AI Essentials: From AI experimentation to confident growth

What a Responsible AI Essentials programme could offer small businesses

The Federation of Small Businesses' Confidence Code makes a strong economic case for helping smaller firms use AI well.

AI use among small businesses has risen from 20% to 55%, yet 92% now have concerns about it. FSB estimates that £42 billion could be added to the UK economy each year if more firms adopted AI and existing users expanded their use.

The opportunity is not simply to increase the number of businesses using AI. It is to help them move from occasional experimentation to uses that improve products, customer experience and business models.

FSB found that firms using AI for basic tasks reported average productivity gains of 10% and revenue gains of 3%. Those using it for more advanced tasks, including developing products and services, reported gains of 13% and 5%. These are self-reported associations rather than proof that AI caused each improvement, but the pattern is useful: how a business adopts AI may matter as much as whether it adopts it at all.

Confidence is part of the growth infrastructure

The report describes a familiar starting point. Businesses adopt technology to save time or reduce costs, then use the capacity they create to expand, improve services or focus on customers.

Among firms that had adopted technology, 22% of AI users said it had enabled them to expand, compared with 8% of businesses that did not use AI. However, 68% of recent AI adopters had not yet seen a change in revenue. Investment, training and changes to working practices take time to produce results.

This suggests that AI policy should not be judged only by licence purchases or headline adoption rates. It should help businesses:

  • choose suitable uses
  • implement them effectively
  • develop their people
  • manage the associated risks
  • demonstrate their approach to customers

A common assurance scheme could support this. It could reduce the need for every customer or larger supplier to create a different AI questionnaire and give smaller businesses a recognised way to show that they have sensible controls.

There is a caution here. FSB reports that only 3% of small businesses held Cyber Essentials certification in 2025, with cost and time contributing to low take-up and lapsing certificates. As certification becomes more important in supply chains, poorly designed requirements can exclude the firms they were intended to help.

A Responsible AI Essentials programme would therefore need to make implementation easier, not merely introduce another badge.

Start with an AI Action Toolkit

Certification may not be the right first step for every business.

FSB found that lack of implementation know-how has become a more significant barrier, rising from 17% in 2023 to 29%. A fifth of small businesses do not know where to start, while only 4% of technology adopters had received support from a government-funded service.

A complementary AI Action Toolkit, based on the NCSC's Cyber Action Toolkit, could help close this gap.

The Cyber Action Toolkit gives small firms free, tailored and bite-sized actions. It organises them into progressive layers, explains why each action matters and allows businesses to track their progress. NCSC research with 2,500 users found that this interactive approach encouraged action more effectively than static guidance alone. It also provides a route towards Cyber Essentials rather than trying to replace certification. (cybertoolkit.service.ncsc.gov.uk)

An AI version could follow a similar structure:

  • Foundation: identify the AI tools in use, set simple rules for company data, use managed accounts, protect access and verify sensitive requests independently.
  • Improver: assess suppliers, train staff, check important outputs, manage integrations and decide which information each system may access.
  • Enhanced: control action-taking AI, limit permissions, introduce approval points, retain logs and prepare to stop, investigate and recover from failures.

The toolkit would not provide certification. It would turn broad advice into practical work and help organisations build the evidence needed for a later assessment.

It could also connect with FSB's proposed AI Skills Hub, adoption course, advisers and vouchers. A business would have somewhere to begin, a way to track progress and a route to further support where changes required time or specialist help.

One standard and proportionate assessment

For businesses that need to demonstrate assurance, a Responsible AI Essentials certificate could provide a common baseline.

Its claim should remain focused:

The organisation has put baseline controls in place to approve and use AI systems, protect its information and remain in control of what those systems can do.

That would not certify every legal, ethical and social question associated with AI. Copyright, discrimination, employment, environmental impact, privacy and security each involve different evidence and expertise. Relevant guidance should sit around the programme, while the certificate itself remains understandable and assessable.

There could be one standard and one certificate, with questions determined by what an organisation's AI can do.

A writing assistant using non-sensitive information would attract a relatively small set of requirements. Further controls would apply if the system could search internal records, retain memory, access sensitive data, call APIs, run code or change business systems.

