Cybersecurity is no longer just about keeping a virus off a laptop. It is about protecting the identities, conversations, cloud services and suppliers your business relies on every day. Attackers do not always need to break through a firewall — sometimes they only need someone to trust the wrong message.
Three developments deserve particular attention: AI can make deception easier to scale, stolen identities can open the door to legitimate services, and ransomware can become a data-theft crisis as well as an outage. The good news? Consistent, well-tested fundamentals still make a meaningful difference.
Slow down unusual requests. Protect accounts as carefully as devices. Know what you expose to the internet. And test your recovery before you need it.
01 / AI-assisted scams are harder to spot
Polished wording is no longer a reliable sign that a message is genuine. Generative AI can help attackers write convincing emails, personalise their approach and imitate a familiar voice. The UK NCSC’s May 2025 assessment projects that AI will enhance existing attack techniques through 2027, including reconnaissance and social engineering. That is an assessment of likely developments, not a claim that every scam uses AI.
Watch for: an urgent payment request, changed banking details, an unexpected QR code or a supposed executive asking you to bypass normal checks. A familiar voice or video image is not enough to authorise a sensitive action.
What to do: verify the request through an independent channel. Call the person on a number already in your records — not the number supplied in the suspicious message. Use a second approver for significant payments and make it acceptable for staff to pause and check.
02 / Identity is part of your security perimeter
A stolen password, session cookie or approved sign-in prompt can give an attacker access to email and cloud applications without an obvious malware infection. Ordinary multi-factor authentication is valuable, but not all MFA methods resist phishing equally. Passkeys and FIDO2 security keys offer stronger resistance to phishing where the service supports them.
Watch for: MFA prompts you did not initiate, unfamiliar sign-ins, new mailbox forwarding rules, unexpected password resets or a cloud application asking for more access than it needs.
What to do: prioritise phishing-resistant MFA for administrators, email and finance accounts. Use unique passwords where passwords are still needed, remove dormant accounts, keep administrative access separate and review app permissions. If an account is compromised, password changes alone may not be enough; your IT team should also review active sessions, tokens and mailbox rules.
03 / Ransomware is also a data problem
Recovery is about more than unlocking files. An attacker may copy sensitive information before disrupting systems and then threaten to publish it. A usable backup can help restore operations, but it cannot undo stolen data. CISA’s StopRansomware Guide is a useful starting point for prevention and response planning.
Watch for: security tools being disabled, unusual administrator activity, unexplained bulk downloads, backup failures or unexpected changes to recovery settings.
What to do: keep offline or appropriately configured immutable backups, separate backup administration from everyday accounts and test restoration. Segment critical systems, monitor endpoints and rehearse an incident plan with named decision-makers. Make sure you know which systems must come back first and how long recovery actually takes.
04 / Exposed systems need risk-based patching
Remote-access gateways, firewalls, web applications and other internet-facing services deserve particular attention. Attackers can exploit known weaknesses when fixes have not been applied. A long patch list is not a strategy: prioritise vulnerabilities that are being exploited, systems exposed to the internet and services whose compromise would have the greatest impact.
Watch for: unsupported equipment, forgotten remote-access services, missed vendor advisories and systems that no one clearly owns.
What to do: maintain an asset inventory and use CISA’s Known Exploited Vulnerabilities Catalog alongside vendor guidance and your own risk assessment. Verify that fixes are actually installed. Where a patch cannot be applied immediately, evaluate vendor-recommended mitigations and restrict exposure. A vulnerability scan is useful, but it is not a guarantee that a system is secure.
05 / Suppliers and cloud access extend your risk
Your security also depends on who can reach your systems. A supplier account with excessive permissions, a forgotten integration or a publicly shared folder can create a route to sensitive information.
Watch for: shared administrator logins, access that remains active after a project ends, broad permissions granted to an integration and supplier bank-detail changes that arrive only by email.
What to do: grant only the access required, use individual accounts, review permissions regularly and agree how suppliers will report security incidents. Know where your important data lives and who is responsible for protecting it. For South African organisations, include POPIA obligations in your incident plan and seek appropriate legal guidance about notification duties; a security checklist is not a compliance certificate.
06 / AI adoption needs sensible data boundaries
AI tools can improve productivity, but staff need clear rules about the information they may submit. Customer records, confidential contracts and credentials should not be pasted into unapproved tools. AI-generated answers and documents also need human review: convincing output can still be wrong.
Watch for: staff using personal AI accounts for company data, browser extensions requesting broad access and assistants connected to more business systems than necessary.
What to do: approve tools deliberately, understand their retention and training settings, limit integrations and require human approval for consequential actions. Treat instructions inside retrieved documents or web pages as untrusted content, not permission for an AI assistant to take action.
Start with the next five working days
- Day 1: confirm who owns security decisions and how staff should report a suspicious message.
- Day 2: review privileged accounts, MFA coverage and payment-verification procedures.
- Day 3: check internet-facing systems and urgent vendor advisories.
- Day 4: restore a sample from backup and record what worked — and what did not.
- Day 5: run a short scenario: a finance mailbox is compromised. Who contains it, who communicates and what evidence must be preserved?
If you suspect an incident, contact your IT or security team through a trusted channel, follow your response plan and preserve evidence. Avoid uncoordinated wiping or recovery that could destroy information needed to understand the incident.
You do not need to chase every headline. Focus on the controls that protect your people, limit an attacker’s reach and help your business recover with confidence.
Explore Sautech’s vulnerability and penetration testing services →Sources & further reading
This briefing combines practical guidance with the references below. The NCSC source is a published forecast; the CISA resources are maintained guidance. This is not a real-time threat feed, a claim of original research or a guarantee of security.
- UK NCSC: Impact of AI on cyber threat from now to 2027 — assessment published May 2025.
- CISA: #StopRansomware Guide — prevention and response guidance.
- CISA: Known Exploited Vulnerabilities Catalog — evidence of exploitation to inform prioritisation.
General information only. Your organisation’s technical, operational and legal requirements need an assessment of its own circumstances. External links open in a new tab.
