Cybersecurity has become a growing challenge for small businesses, particularly as cybercriminals adopt more sophisticated tools and artificial intelligence accelerates both attacks and the discovery of new vulnerabilities. For businesses with limited IT resources, keeping systems protected around the clock while managing patches, employee security, compliance requirements and emerging AI risks can quickly become overwhelming.

To explore what small businesses should be doing to strengthen their defenses, I spoke with Tony Anscombe, Chief Security Evangelist at ESET. Anscombe has spent roughly 30 years in the technology and cybersecurity industry and works with organizations, technology partners and the media to help explain the constantly changing threat landscape.

During our conversation, Anscombe discussed why small businesses should stop viewing cybersecurity strictly as an IT problem and instead consider it a broader business risk. We also talked about the challenges of 24/7 threat monitoring, the difference between traditional IT expertise and specialized cybersecurity expertise, when businesses should consider outside help, and how artificial intelligence is changing the threat landscape.

Anscombe also explained what small businesses should expect from managed detection and response services and managed service providers, as well as the responsibilities that should remain inside the business even when cybersecurity is partially outsourced.

Here is our conversation.

Leland McFarland: Hello, Small Business crew! I have a special interview for you. Got Tony Anscombe, the Chief Security Evangelist of ESET. Tony, great to have you on.

Tony Anscombe: Hey, good to be here, Leland.

Leland McFarland: Great. All right, why don’t we start off by having you tell the audience a little bit about yourself and a little bit about what you do at ESET?

Tony Anscombe: Okay. Well, as you said, I’m Tony, Chief Security Evangelist at ESET. So what does that actually entail? Well, you know, I go around talking about cybersecurity and the current threat landscapes and things like that at conferences and to the media, but I also work with a number of technology partners as well. So, some of the underlying companies that we all rely on from cybersecurity perspectives and in generally our day-to-day lives, I try and look after some of those relationships, find out what they’re doing and stuff as well. So, pretty interesting stuff. And just to give you the snippet of where did I come from: well, I’ve been in the business 30 years, and I started life as a COBOL and FORTRAN programmer. Now poor old Leland here is going to have to look that up.

Leland McFarland: No, I learned about FORTRAN back in… My career started out with a computer programming degree at Oregon State University, so I actually studied it a little bit. Not a lot, but I know where you’re coming from.

Tony Anscombe: Well, it was on punch cards if that if that rings any bells. So, yeah, going back a bit.

Leland McFarland: Great. All right, so when you look at small IT teams today, what are the absolute biggest hurdles they face trying to lock down a small business?

Tony Anscombe: Well, it is challenging, and I think AI has added some elements to this that probably is drawing—not confusion, I think there’s an element of unknown in there when you start talking about AI. Are we talking about threats? Are we talking about the deployment of AI, etc., etc.? And I know we’re going to get to some of that in the interview, but if you overlay that then on my questions, you’ve got the whole issue of cybercriminals don’t come when you expect them to come. They don’t work 9 to 5, they’re not in your time zone, unfortunately. So, you know, the big challenges out there are 24/7 monitoring. So realistically, today, to protect a business, you’ve got to be protecting it day and night, every day of the week, because at 3:00 on a Sunday morning, that’s when the cybercriminal’s going to come knocking on the door. And are your teams there?

The other big one I think in there at the moment—and this is kind of on that AI-related—is vulnerability and patch management. You know, if you look over the last 12 months, in fact, to the start of this year, the first three months of this year—and I’ll just use this as an indication—you know, Microsoft’s Patch Tuesday, that fateful day where your machine turns around and says it’s updating… At the start of the year, they used to patch for the first three months between 150 and 200 fixes per Patch Tuesday. September was 974. And that’s because AI is being used to find the vulnerabilities at a scale that we’ve never seen. So I think as a small business trying to keep pace with some of that—and you know, the Patch Tuesday one is a fairly automated process, but you think of all the different components, all the different software, all the different hardware you’ve got in a business—keeping up at that scale, I think, is virtually impossible.

Leland McFarland: Right. Small businesses sometimes assume that they aren’t large or valuable enough to be a serious target. I’ve heard stories otherwise, but why is that mindset very dangerous today?

Tony Anscombe: Well, it certainly is dangerous, and one of the reasons is because small businesses are a conduit. They’ve got partnerships with bigger businesses, so they could be the weakness in the chain. I’m going to use an example here because actually, I think it was on such a mass scale that I think it’s important to understand the learnings from it. Jaguar Land Rover, JLR, had that cyber incident. It was fairly well-published across the world. Shut down production of their entire car plants in multiple countries, and it cost around just under £2 billion for the cyber incident. I can’t even start to fathom how you recover from that.

The importance here, though, is there were 5,000 small businesses involved. They had to lay off nearly 300,000 people between them. So when you start thinking about that, now, obviously that incident was JLR, so it’s the primary, it’s the hub of all things, and that doesn’t really answer your question. But it was actually a small business in amongst that mix that caused the issue. It was a service provider that was compromised, and thus JLR was compromised. So there you go. That’s why you’ve probably got information that somebody wants.

