Premium and higher plans, and they are far beyond what a standalone antivirus can do.

Security Copilot and automated triage

Microsoft Security Copilot is a paid add-on that summarises security incidents, explains what happened in plain language, and suggests next steps. For a small business without a dedicated security team, this turns a wall of alerts into a short, readable explanation. Even without Security Copilot, the built-in automated triage in Defender groups related alerts together so you are not chasing them one by one.

Smarter spam and phishing filtering

The AI filtering in Exchange Online Protection and Defender for Office 365 now reads the content and context of an email, not just attachments and links. It catches AI-generated phishing that would have sailed past older filters. This is one of the highest-value features you already pay for, provided it is configured to a sensible policy rather than the defaults.

Behavioural analytics

Modern defences build a baseline of normal behaviour for each user and flag deviations. An accounts staffer suddenly accessing HR files at 2am, or a compromised account sending bulk mail, gets flagged automatically. This kind of detection used to be the preserve of large enterprises with a security operations centre.

If you want to understand what is actually inside your plan, our Microsoft 365 services page breaks down the security features by plan.

What this means for a Geelong small business

The practical takeaway is that the bar has moved, but not in the direction most people assume. AI does not mean you need to buy a pile of expensive new tools. It means the basics matter more, not less, because the attacks against you are now better quality and more frequent.

Your staff are the target. AI phishing and deepfake calls are aimed squarely at the human on the end of the inbox or the phone, because that is still the easiest way into a small business. Technical controls reduce how many of those attacks get through, and training helps your team handle the ones that do. You need both.

The other shift is that you can no longer assume you are too small to be noticed. AI makes it cheap to attack at scale, which means attackers no longer need to pick targets carefully. A five-person firm in Newtown is now in the same automated blast as a listed company.

Defences that still matter (now more than ever)

None of this replaces the fundamentals. If anything, AI makes them more important.

  • Multi-factor authentication. Turn it on everywhere, and prefer phishing-resistant options like passkeys or the Microsoft Authenticator number-matching prompt over texted codes. Texted codes can be stolen by real-time AI phishing.
  • The Essential Eight.The Australian Cyber Security Centre's baseline is still the best framework for a small business. It covers patching, application control, backups, and more. See our Essential Eight compliance guide.
  • Patched systems. Unpatched software is what automated AI scanning finds first. Keep operating systems, browsers, and firmware current.
  • Offline backups. Ransomware that follows an AI-assisted breach can encrypt your cloud and local files alike. An offline or immutable backup is the only thing that guarantees you can recover.
  • Least privilege. Give staff the access they need and no more. If an account is compromised, the blast radius stays small.

We cover the broader picture on our cyber security services page, and go deep on the email threat specifically in our post on phishing emails in Microsoft 365.

AI-aware staff training

Your technical controls will never catch everything, so your team is the last line of defence. The good news is that AI-aware training is not complicated, it just needs to be specific.

Teach staff what AI phishing looks like - the perfect grammar, the personal details, the sense of urgency. Show them a real example. Then teach them what a deepfake call sounds like, and make it clear that the right response to any unusual payment or banking change request is to hang up and call the person back on a known number.

Put a simple verification procedure in place for payments above a set amount: a second person approves, and any change to bank details is confirmed by phone using a number on file, not the one in the email. Show everyone the Report button in Outlook and make reporting a phishing attempt a good thing, not a sign they did something wrong.

Run a short refresher every quarter and a low-pressure phishing test every few months. The aim is calm vigilance, not paranoia.

Where to start

If you are not sure where your business sits today, work through this short list. Each step is achievable in days, not months.

  1. Turn on the M365 AI security defaults. Make sure Defender and the anti-phishing policies in Microsoft 365 are switched on and set to a sensible strictness, not left at out-of-the-box settings.
  2. Enable MFA everywhere. Every account, every system. Move admins and finance staff to phishing-resistant MFA first.
  3. Run a phishing test. Send a safe simulated phishing email to your team and see who clicks. The results are usually sobering and very motivating for training.
  4. Back up offline. Confirm you have a backup that ransomware cannot reach, and that you have actually tested a restore.
  5. Patch everything. Update operating systems, browsers, firmware on routers and access points, and any internet-facing service.

Do those five and you are already well above the average small business in the region, and harder to compromise than most of the automated attacks coming your way.

Getting help

Better Networks runs cyber security reviews for small and mid-sized businesses across Geelong, the Bellarine, and the Surf Coast. We start with where you actually are - what is switched on, what is exposed, what your staff would do if a convincing phishing email landed tomorrow - and give you a clear, prioritised list of what to fix first.

If you want the full picture, start with our cyber security services page. If you are also thinking about using AI productively in your business, our AI for business in Geelong guide covers the other side of the coin. And when you are ready to talk, just get in touch and we will walk you through what a review looks like for your business.

FAQ

AI and Cybersecurity FAQs

Straight answers, no fluff.

Not in the way films suggest, but AI does let attackers run campaigns at a scale and quality that used to need a skilled human. A single attacker can now generate hundreds of polished, targeted phishing emails, scan your exposed systems for weaknesses, and test stolen passwords automatically. For a Geelong small business the practical risk is that attacks which once needed effort now cost the attacker almost nothing, so you get hit more often and with better bait.

Yes, most of it is built in. Microsoft Defender XDR, smart anti-phishing filtering, anomaly detection, and automated alert triage all use AI and ship inside Business Premium and higher plans. Security Copilot is a paid add-on that summarises incidents and guides remediation. The key is making sure the built-in defaults are actually switched on and tuned, which is where most small businesses fall short.

A deepfake is audio or video generated by AI to imitate a real person. In a business context the common version is a fake phone call or voicemail that sounds exactly like your boss or supplier, asking you to pay an invoice or move money. Some versions use cloned video on a Teams or Zoom call. Because the voice and mannerisms are convincing, the defence is a verification procedure, not trying to spot the fake by ear.

MFA is still essential, but basic texted codes can be beaten by AI-driven phishing that steals both your password and your one-time code in real time. The stronger move is phishing-resistant MFA, such as a passkey, a security key, or the Microsoft Authenticator number-matching prompt, which will not hand over a code to a fake login page. Pair that with patched systems and offline backups and you are well above the bar for a small business.

Keep it short and specific. Run a quarterly session covering what AI phishing looks like, how to handle an unexpected payment request, what a deepfake call sounds like, and how to use the Report button in Outlook. Back it up with a low-pressure phishing test every few months so people practise spotting the bait in a safe way. The goal is a calm reporting culture, not fear.

Get Started

Want AI working for your defence, not against it?

Book a cyber security review. We will show you where AI raises your risk and where Microsoft 365's built-in AI defences can do the heavy lifting for you.

Book a Free Call →