How Can Businesses Protect Themselves From AI Threats?
Businesses can protect themselves from AI threats by strengthening existing cybersecurity controls, improving staff awareness and by using select AI tools. AI has made phishing, impersonation and social engineering attacks much more convincing, so it is important businesses focus on how they can improve their posture against AI threats.
What AI Threats Should Businesses Be Aware Of?
Businesses should be aware that cyber criminals can use AI to their advantage to create more convincing attacks and make them much harder to spot. Below are some of the common threats businesses will see more of due to AI.
AI Powered Phishing:
AI has the ability to create extremely convincing phishing copy in seconds. This is because AI can pull vast amounts of data on businesses which attackers can use to personalise their message further. The more personal the message, the more likely it is to be clicked.
Make sure to double check before opening any links sent in email and ensure you’re dealing with the person you think you are. It is no longer as easy to spot the common errors attackers made such as poor spelling.

Shadow AI:
Shadow AI is when employees use AI (Artificial Intelligence) tools without the knowledge or approval from their IT team or directors. This creates the risk of potential data leak and cyber related threats.
An employee might sign up for an AI writing tool, transcription service or productivity agent because it makes their job easier. The problem is that the business may have no idea what data is being shared, who can access it or whether the service meets its security requirements. Many AI services are open, meaning the data you input is used to train the model. It is imperative to not put business data into it if that is the case.
As AI becomes more accessible, knowing which tools are actually being used across your business is becoming an important part of managing cyber risk.
AI Assisted Cyber Attacks:
Cyber criminals are almost certainly using AI to enhance pre-existing tactics and techniques in finding victims and methods to breach systems. As AI becomes more accessible, we can only see this increasing too. It is therefore important for businesses to make sure that their systems reflect best practices found in cyber security frameworks such as Cyber Essentials.
How Can You Protect Your Business From AI-Powered Attacks?
Businesses can protect themselves from AI powered attacks by following best practice guidelines such as Cyber Essentials to ensure that the companies cybersecurity is sufficient. Below are some common areas found in the Cyber Essentials framework which businesses should be following.
Multi Factor Authentication (MFA):
Multi Factor Authentication (MFA) adds a further layer of protection at the log in stage. This is important if someone were to gain a password for one of your employees accounts. We are also commonly seeing passkeys being used as an alternative verification method, with Microsoft choosing this to be the default as of September 2026. One thing which is very important and overlooked is not using the same password for multiple sites.

Microsoft 365 Security Controls:
If your business uses Microsoft 365, there are multiple ways to use built in features which will help protect your business from AI threats. Microsoft Entra ID provides controls for managing identities and individual user access whilst Microsoft Defender can help respond to threats if they do come in.
Protect your Email with SPF, DKIM and DMARC:
Email authentication protocols such as SPF, DKIM and DMARC can help prevent criminals from successfully impersonating your domain. They won’t stop every phishing email from reaching your employees, but they can make it harder for attackers to send fraudulent messages that appear to come directly from your business.
Use Conditional Access and Identity Protection:
Conditional access policies can help control when and how users are allowed to access business systems. You can use factors such as the user’s identity, device, location and risk level to determine whether access should be allowed or additional verification should be required. This becomes particularly useful if an attacker manages to obtain valid credentials. Instead of treating a correct username and password as enough, businesses can put additional checks around access to sensitive systems and information.

AI Security Checklist for Businesses:
☐ Know which AI tools employees are using:
Keep track of the AI applications being used across your business. Unapproved tools can create security and data protection risks. This is known as Shadow AI.
☐ Create an acceptable-use policy
Set clear rules around which AI tools employees can use, what they can use them for and what information must not be entered into them.
☐ Keep sensitive information out of unapproved AI tools
Employees should never enter passwords, customer information, confidential documents or commercially sensitive data into an AI tool unless the business has assessed and approved its use.
☐ Enable MFA across business accounts
Protect business accounts with multi-factor authentication and consider phishing-resistant authentication for higher-risk users and systems.
☐ Review your Microsoft 365 security settings
Check that the security features included with your Microsoft 365 subscription are configured appropriately for your business rather than relying on the default settings.
☐ Configure SPF, DKIM and DMARC
Use email authentication to make it harder for attackers to impersonate your business domain.
☐ Review permissions and third-party AI integrations
Check which AI services have access to business data, Microsoft 365 accounts or other systems, and remove access that is no longer required.
☐ Have a process for reporting suspected AI-related security incidents
Make it easy for employees to report suspicious emails, unusual AI tool activity or accidental data sharing. The sooner a potential incident is reported, the sooner it can be investigated.
How Three Cherries Can Help With AI Cybersecurity
At Three Cherries, we have been helping businesses with cybersecurity for over 25 years. Although the sector is changing, fast, the principles are still the same. If your business needs any support with Cybersecurity in the AI era, get in touch! At Three Cherries, we take the gamble out of business technology.
CALL THE IT EXPERTS
SPEAK TO US TODAY
Contact our friendly and knowledgeable team today for IT support in Bristol and the South West.
