Field note
AI Phishing and UK SMEs: Controls That Work
You cannot train staff to spot every AI-written email or cloned voice. You can make a stolen password useless and make sure no payment details change on the strength of a message.
Phishing is still the attack most UK businesses see. The government's Cyber Security Breaches Survey 2025/2026, published on 30 April 2026, found that 43 per cent of businesses identified a breach or attack in the last 12 months, and 38 per cent of businesses experienced phishing.
AI changes the quality of those attacks rather than the type. The NCSC's assessment of AI's near-term impact says AI provides capability uplift in reconnaissance and social engineering, almost certainly making both more effective, efficient and harder to detect.
For an SME, that means the old advice to look for bad spelling no longer works. A cloned voice or a well-written email can be convincing. The controls that hold up are the ones that do not depend on someone spotting the fake.
Quick answer
- Require phishing-resistant MFA, such as passkeys or Windows Hello for Business, for admins first and then everyone.
- Turn on Defender for Office 365 preset security policies, at Standard at minimum.
- Publish DMARC at enforcement so criminals cannot send as your domain.
- Never change payee bank details on the strength of an email, message or call. Call back on a number you already hold.
- Block external mail forwarding and review inbox rules regularly.
What the UK figures say
The Cyber Security Breaches Survey 2025/2026 gives useful context from fieldwork between August and December 2025:
- Breach rates rise with size: 42 per cent of micro businesses, 46 per cent of small businesses and 65 per cent of medium businesses.
- Among businesses that were breached, 51 per cent experienced phishing only, up from 45 per cent the previous year.
- 12 per cent of businesses reported impersonation, down from 17 per cent two years earlier.
- Only 47 per cent of businesses use two-factor authentication.
The survey does not give figures for deepfakes or voice cloning, so treat claims of precise AI fraud numbers with care. What it does show is that phishing remains the most common route in and that half of businesses still lack basic multi-factor sign-in.
Stop stolen passwords from mattering
AI-written phishing pages are designed to collect passwords and one-time codes. Standard MFA with a code or push approval can be relayed by an attacker in the middle.
Microsoft Entra ID includes a built-in Phishing-resistant MFA authentication strength. It allows methods that require an interaction between the authenticator and the sign-in surface, such as passkeys, FIDO2 security keys and Windows Hello for Business. A fake site cannot complete that exchange.
A practical order:
- Require the phishing-resistant strength for all admin roles through Conditional Access.
- Register passkeys for finance staff and anyone who approves payments.
- Extend to all staff once registration is stable.
The passkeys in Entra ID practical rollout guide covers the registration steps and common snags.
Make email filtering do more of the work
Defender for Office 365 preset security policies apply Microsoft's recommended settings for anti-phishing, Safe Links and Safe Attachments. On first visit, Standard and Strict protection are usually turned off, so someone has to switch them on and assign users.
For an SME, Standard for everyone with Strict for finance and directors is a sensible start. Impersonation protection is worth configuring for the names of senior staff and key suppliers, because payment fraud often relies on a look-alike sender.
On the sending side, DMARC at p=reject stops criminals sending mail that appears to come from your exact domain. It does not stop look-alike domains, which is why impersonation protection and payment checks still matter.
Voice cloning and payment diversion
Payment diversion fraud usually follows a pattern: a message or call that appears to come from a supplier or a director, then a request to pay a new account urgently. AI voice cloning makes the phone call more believable. It does not change the defence.
A payment control that works:
- Written rule. Bank details never change on the strength of an email, text, voice note or inbound call.
- Call-back. Finance calls the supplier on a number already held on file, not one in the message, and confirms the change with a known contact.
- Two people. A second person approves any new payee or changed bank details before the first payment.
- No urgency exception. A director asking for an urgent transfer follows the same process. Agree a verification step in advance.
- Record. Keep a note of who called whom and when.
This costs nothing in licences and blocks the attacks that technology misses.
Watch for the signs after a click
Some attacks will get through. The common follow-up is a mailbox rule that hides replies from a supplier, or forwarding that copies invoices to the attacker.
Block automatic external forwarding in the outbound spam policy. Review inbox rules on finance mailboxes monthly. Make sure unified audit logging is on so you can see what happened. The mail forwarding and inbox rules audit walks through the checks.
Finally, tell staff how to report a suspicious message or call, and thank them when they do. A fast report is worth more than a perfect training score.
Source basis
Related notes
22 Jan 2026 · 5 min
08 May 2026 · 4 min
19 Feb 2026 · 4 min
Need help mapping this to your own tenant, controls, or assessment timeline?