01 / SPEED
AI is reducing the time and specialist knowledge needed to exploit a stolen credential.
Anthropic's September threat report describes disrupted operations in which attackers used AI across reconnaissance, exploitation, data processing, and credential abuse. The report says some actors moved from a single working token to much broader access within hours. These cases are not typical small-business incidents, but they show why an exposed password, API key, or active session can become more consequential more quickly than it once did.
02 / EXPOSURE
The weakest credential may sit outside the system an owner thinks of as critical.
The report includes stolen keys found in code repositories, applications, integrations, and vendor environments, plus cases where access to a software provider exposed downstream customers. Small companies often accumulate similar access quietly: a former employee's account, a shared administrator login, a connector installed for a trial, or an automation key nobody remembers creating. The risk is not only whether a tool is secure. It is how far one credential can travel across the business.
03 / VERIFICATION
Basic operating controls still interrupt many high-cost outcomes.
FTC guidance for small businesses recommends unique passwords, a password manager, current software, staff phishing awareness, email authentication, and independent verification of unusual requests. It also advises confirming sensitive requests through a known phone number rather than contact information inside the message. Those steps sound ordinary because they are. Their value is that they force an attacker to defeat more than one path before money, data, or control changes hands.
THE CJC VIEW
Implementation beats experimentation.
Small-business cybersecurity is often framed as a technical program. The first layer is really an operating discipline: know who has access, limit what each credential can do, and slow down unusual decisions involving money or sensitive data.
AI does not make every business an immediate target, and fear is not a useful control. But faster attacker workflows make forgotten access and informal approval habits less forgiving. The right response is a smaller blast radius: fewer standing privileges, fewer shared credentials, shorter-lived keys, and a second channel for consequential approvals.
PRACTICAL NEXT STEP
Run a one-hour access and payment check
- List the five systems that could expose customer data, company email, banking, payroll, or the website if an account were taken over.
- For each system, remove former users, replace shared logins, and confirm that every administrator still needs administrator access.
- Turn on multifactor authentication and store unique credentials in a password manager wherever the system supports it.
- Rotate any API key or integration token that is old, ownerless, broadly shared, or stored in a document, message, or code repository.
- Set one rule for unusual payments or access changes: verify the request with a second person through a known phone number or separate channel before acting.
AI is increasing the speed available to both operators and attackers. A small business does not need a large security department to respond. It needs deliberate access, visible ownership, and a reliable pause before the decisions that are hardest to reverse.
Sources and further reading
- Detecting and countering misuse of AI: September 2026 — Anthropic
- Cybersecurity for Small Business — Federal Trade Commission
- Small Business Cybersecurity: Non-Employer Firms — National Institute of Standards and Technology