And even if you’re not in what I’d define as the service chain—i.e., maybe you’ve got credentials or maybe you’ve got access to their systems or whatever—if you were a service provider that you made the magic screw that held the gearbox together, and as a cybercriminal I can work out that supply chain and I can come and take you offline, and I can bring JLR’s production line to a halt because they can no longer get the magic screw, then you’re holding a really influential part of that supply chain for them. So my point here is, however small your business is, you’re probably critical to someone. And it’s when a cybercriminal realizes that, then actually you just made yourself a target.

Leland McFarland: Right. Is there a point where SMBs should recognize that managing cybersecurity entirely in-house is no longer realistic, and what warning signs should an owner or IT manager be looking for?

Tony Anscombe: Well, firstly, I’d like to suggest that owners and IT managers in small businesses stop thinking of this as cyber risk, because I think we historically all think about, “Yeah, the computer’s down,” or this—it’s blamed on IT; it’s blamed on cyber connectivity. This is about business risk. And you need to approach cyber with a business risk hat on.

So, you know, can your business survive? Can you be realistic about being able to do 24/7 monitoring, because we know that cybercriminals come at those weird times of day? Do you have trained security analysts on staff? If you don’t, do you have access to them in a fairly free way? I.e., can you access them when you need them, or are you on a long list of customers that are in the line for them?

My point here is I think you need to ask yourself the question of, “Can my business survive a cyber incident? If a cyber incident unfolds today, how resilient am I?” If I’m not resilient enough, then I need to be going to get some help. Can I keep my business operational? And you see even big companies don’t do this very well. There’s incidents around the globe where you see a big company go offline for two, three days if they have a big cyber incident—the JLR one as we just talked about is a good example for weeks. But then you see a small business down the street switch to paper, and, you know, they turn their business around and keep it going. So, could you keep going? And I think that to me would be the telling time of: if I can keep going, then maybe I don’t need the outside help; if I can’t, then I do.

Leland McFarland: All right. A lot of small companies have an IT person or a small IT team, but not a dedicated security team. What is the difference between being good at IT and having the expertise needed to detect and respond to modern cyberattacks?

Tony Anscombe: I heard somebody put this in such a beautiful way recently. So, you have a family practitioner, and the family practitioner is pretty good at telling you whether you’ve got flu or whether you’ve got something that needs a specialized doctor to look at it. Would you trust your family practitioner to do the neurosurgery? Therein is—I think we just answered the question, didn’t we? That’s why you need security experts.

When you look at the sophistication of a cyberattack today, it can be really complicated, because cybercriminals don’t just deploy a piece of malware and carry on. They infiltrate, they move laterally around networks, they exfiltrate data, there may never be any malware. They might have persistence in the network—i.e., they may have left themselves multiple methods in, so even if you lock one… So you need that specialized doctor. You need the security analyst, that expert, to help you out. And I thank whoever it was that I heard use the medical analogy. I thank them for it because everybody smiles when you use it, and it’s like, “Oh yeah, okay.”

Leland McFarland: That is a great example. It really kind of hits home how important the difference is between the average guy who’s good with technology and the person who has dedicated their life towards actually stopping cyberattacks. All right. Cybersecurity increasingly requires round-the-clock monitoring. What can happen if an attack begins at 2:00 AM on a Saturday and no one is actively watching the environment until Monday morning?

Tony Anscombe: Well, as you roll out of the nightclub at 2:00 AM on a Saturday morning and your phone goes off saying you’ve got a security alert… No. You know, and I say that with jest because at my age I’m not going to a nightclub anymore, certainly not at 2:00 AM in the morning.

But my point here is if a cybercriminal can gain access at 2:00 AM on a Saturday morning, then basically, if your business is a Monday to Friday business, realistically they’ve got two days to sit there and move around, work out what data is important, exfiltrate it, and by the time you come in on Monday morning, you’re either facing a data breach or you’re facing a system that’s completely non-operational. So, I can’t express enough that actually you need that continual monitoring. And even if you’re a small business and you don’t have that 24/7 response, or you haven’t got systems that can respond automatically, then you’re not going to be in a good shape in today’s world, unfortunately.

And I think most companies are starting to understand that. I think more sophisticated cybersecurity solutions are being either implemented, are implemented, or are thought about within the next 12 months, so I think we are starting to see that change from the business side.

Leland McFarland: Great. All right, enterprise-managed services usually come with an enterprise-grade price tag. What realistic options are there out there for small and mid-sized businesses that still need robust security?

Tony Anscombe: Well, firstly, I’ll say that you can’t think of cybersecurity… It’s about the value of keeping your business running, so can you afford to be without it? And yes, there’s an element of risk in here that you have to then calculate, i.e., if this happens and I lose my business for the next two weeks, does my business actually survive? So therefore, then you’ve got to calculate what it is that you’re willing to spend or what I need to spend to make sure that my business will continue or will recover in a good time frame. So you have to think about your appetite for risk, so to speak, as a business owner.