Certification should also cover a continuing process rather than a fixed product list. AI tools and supplier features will change during the life of a certificate. The organisation should be able to introduce a new system, assess its capabilities and apply the relevant controls without seeking a new certification each time.

FSB proposes self-assessment with independent audit. In practice, a proportionate model may sit between a declaration and a full technical audit.

The applicant could complete a structured assessment and submit selected evidence. An independent assessor would review it, challenge unclear answers and decide whether the requirements had been met. Technical testing could be reserved for systems with sensitive access or the ability to take consequential actions.

This would provide more confidence than self-declaration without imposing a full audit on a sole trader using an ordinary supplier-managed service.

Design for frontier and agentic AI

Any baseline introduced now will need to account for systems becoming more capable.

NCSC describes agentic AI as systems that can plan tasks, make decisions and take actions on a user's behalf. They may access data, remember context, use tools and operate without continuous human involvement. NCSC advises organisations to begin with bounded, lower-risk uses, apply least privilege, monitor behaviour and retain the ability to contain the system. Where an organisation cannot understand, monitor or contain an agent's actions, it is not ready for deployment. (National Cyber Security Centre)

A Responsible AI Essentials standard would therefore be more durable if it assessed capabilities rather than labels such as assistant, copilot or agent.

The relevant questions are practical:

  • What information can the system reach?
  • What tools and business systems can it use?
  • What actions can it complete?
  • Which actions require independent approval?
  • Can the organisation see what it has done?
  • Can access be withdrawn and changes reversed?

This also reflects NCSC's broader frontier AI message. AI does not remove the need for established cyber-security controls, but it raises the consequences when those controls are absent. (National Cyber Security Centre)

Responsible AI Essentials should therefore complement Cyber Essentials. Existing evidence on identities, devices, access and security updates could be reused, while the AI assessment concentrated on the additional risks created by data use, unreliable outputs, manipulated instructions, system connections and autonomous action.

Adoption changes roles as well as tools

The report's workforce findings are important because successful adoption is not primarily a software installation exercise.

Businesses reporting revenue gains were more likely to have gathered employee feedback, trained staff, developed an implementation plan and introduced an AI policy. FSB's qualitative research also found that automation was often accompanied by upskilling. Roles shifted towards creativity, strategy and customer engagement, while staffing reductions were more commonly achieved by not replacing leavers than by immediate redundancies.

Human oversight should reflect this changing division of work.

It does not necessarily mean asking someone to check every routine output indefinitely. It may mean people setting boundaries, approving important exceptions, reviewing patterns and outcomes, and remaining accountable for significant decisions.

There is also a question of who benefits. Female entrepreneurs in the survey were slightly more likely to use AI than male entrepreneurs, but reported lower productivity and revenue gains. FSB suggests that greater concern about liability and responsible use may be limiting the systems, data and workflows they feel able to use. Disabled entrepreneurs also reported greater concern about security, liability and deepfakes.

Accessible guidance and credible guardrails could therefore support more inclusive growth. Confidence would not only help non-users begin. It could help existing users move into more valuable applications.

Gather supplier information once

Many of the questions facing small businesses cannot be answered through their own controls.

FSB found widespread concern about where data is processed, whether it is used for training, who owns AI-generated outputs and where liability sits. Its proposal for centrally published model cards could reduce the need for every small firm to investigate the same major suppliers.

These profiles could cover:

  • data location and retention
  • use of customer inputs for training
  • available security and administrative controls
  • supported integrations and actions
  • logging and incident notification
  • changes to models and capabilities
  • output ownership and contractual responsibility

The organisation would remain responsible for its configuration and use. Providers would supply information about the systems they are better placed to understand.

The wider market also matters. FSB's chapters on technology subscriptions describe unpredictable costs, difficulty moving data and supplier lock-in. Its research on small technology firms highlights the role of open-source models, access to usable data and proportionate access to compute.

An assurance programme should not become a list of favoured vendors. It should consider portability, exit arrangements and interoperability so that certification does not make it harder for small firms to change services or for smaller AI providers to compete.

Build a pathway from guidance to mature governance

The UK is not starting from nothing.

