
What to automate first in a small business
Choose a first automation by scoring the work, data, risk, ownership, and reversibility. Then validate one pilot before you expand it.
In 2025, Slovak companies saw a record increase in phishing attacks. This shouldn't be surprising. Attackers now have tools they could only dream of a few years ago. Large language models generate convincing emails without grammatical errors. AI can clone a voice from just 3 seconds of recording. Deepfake videos are increasingly indistinguishable from reality. According to the ENISA 2025 report, the number of AI-assisted phishing attacks in the EU increased by 135%.
Cybersecurity is no longer just about firewalls and antivirus software. It's about whether your people can recognize a well-crafted attack.
Traditional phishing was relatively easy to spot. Poor grammar, suspicious sender, generic message. AI phishing is a different league.
AI can analyze publicly available information about the target (LinkedIn profile, company website, social media) and create an email that looks like it was written by a specific person from the company. No typos, the right tone, relevant context.
One of the traditional warning signs was poor language in phishing emails. With LLM models, this warning disappears. AI generates fluent, grammatically correct text including industry terminology.
How many of your employees would be able to distinguish a perfectly written phishing email from a real internal message?
Attackers combine AI with OSINT (open source intelligence). They monitor public procurements, company changes, financial statements. The phishing email then arrives at the right time with relevant content.
In 2025, cases emerged where attackers used deepfake voices for calls to managers:
Just a few seconds of publicly available voice recording (podcast, video, conference recording) and AI creates a convincing deepfake. Combined with phone number spoofing, the attack is nearly perfect.
Technology alone isn't enough. Without established internal procedures, it's only half the solution.
When a request changes banking details, a safer system flags it for verification through a second channel and records the change in an audit log. The rule should be evaluated from confirmed incidents and false positives, not an unsupported marketing anecdote.
If you answered "no" to more than two questions, it's time to act. Contact us. We'll help you set up processes and tools so your company isn't an easy target.

Choose a first automation by scoring the work, data, risk, ownership, and reversibility. Then validate one pilot before you expand it.
The AI Act applies fully from August 2, 2026. AI used for job ads, CV screening, and candidate scoring falls under high-risk rules. Practical compliance guide.
Companies either ignore AI or try to change everything at once. Both are wrong. Here's a realistic 30-day plan.