Felk warns AI is fuelling attacks on smaller firms
Fri, 24th Jul 2026 (Yesterday)
Felk has warned that artificial intelligence is accelerating cyber attacks against small and medium-sized businesses, with smaller companies becoming the main targets.
The London-based cybersecurity provider said AI is cutting the time between the discovery of a software flaw and its exploitation from weeks to hours, putting greater pressure on businesses with limited monitoring and security staff.
Smaller businesses have become attractive targets because the economics have shifted in attackers' favour. Cybercrime-as-a-Service tools have lowered the technical barrier to entry, while automation has reduced the time and cost needed to launch more sophisticated campaigns.
As a result, companies with small IT teams, or none at all, face greater risk. Web-based systems used by smaller firms can hold payment details, personal information and login credentials, but often lack continuous monitoring, regular vulnerability scanning and responsive detection tools.
Felk cited wider industry data to support its warning, including research showing that 59% of UK and European SMEs reported a cyber attack in the past year, while 57% said the incident involved an AI-related vulnerability.
European threat monitoring has also highlighted the pace of change. ENISA's 2025 threat landscape said attackers are weaponising newly discovered vulnerabilities within days of disclosure, a timeframe that can outstrip the response processes of many smaller organisations.
Cost pressure
The financial impact can be severe. UK government survey data put the average cost of a significant cyber attack on a British business at nearly £195,000, including downtime, recovery work, legal costs and reputational damage.
For smaller companies, that level of loss can be more than a temporary setback. Some struggle to win new customers after an incident, while others report weaker business performance in the aftermath of an attack.
Many SMEs may already be dealing with so-called silent attacks, in which intruders avoid triggering conventional alarms and wait for an opportunity to use stolen credentials or data. Felk said newer AI-enabled attacks are increasingly focused on session tokens, login details and weaknesses in application logic rather than methods that create obvious alerts.
Recent high-profile retail incidents have drawn attention to the role of third-party compromise in wider attacks. That has added to concerns among security providers that smaller firms can become entry points into broader commercial networks.
"Many businesses believe they are too small to be on a cybercriminal's radar. That assumption is not only wrong, it is one of the most dangerous beliefs a business owner can hold in 2026. AI-driven attacks do not discriminate by size. They target the weakest defences, and right now, that too often means a smaller business website," said Uditha Atukorala, chief executive officer of Felk.
Response steps
Felk is urging smaller businesses to treat web protection as a core business issue rather than a narrow IT task. It said firms should review whether they still rely on static, rule-based tools that may struggle to keep pace with automated attacks.
Among the measures it highlighted were stronger passkey-based authentication, vulnerability assessments for public-facing systems, incident response planning and regular staff training. Felk noted that only a small minority of SMEs provide employees with AI security training, despite the rise in AI-generated phishing and social engineering attempts.
The warning reflects a broader shift in cyber risk for smaller firms. Attackers no longer need the same level of skill or resources to run convincing campaigns at scale, while many SME defenders still rely on stretched internal teams or outside support that may not operate in real time.
That imbalance is one reason security specialists are focusing more closely on smaller organisations as a weak point in supply chains and customer ecosystems. A breach at a modest-sized company can expose data directly, but it can also provide a route into suppliers, partners or clients with wider reach.
Atukorala said smaller firms do not need the spending power of large corporations to improve their position, but they do need tools and processes that match the speed of the threat.
"The threat is real, but so is the solution. Small businesses don't need enterprise budgets to protect themselves - they need the right tools, deployed in the right way, at the right speed. AI is being used against them, but it can equally be used to defend them," Atukorala said.