UpTrajectory Review
Harvard Business Review has published a piece by Daniel Dobrygowski on how artificial intelligence is reshaping both cyber threats and the defenses available to small businesses, framed around five concrete actions leaders can take. The available excerpt is minimal—essentially a subtitle—so this review addresses what the headline and framing signal, and what small-business operators should expect from the full article. Dobrygowski writes frequently on cybersecurity policy and governance, which suggests the piece likely bridges technical threat dynamics with organizational decision-making rather than offering a purely tactical checklist.
For small-business operators, the premise alone is worth taking seriously. AI has lowered the cost of generating convincing phishing emails, deepfake voice calls, and automated vulnerability scanning, meaning attackers can now run operations that once required significant skill and manpower. At the same time, AI-driven security tools—automated threat detection, anomaly monitoring, and response orchestration—have become more accessible to organizations without dedicated security teams. The asymmetry question is real: does AI help attackers more than defenders, or does it democratize defense? The framing of the article suggests Dobrygowski believes small businesses are not helpless, but only if leadership treats cybersecurity as an operational priority rather than an IT afterthought.
The five-actions structure is a familiar HBR format, and it carries both strengths and limitations. On the positive side, it implies the article moves beyond awareness-raising into prescriptive territory—likely covering areas such as employee training, vendor and supply-chain risk, incident response planning, and the adoption of AI-assisted security tooling. Where we would urge some skepticism is in the assumption that small-business leaders have the bandwidth, budget, or technical literacy to evaluate AI-based security products effectively. The market is crowded with vendors marketing 'AI-powered' solutions of wildly varying quality, and a listicle format rarely leaves room for the kind of procurement discernment operators actually need.
The downstream effects of AI-driven threat escalation are unevenly distributed. Businesses that handle sensitive customer data—healthcare providers, financial services firms, legal practices—face higher regulatory and reputational stakes if breached, yet often lack enterprise-grade security infrastructure. Retailers and hospitality businesses face payment-card and point-of-sale risks amplified by social engineering. Meanwhile, the rise of AI-enabled defense tools may widen the gap between businesses that can afford managed security service providers and those relying on off-the-shelf software. There is also a workforce dimension: as AI handles more routine threat detection, the human skills that matter most shift toward judgment, incident communication, and vendor oversight—capabilities that are harder to outsource.
Operators should read the full article with two questions in mind: which of the five actions can be implemented within thirty days at minimal cost, and which require a longer-term investment in either tooling or outside expertise. At minimum, businesses should audit their current exposure to AI-enhanced social engineering—voice-cloned executive impersonation and highly personalized phishing are no longer theoretical—and ensure that verification protocols for financial transactions and data access do not rely solely on email or voice confirmation. Watching how cyber insurance carriers adjust their requirements in response to AI-driven threat trends will also be instructive, as insurers are often the first to mandate specific controls when loss patterns shift.
The broader signal here is that cybersecurity is no longer a problem that small businesses can defer to a managed service provider and forget. AI has compressed the timeline between vulnerability discovery and exploitation, and it has made sophisticated attacks economically viable against targets that would previously have been too small to attract attention. Whether Dobrygowski's five actions fully account for the resource constraints of the smallest businesses remains to be seen, but the article's existence in a mainstream management publication underscores that the topic has moved from the IT department to the leadership agenda.
Takeaway: Treat AI-enhanced social engineering as an active threat: audit your verification protocols for financial transactions and data access before attackers audit them for you.
Excerpt from the original — Harvard Business Review
<p>Five actions leaders can take.</p>