1 in 5 enterprises admit they aren’t prepared for AI cyberattacks

A new study from Kaspersky (yes, it still exists) has revealed that one in five enterprises fail to adequately protect their organisation from AI-powered threats.ย You might be inclined to put this down to end of the year speculative โ€œthreats of the futureโ€ ball-gazing, but you would do so at risk of ignoring a very real and present danger to your data.

Threat intelligence analysts at Group-IB have, during the last few days alone, issued a report covering the use of AI-generated voices in a large-scale campaign targeting consumers of gaming applications.

The same threat intel service recently warned of a cyberattack on a โ€œprominent Indonesian financial institutionโ€ that used AI-deepfakes, virtual camera software and face-swapping technology to bypass biometric banking protections that included liveness detection.

Still think that the AI threat isnโ€™t something you should taking seriously, at least not yet? OK, a few more examples to shake you into acceptance: the deepfake impersonation fraud against the CEO of a cybersecurity company only failed because the attackers had used a recording of him giving a keynote presentation to fake his voice. A giveaway because his staff knew he had speech anxiety and his voice changed from normal when doing so.

Thatโ€™s the CEO of a cybersecurity company, remember. Another cybersecurity consultant was very nearly compromised by a tech support scam driven by an AI-generated chatbot. Or how about another using AI-generated copyright violation messaging?

Time to prepare for AI cyberattacks

Like it or not, AI has become good enough, easy enough to use and – perhaps most importantly – cheap enough to deploy that ignoring it is no longer an option.

Yet, โ€œdespite understanding the severity of the threat,โ€  Kaspersky said, many businesses are struggling to keep pace with the rapid evolution of AI-driven cybercrime.

โ€œBarriers such as skill shortages, lack of AI-powered tools, and the complexity of managing advanced cybersecurity infrastructures leave many organizations vulnerable,โ€ the report warned. 

Here are the numbers that should have you worried and looking for answers:

  • 19% of respondents said they have considerable gaps in their cyber protection.
  • 44% of organisations cited a lack of AI-related cybersecurity training for employees as a critical issue.
  • 44% said the complexity of managing cybersecurity infrastructure makes it harder to stay ahead of attackers.
  • 43% admitted that they lacked modern AI-powered cybersecurity solutions.
  • 41% struggled with a lack of information from external experts about the evolving AI-related threat landscape.

Come on folks, please, start taking the AI threat seriously. Get off your collective arses now, before it is too late. Donโ€™t let 2025 be the year you discover the costly consequence of not believing the hype.

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.