The AI Cyber Security Code of Practice provides lifecycle security principles for developers and organisations deploying AI, including risk assessment, human responsibility, supply chains, documentation, testing, monitoring and incident management. It is being taken forward through ETSI as the basis for international requirements. (GOV.UK)

AI Management Essentials attempted to turn broader governance frameworks into an accessible self-assessment. The consultation supported the objective but called for simpler language, more practical guidance and different journeys based on how organisations interact with AI. The government decided not to publish AIME in its proposed form and is instead focusing on foundational support for SMEs. (GOV.UK)

ISO/IEC 42001 sits further along the assurance journey. It provides requirements for establishing, maintaining and continually improving a full AI management system. It is valuable where an organisation needs comprehensive governance, but involves a broader organisational commitment than many small users of supplier-managed AI will initially require. (ISO)

Other countries offer useful components. Singapore's AI Verify combines a governance framework with technical and procedural testing, while its newer framework for agentic AI emphasises bounded authority, human approval points and lifecycle controls. Australia simplified its voluntary safety standard into six essential practices for AI adoption. The US NIST AI Risk Management Framework provides a flexible risk framework and a specific generative AI profile. The EU AI Pact supports voluntary action on governance, high-risk system mapping and staff literacy. (IMDA)

The opportunity for the UK may be to connect these ideas into a clear progression:

  1. An AI Action Toolkit helps a business take its first practical steps.
  2. Responsible AI Essentials provides independent assurance that a defined baseline has been met.
  3. ISO/IEC 42001 supports organisations that need a comprehensive AI management system.

The stages would complement one another rather than compete.

From caution to useful adoption

FSB's report is ultimately about growth.

Small businesses are already using AI, but uncertainty is shaping where they feel able to use it. That may keep adoption concentrated in low-risk drafting and administrative tasks, even where more valuable opportunities exist.

A certificate alone will not solve this. Smaller firms need a practical route from awareness to action, support when implementation becomes difficult and credible assurance when customers ask for evidence.

An AI Action Toolkit could provide the starting point. Responsible AI Essentials could establish a recognised baseline. Existing standards and regulation could address more complex organisations, providers and higher-risk uses.

Together, these measures could help small businesses use AI with greater ambition while retaining control of their information, decisions and operations.

The policy question is therefore not only how to reduce the risks of AI. It is how to give businesses enough confidence to use it where it can make the greatest difference.

References

  • Federation of Small Businesses, The Confidence Code: The challenges and opportunities of AI for small businesses, July 2026.
  • National Cyber Security Centre, Cyber Action Toolkit.
  • National Cyber Security Centre, Frontier AI: what you need to know.
  • National Cyber Security Centre, Thinking carefully before adopting agentic AI, May 2026.
  • Department for Science, Innovation and Technology, AI Cyber Security Code of Practice, January 2025.
  • Department for Science, Innovation and Technology, Guidance for using the AI Management Essentials tool: government response, February 2026.
  • ISO, ISO/IEC 42001:2023: Information technology — Artificial intelligence — Management system.
  • ETSI, EN 304 223: Baseline Cyber Security Requirements for AI Models and Systems, December 2025.
  • Singapore Infocomm Media Development Authority, AI Verify.
  • Singapore Infocomm Media Development Authority, Model AI Governance Framework for Agentic AI, updated May 2026.
  • Australian Government, Voluntary AI Safety Standard and subsequent Guidance for AI Adoption.
  • US National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework 1.0, January 2023.
  • US National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, July 2024.
  • European Commission, AI Pact.

The biggest catch: What is whaling in cybersecurity?

Whaling is a sophisticated form of cyberattack that targets high-profile executives and senior decision-makers within organisations – aka the “big fish”.

Unlike standard phishing attacks that cast a wide net, whaling attacks are meticulously crafted and highly personalised campaigns. They’re designed to deceive C-suite executives into authorising fraudulent transactions or revealing sensitive information – making them one of the most dangerous threats facing businesses.

How do whaling attacks work?

Whaling attacks typically begin weeks or even months before the victim receives the first malicious email. Cybercriminals gather information from various sources, studying their targets’:

  • Communication style
  • Business relationships
  • Operational schedules

This enables them to build a comprehensive picture of how the target operates.  

Armed with this knowledge, attackers craft seemingly authentic emails that appear to come from trusted sources. Think board members, legal counsel, or business partners.

