When Cybersecurity Becomes a Question of Verification: Why SMEs need to rethink their identity in the age of AI

By Luca Rognoni, CISO & Co-Founder, YEO Messaging

We advise a lot of organisations – large and small, public and private, on how to handle the main weak points in cybersecurity. For years, generic cybersecurity advice for SMEs has followed a familiar pattern: use strong passwords, enable multi-factor authentication, train your staff, keep your software updated. That advice hasn’t gone away. But over the last three years, it’s true to say that the threat landscape has shifted considerably.

The fastest-growing risk facing SMEs today isn’t unauthorised access to systems in the traditional sense. It’s the growing difficulty of verifying who is actually on the other end of a digital interaction. It’s the next stage of scamming and it’s happening right now to companies up and down the UK.

AI has made impersonation attempts dramatically easier and increasingly prolific. Deepfake voice technology can replicate one of your managers requesting an urgent payment, at the touch of an app button. Fraudsters can produce convincing versions of emails, messages and video calls. A familiar WhatsApp message, a Teams notification, a recognised email address, none of these are reliable proof of identity anymore.

For SMEs, this is a particularly uncomfortable reality. Smaller organisations rarely have large security teams or significant cybersecurity budgets. They largely depend on trust, speed, gut choices and close working relationships to get things done. Those are precisely the conditions that make social engineering attacks effective.

Somehow we have left our SMEs behind and powerless to move forward into a regulated state. Their conventional security tends to focus on the point of login. Once someone is inside a platform, they’re treated as trusted. In a world shaped by generative AI, that model has a fundamental weakness. Passwords, one-time authentication and familiar names are no longer enough on their own, we need constant verification throughout the entire digital transaction.

In fact, the next phase of cybersecurity for all will likely be less about securing devices and more about verifying people continuously and proportionately and with proof points at the moments that matter, like at the moment of transaction.

This sounds complex but in reality it doesn’t have to mean deployment of an expensive infrastructure or dedicated assistance from IT. In many cases, straightforward verification steps, tighter internal processes and a culture of questioning unusual requests can meaningfully reduce exposure.

In a world where identities can be artificially constructed, the businesses that hold up best will be those that have learned to verify trust rather than assume it. These will be the UK authenticated businesses that survive and thrive in decades to come.