On 22 June 2026, the NCSC published what they called an open letter to business leaders, signed jointly with the government’s Economic Security Advisory Service. The message was unusually direct for a government publication: AI is changing the threat landscape faster than most organisations are keeping up with, and businesses that treat cyber security as an IT department problem rather than a board-level concern are increasingly at risk.
For large enterprises, this kind of communication lands in the CISO’s inbox and triggers a review. For small businesses — which make up the vast majority of UK organisations — the same advisory often goes unread because it doesn’t feel like it’s meant for you. Here’s the thing: it is. In fact, small businesses are disproportionately attractive targets precisely because they’re less likely to have formal security processes.
What the NCSC Is Actually Warning About
The core of the advisory isn’t that AI creates entirely new types of attacks. It’s that AI lowers the barrier and accelerates the speed of attacks that already existed. Phishing emails are more convincing because large language models can write fluent, personalised, context-appropriate messages at scale without any of the grammatical tells that used to help people spot them. Vulnerability scanning is faster because AI can identify and prioritise weaknesses across a target’s exposed services in minutes. And social engineering — the manipulation of people rather than technology — is more sophisticated because AI can research a target organisation, its employees, and its suppliers to build convincing pretexts.
The NCSC’s timeline assessment is particularly worth noting. They’ve indicated that the capability increase from AI represents a shift measured in months, not years. That’s not a slow-moving trend you can plan to address in next year’s IT budget — it’s happening now.
For small businesses, the attacks that benefit most from AI are exactly the attacks you’re most likely to face: phishing, business email compromise, and credential theft. These don’t require sophisticated technical exploitation. They require convincing communication, and that’s where AI genuinely makes a difference.
What the Advisory Recommends
The NCSC’s guidance for smaller organisations focuses on the Cyber Action Toolkit — a set of free resources that walk you through the fundamental security controls that address the majority of attack vectors. These aren’t exotic technical measures. They’re things like:
Making sure you have multi-factor authentication on every account that can access your business systems. Using strong, unique passwords (a password manager makes this manageable without anyone needing to memorise anything). Keeping your software and operating systems updated promptly rather than clicking “remind me later” indefinitely. Backing up your data and — this is the one people often skip — making sure you can actually restore from those backups. Knowing who to call if something goes wrong.
None of this is complicated. What’s complicated is actually doing it consistently across a small team where everyone is busy doing the actual work of running the business.
The Board Engagement Point
The open letter specifically calls out board engagement, and this is worth taking seriously even if your “board” is just you and two colleagues. The NCSC’s point is that cyber security decisions — budget, priorities, who’s responsible for what — need to be made at the level where resources and authority actually sit. Delegating cyber security entirely to whoever is most technical in your team, while everyone else continues to click suspicious links and reuse passwords, doesn’t work.
What does work is agreeing as a business on a few basic expectations: that everyone uses MFA, that people know how to report a suspicious email, that there’s a clear plan for what to do if something goes wrong. That conversation doesn’t need to be long. It just needs to happen.
Cyber Essentials: Still the Right Starting Point
For UK small businesses that want a structured framework, Cyber Essentials remains the best starting point. It’s a government-backed certification scheme that covers five basic security controls: firewalls, secure configuration, access control, malware protection, and patch management. Businesses that achieve Cyber Essentials are significantly less likely to suffer a successful cyberattack, according to NCSC data.
Basic Cyber Essentials certification costs around £300 and involves a self-assessment questionnaire verified by an accredited body. Cyber Essentials Plus adds an independent technical audit and costs more, but is worth considering if you handle sensitive customer data or if a cyber incident would have serious consequences for your operations.
Cyber Essentials certification also makes your business more attractive to larger clients who ask about security practices as part of procurement — some government contracts and NHS supply chain positions require it.
The Practical To-Do List
If you read nothing else from this article, do these five things:
Turn on multi-factor authentication for your email, your accounting software, and anything else that contains customer data or financial information. This single control stops the majority of account takeover attacks.
Make sure your devices are running current operating system versions with automatic updates switched on. Unpatched software is the most common entry point for automated attacks.
Set up a backup that runs automatically and stores copies somewhere separate from your main systems — cloud backup or a disconnected drive. Test it.
Brief your team on what a suspicious email looks like and what to do when they see one. “Don’t click, report to [name]” is enough.
Identify who you’d call if you discovered a breach today. Action Fraud (0300 123 2040), your bank, and any affected customers are the first contacts. Knowing this before it happens means you’ll react faster.
The AI-accelerated threat environment the NCSC is describing doesn’t require a security overhaul from small businesses. It requires doing the basics properly, consistently. That’s always been true, and it’s more true now.