Why do cybercriminals target the C-suite?

Hackers focus on executives because they are the highest value targets in any organisation. Senior leaders typically have:

  • Unrestricted access to financial systems
  • The authority to approve large transactions without extensive oversight
  • Intimate knowledge of business operations, strategic plans, and sensitive client information

Their busy schedules mean they're more likely to act quickly on urgent requests without following standard verification procedures.

What makes whaling attacks so dangerous?

When criminals successfully deceive an executive, the potential payoff is exponentially higher than targeting regular employees. Successful CFO or CEO fraud can result in hackers gaining access to highly sensitive business data and the theft of millions of pounds in fraudulent transfers.

What makes whaling dangerous?

  • Attackers extensively research and personalise their campaigns
  • Criminals exploit the authority and trust that senior positions command
  • Financial losses typically run much higher than standard phishing attempts
  • Their sophisticated nature makes them harder to detect

Whaling vs phishing vs spear phishing

While all three attack types fall under the social engineering umbrella, they differ significantly in scope and targeting.

Phishing

Phishing casts the widest net, sending generic malicious emails to thousands of recipients, hoping to land a catch. These attacks often contain obvious red flags like poor grammar or suspicious links.

Spear phishing

Spear phishing narrows the focus to specific individuals or groups within an organisation. In spear phishing attacks, hackers use publicly available information to create convincing messages tailored to the target.

Whaling

Whaling goes further still, exclusively targeting high-value executives with extensively researched, highly personalised attacks that can take weeks or months to prepare. Criminals invest this time because the potential payoff is enormous.

AI’s impact on whaling attacks

AI has made whaling and other social engineering attacks more sophisticated and accessible than ever before. Recent research claims cybercriminals use AI in 67.4% of all phishing attacks. The question is, how?

Content creation

AI allows hackers to create emails that perfectly mimic an executive's writing style, tone, and communication patterns. Gone are the days when you could spot a fake email by looking for typos or unusual phrasing.

Voice phishing

Voice phishing (or vishing) attacks surged 442% between the first and second halves of 2024. Cybercriminals use AI-generated voice clones that can replicate an executive's speech patterns from just a few seconds of audio.

Deepfake whaling attacks

A relatively recent trend has seen cybercriminals use AI to make sophisticated deepfake video calls. These attacks involve creating realistic avatars of executives that participate in live video conferences, making requests for fund transfers or sensitive information.

The technology has advanced to the point where deepfakes can convincingly replicate facial expressions, speech patterns, and mannerisms, making it extremely difficult for victims to detect.

7 Whaling prevention and mitigation strategies

Protecting your organisation against whaling attacks requires a multi-layered approach that combines technology, processes, and employee awareness.

1. Multi-factor authentication and access controls

Set up multi-factor authentication (MFA) for all senior executives and anyone with access to financial systems. Create separate administrative accounts and ensure that no single person can authorise high-value transactions without additional verification.

2. Verification protocols for financial requests

Establish mandatory dual-channel verification for any financial request over a certain threshold. If someone receives an email requesting a wire transfer, they must verify the request through a different communication method ideally, an in-person conversation or phone call to a known number.

Create a “safe word” system for urgent requests, where executives and finance teams use predetermined phrases that criminals can’t easily discover through research.

3. Executive phishing awareness training

Run cybersecurity awareness training sessions that specifically address social engineering attacks. Training should include hands-on simulations using realistic scenarios that executives might encounter, such as urgent legal requests or time-sensitive acquisition communications, as well as:

  • How to identify social engineering tactics
  • The importance of verifying unusual requests through secondary channels
  • Staying alert to potential deepfake audio and video attacks

4. Email security and filtering

Deploy advanced email security that can detect sophisticated phishing attempts. For the best protection, consider investing in a system that uses AI to analyse communication patterns and flag unusual requests – even when they come from legitimate-looking accounts.

For added protection, implement domain-based message authentication, reporting, and conformance (DMARC) to prevent domain spoofing and ensure emails claiming to be from your organisation are legitimate.