Now, the second part of that question is: actually, no, it doesn’t necessarily need to be expensive. It’s about finding the right partner, and actually at ESET, we have recently repackaged our MDR. Obviously when we bring out product releases, there’s new features and all those sorts of things, but we’ve kind of repackaged it and taken the view that actually, MDR should be available to everyone. It should be, and there should be a price option that all businesses could take advantage of. And I’d recommend come talk to us or come talk to an MSP and actually find out what it would cost to have the right protection and the different levels of protection being offered, so that you can then work out where your appetite for risk is or what your business can actually afford to implement.

Leland McFarland: So AI is giving attackers new ways to automate phishing, reconnaissance, and other parts of an attack, while businesses themselves are rapidly adopting tools like generative AI and AI agents. How is that changing the security challenge for small businesses?

Tony Anscombe: Well, we’re all doomed, aren’t we, Leland? You know, AI’s coming and it’s… No, I kind of say that tongue-in-cheek, because we’re not. I think there are lots of things coming that are a problem. So, in a business, if you’re a small or medium business—and in fact, I’d say even a lot of bigger businesses still don’t have a handle on this—you potentially have got data leakage. I’d ask you the question, Leland: do you ever actually look anything up using an LLM? Have you crafted a piece of text? And you’re smiling on the video stream, so I know…

Leland McFarland: Yeah, a couple times.

Tony Anscombe: Yeah, right. Have you ever uploaded something that could become company-sensitive? Hmm. You have to think about that.

Leland McFarland: I try not to. I try not to.

Tony Anscombe: Yeah. But the problem is, you and I probably know very well because we’re in the industry that we shouldn’t be doing this, but we step down into industries where actually the people aren’t as aware as we are—I think is a better term for that. They may well upload data; they could be uploading IP; they could be asking a system to rewrite their emails or rewrite some text. But actually, if they’re doing that on a public system, then obviously that data leakage, that information is going into the training of the next version of the model. So potentially it could be resurfaced at some stage to somebody else.

Then you’ve got agent activity, and that’s kind of where my tongue-in-cheek bit was: “We’re all doomed, the rogue agents are coming.” No, no, you know… If you run it, but I think there’s two sides to that. If you’re running agents internally, so an employee might be running an agent—I saw some AI skills recently, some pretty cool skills actually, that teach an agent how to create PowerPoint presentations. You upload a couple of pages of text, it creates the slides and the speaker notes for you. You know, that could be a useful tool to a lot of people, at least to get your presentation started, etc. But again, you’re expanding the entire attack surface using this type of thing. And AI skills—we recently published some research that showed they can be malicious. Bad actors have realized this and are infiltrating them and putting bad code in them.

AI-generated content: when an AI agent does give you that text back, creates that presentation, are you verifying what it tells you? Are you actually verifying the output from the agent, or are you using it for business purposes? I think a lot of people would just trust it: “Well, the AI told me that, it must be right.” And put it in the email and send it to a customer, and people aren’t looking at it. So you’ve got this lack of general visibility as well.

But on the other side of that, attacks are unfolding faster, deception’s easier, you’ve got this extended attack surface. It’s a challenge. Look, AI is a challenge, and right up front I said it’s the unknown, because you’re seeing this unfold at a pace where I think it’s challenging for anybody to keep up.

Leland McFarland: So when an SMB brings in an MSP or managed security provider, what responsibilities should still remain inside the business? In other words, what parts of cybersecurity shouldn’t simply be handed off and forgotten about?

Tony Anscombe: Well, firstly, you’re partnering. You’re not handing off; you’re partnering. You’re doing this with somebody. So there are certain things that should remain internal. Governance and policy remain an internal issue. So the service provider is providing something to within the policies that you want to have in your company, and you need to make sure the service matches your policy and continues to make you compliant. There may be regulatory issues, there might be legislation that requires you to do certain things, especially if you’re in healthcare or you’re in critical infrastructure or such like, or you’ve just as a business got to adhere to privacy legislation depending on where you might be doing business around the world. So some of these things need to stay within your organization.

Training is a good example; training of your own employees on cybersecurity awareness, that’s definitely something that remains on your internal side. And business resilience planning—cyber, the bit that you’re outsourcing, is a part of the puzzle. Can your business manage if you did have an incident? And bear in mind incidents aren’t always cyberattacks; could be a power outage, it could be an internet outage, who knows? But will your business survive? Business resilience planning definitely belongs internal, and a large element of that is cybersecurity.

The other one I’d add in there is crisis management. Crisis management is part of a cybersecurity plan, but these days that might be handed off to an insurer, so there you go, you might have another third party involved here doing your crisis management as well. So then it’s about being the director of the play and keeping all the acts on the stage at the right time and making sure they’re all doing the right things for your business.

Leland McFarland: So we hear a lot about detection, but detection is only useful when someone actually responds. What should a small business expect to happen after a managed security service identifies a serious threat?

Tony Anscombe: Well, firstly, if they’ve identified a seriou