← SecureAZ Blog

Security Awareness · 7 min read · Published 15 August 2026 · Reviewed 17 August 2026

How to Protect Your Business From AI Security Threats

AI has changed what cyber attacks look like and how fast they move. Here is what the AI threat landscape means for NZ businesses in practical terms, and the specific controls that work against AI-assisted attacks.

Artificial intelligence has fundamentally changed the threat landscape for NZ businesses. This is not a future concern — it is the current reality. AI tools are being used by attackers right now to craft more convincing phishing, automate vulnerability scanning, accelerate lateral movement inside compromised networks, and conduct reconnaissance that previously required skilled human analysts.

Understanding what AI-assisted attacks actually look like — and which controls work against them — is now a baseline requirement for any NZ business taking security seriously.

How AI Is Being Used in Attacks Against Businesses

### AI-Generated Phishing at Scale

Traditional phishing was limited by the quality of the attacker's English and their knowledge of the target. Both constraints have been removed. AI tools allow attackers to generate fluent, grammatically perfect phishing emails personalised to the recipient — referencing their employer, their role, recent company news, or industry context — at volume and at near-zero cost.

The practical implication: you can no longer train staff to look for spelling mistakes and awkward phrasing as phishing indicators. The behavioural signals matter now — urgency, unexpected requests, sender address anomalies — not quality signals.

### Deepfake Voice and Video Fraud

AI-generated voice cloning can replicate a person's voice from a short audio sample. Video deepfakes can generate convincing video of a real person. Both are being used in business fraud:

  • Attackers clone the voice of a CEO or financial director and call finance staff to authorise urgent wire transfers
  • Deepfake video is used in video calls to impersonate executives during supplier onboarding or contract discussions

CERT NZ has received reports of voice-cloning-assisted fraud attempts targeting NZ businesses. The defence is a process control: any out-of-band payment instruction — arriving by a channel different from the established process — requires verification through a separately established contact method regardless of how convincing it sounds.

### Automated Vulnerability Exploitation

AI-assisted scanning tools allow attackers to identify every internet-facing system in a country, map their software versions, and identify which have known vulnerabilities — in minutes. When a new critical vulnerability is published, automated exploitation can begin before most organisations are even aware the patch exists.

The window between vulnerability disclosure and active exploitation has shortened dramatically in 2025 and 2026. A patching SLA of weeks is no longer adequate for internet-facing systems. Critical patches need to be applied within days.

### AI-Accelerated Ransomware

Once inside a network, AI tools assist attackers in identifying the fastest path to high-value targets — domain controllers, backup systems, financial data — and automating lateral movement. Ransomware attacks that previously took days to move from initial access to full encryption are now completing in hours.

This compresses the window for detection and response. Security programmes designed around multi-day dwell times need to be rethought.

The Controls That Work Against AI-Assisted Attacks

### MFA Still Works Against AI Phishing

Even if an AI-generated phishing email convinces an employee to enter their password on a fake login page, MFA blocks the attack. The stolen password alone is not sufficient to log in. MFA remains the highest-leverage control for credential-based attacks regardless of how convincing the phishing has become.

The caveat: real-time phishing proxies can relay MFA codes in real time, intercepting the code the victim enters and using it immediately. Phishing-resistant MFA — hardware security keys (FIDO2/WebAuthn) or passkeys — defeats this. For high-risk roles (finance, IT administrators, executives), phishing-resistant MFA is the appropriate standard.

### Training That Focuses on Behaviour, Not Quality

Staff training needs to shift from "spot the bad spelling" to "recognise the manipulation pattern." The warning signs that matter against AI-generated phishing are behavioural:

  • Urgency and pressure to act immediately
  • Requests for credentials or verification codes
  • Unexpected financial or access requests from known contacts
  • Links going to unexpected destinations

Phishing simulations that test staff with AI-quality content — not obvious fake emails — are necessary to build accurate detection skills for 2026 threats.

### Process Controls Against Deepfake Fraud

Technical controls cannot fully defend against deepfake voice and video. The defence is procedural:

  • Any payment instruction received through a non-standard channel requires verification through a separately established contact method
  • Payment authorisation for amounts above a threshold requires dual authorisation from two individuals
  • New supplier banking details require phone verification to a number obtained independently from the payment instruction itself

These process controls work regardless of how convincing the deepfake is.

### Rapid Patching for Internet-Facing Systems

Against AI-automated vulnerability scanning and exploitation, patch velocity is the key variable. A 48-hour patching SLA for critical vulnerabilities on internet-facing systems — the CERT NZ recommendation — reflects where the real risk sits. Anything slower allows the window between disclosure and exploitation to be used against you.

Automate patching where possible. For systems that cannot be auto-patched, treat critical vulnerability notifications as urgent operational events, not routine maintenance.

### Network Segmentation to Slow AI-Assisted Lateral Movement

AI-accelerated lateral movement means that initial access to one system can translate to full network compromise faster than defenders can respond — unless network segmentation slows the attacker down. Segmenting your network so that compromise of an office workstation does not automatically provide access to your servers, backups, and financial systems limits the blast radius of any initial access.

This does not require a complex technical implementation for most NZ SMEs. Separating staff workstations from server infrastructure and keeping backup systems on isolated networks are practical starting points.

### Offline or Immutable Backups Against Faster Ransomware

If ransomware is moving from initial access to detonation in hours rather than days, the backup strategy needs to account for that speed. Backups that are continuously connected and replicating will be encrypted along with the primary data if ransomware deploys fast enough. Offline backups taken at regular intervals that are not continuously connected, or immutable backups configured to prevent deletion for a defined retention period, are the specific configuration that survives rapid ransomware deployment.

What NZ Businesses Should Do Now

  1. Enable MFA on all accounts that support it — phishing-resistant MFA for high-risk roles
  2. Update staff training to focus on behavioural phishing indicators, not quality indicators
  3. Implement a process requiring out-of-band verification for any financial instruction received through an unexpected channel
  4. Apply a 48-hour patching SLA for critical vulnerabilities on internet-facing systems
  5. Review backup strategy to ensure at least one backup copy is offline or immutable
  6. Assess network segmentation between workstations and servers

AI has raised the baseline security posture required to defend a NZ business. The controls that work against AI-assisted attacks are not fundamentally different from good security practice — they just need to be implemented correctly and at the right level of rigour.

Build AI-threat-aware security skills across your team with SecureAZ