5. Digital footprint management

Conduct regular audits of executives' online presence and limit the amount of publicly available personal and professional information. This includes:

  • Reviewing social media privacy settings
  • Limiting biographical information on company websites
  • Being cautious about sharing travel schedules or personal details publicly

6. Incident response planning

Develop incident response procedures for whaling and business email compromise (BEC) attacks, and test them regularly to ensure everyone knows what to do in the event of a breach. According to Verizon, over half of BEC victims were able to recover at least 82% of their stolen money when they reported fraudulent transfers quickly.

Your response plan should include immediate contact procedures for banks, law enforcement, and cybersecurity teams, along with clear escalation processes for different types of whaling attempts.

7. Zero-trust architecture

Implement a zero-trust security model that assumes every request could be malicious, regardless of its apparent source. This means verifying every transaction, access request, and communication before acting.

Consider using advanced threat detection that detects unusual patterns in executive communications and financial activities.

Whaling attack examples

Understanding how whaling attacks unfold in practice helps illustrate why these threats are so effective and costly.

The FACC aerospace attack

In 2015, Austrian aerospace manufacturer FACC fell victim to a whaling attack that resulted in €50 million in losses.

Criminals impersonated the company's CEO in an email to a finance employee requesting an urgent fund transfer for what appeared to be a confidential acquisition deal. The finance worker, believing the request came directly from the CEO and feeling pressure to act quickly on the sensitive matter, authorised the transfer without seeking additional verification.

The $25 million deepfake conference call

One of the most sophisticated whaling attacks on record occurred in 2024 when criminals used deepfake technology to orchestrate an elaborate video conference scam targeting Arup, a multinational engineering firm. 

The finance worker believed they were participating in a legitimate meeting with senior colleagues, including the CFO. During the call, hackers convinced the unfortunate employee to transfer $25 million out of the company.

US non-profit fraud scheme

In 2024, law enforcement arrested a Nigerian cybercriminal who’d targeted charitable organisations in the US, stealing over $7 million

The attacker first compromised email accounts at one charity, then used that access to study internal communications and procedures. Armed with insider knowledge, the criminal impersonated legitimate employees to request fund transfers from a second charity, making the requests appear routine.

What is whaling in cybersecurity? A threat you can’t ignore

What is whaling in cybersecurity? In a nutshell, it’s one of the most sophisticated and expensive cybersecurity threats facing businesses. With BEC attacks costing companies over $16.6 billion in 2024 and AI making these attacks more accessible, organisations can no longer treat executive targeting as an edge case.

Defending against whaling requires robust technical controls, clear verification processes, and ongoing awareness training. By implementing comprehensive security measures, like those outlined in the government-backed Cyber Essentials certification, you can ensure your organisation's executives don't become the next big catch.

Want to give your people the skills to recognise cyber threats before they turn into breaches? Check out CyberSmart Learn, our cybersecurity focused learning management system.

Zeus, SpyEye, Emotet. What do those names mean to you? As much as they sound like Marvel supervillains, they’re all examples of high-profile banking trojans.

Emerging in the mid-noughties, banking trojans have morphed into one of the most dangerous SME cybersecurity threats. But what are banking trojans? And how can you protect your business from them?

WHAT IS A BANKING TROJAN?

A banking trojan is a particularly nasty form of trojan horse malware that aims to give cybercriminals access to networks and confidential information stored in online banking systems.

Banking trojans typically come in two forms:

  1. Backdoor trojans: Use backdoors in your system to circumvent security measures and gain access to your computer.
  2. Spoofers: Steal user credentials by creating a fake version of a financial institution’s login page.

HOW DO BANKING TROJANS WORK?

A banking trojan works in much the same way as the mythological wooden horse from which it draws its name. A typical banking trojan looks and behaves like legitimate software until you install it. Once it’s on your device, it shows its true colours.

Cybercriminals use banking trojans to:

Did you know that 47% of UK SMEs feel more threatened by cybercrime since the cost of living crisis began? Find out more in our latest report.

WHY ARE BANKING TROJANS SO DANGEROUS? 

Banking trojans are a particularly hazardous form of malware for several reasons. Firstly, they’re usually well disguised as legitimate software, which makes them difficult to detect for anyone who isn’t a cybersecurity expert.

Secondly, they cause significant damage. In a worst-case scenario, a banking trojan can give cybercriminals total access to your bank accounts, which could spell financial ruin.

HOW DO YOU KNOW WHEN YOU’VE BEEN HIT? 

Although it can be challenging to spot a banking trojan, it’s not impossible. Like any malware attack, there are a few telltale signs to look out for:

It’s important to note that none of these are conclusive proof that someone’s successfully hacked your system. Think of them as signs that suggest something isn’t quite right. So, if you’re in any doubt, it’s time to call the professionals.

WHAT CAN YOU DO TO PROTECT YOUR BUSINESS?

Thankfully, protecting your business against banking trojans and similar forms of malware is relatively straightforward. Beyond investing in reliable threat monitoring software, we recommend following these six simple steps.

Use multi-factor authentication 

Multi-factor authentication (MFA) is a security measure that requires you to provide two or more verification methods to sign into an application. Instead of asking for your username and password, MFA demands additional information such as:

The idea behind MFA is simple: the more locks you have on the door, the harder it is for an intruder to break in. Think of it as adding a cyber deadbolt, a door chain lock, and some cameras to keep the bad guys out.

Train staff how to spot the signs

Human error is responsible for as much as 90% of cyber breaches, and it’s easy to see why. Few of us are cybersecurity experts, and if you aren’t aware of what a cyber threat looks like, you’re much more likely to find yourself on the receiving end.

Cybersecurity training can bridge this knowledge gap. Training helps staff recognise, understand, and mitigate the threats they face. What this training looks like depends on your business and the knowledge within it. For some, it’s a case of starting from scratch and covering the basics; for others, it’s about addressing specific weak spots.

Patch software regularly 

Patching your software is the simplest way to improve your business’s cybersecurity. Even the best software can develop vulnerabilities, suffer a breach, or become outdated. Software developers release security patches to ensure cybercriminals don’t have an easy route into their clients’ systems.

It’s easy to install these patches. You can check your system for updates every few days or activate the auto-update setting on all company devices.

Use a password manager 

Many banking trojans use keyloggers – programs that record your keystrokes so cybercriminals can steal your PIN or password. Using a password manager, which doesn’t require you to type anything, instantly overcomes the threat of keyloggers.

Only download files from trusted sources

This might seem obvious, but if you’re unsure about the origin of a file or piece of software, don’t download it. Set clear rules throughout your business to ensure people only download software from trusted sources, such as Microsoft, Google, or Apple stores. This helps to minimise your exposure to compromised software and malware.

Use all the security features offered by your bank

Banks offer a range of security features. Use them! If your bank provides MFA for sign-in (virtually all of them do), use it. Many business-oriented banks also have app stores full of free or low-cost cybersecurity features. Use them, too. These little extras are often the difference between cyber safety and falling victim to a banking trojan.

BANKING TROJAN EXAMPLES TO WATCH OUT FOR

Zeus

Active since 2007, cybercriminals use Zeus to target Microsoft Windows and steal financial data. It quickly became one of the most successful pieces of malicious software in its class, affecting millions of systems worldwide and giving rise to a host of similar threats. After a brief lull in 2010, when the creator reportedly retired, we’ve seen an uptick in Zeus variants since the source code went public. 

SpyEye

Once touted as the successor to Zeus, SpyEye established itself as one of the most dangerous banking trojans in the early 2010s. SpyEye enabled its creators to steal sensitive information from its victims’ bank accounts, including account credentials, credit card information, and PIN numbers. Its Russian creator was sentenced to nine-and-a-half years in prison in 2016.

EMOTET

Emotet is a banking trojan that spreads primarily through email. These emails often use familiar branding and convincing wording to trick the victim into clicking on a malicious link. Emotet has gone through a few iterations since emerging in 2014, in an attempt to circumvent modern detection methods.

DON’T SUFFER THE SAME FATE AS TROY

Understanding the threat banking trojans pose and adopting appropriate countermeasures are integral to safeguarding your financial information in today’s digital landscape.

Simple, inexpensive malware prevention tips – like updating your software regularly, using a password manager, and educating staff – help protect your business against banking trojans and other malware strains, too.

Want to know more about the threats facing small businesses? Check out our new research report on SMEs and the cost of living crisis.

SME cost of living crisis