Small business cyber security handbook
Explore the practical steps small business can take to protect their systems, data, staff and customers from cyber threats.
- Published
-
- Last reviewed
-
Using AI securely in your business
Artificial intelligence (AI) refers to tools that allow computers to perform tasks that normally require human thinking, such as problem-solving, understanding language and making decisions. AI can help you save time, improve efficiency for your staff, and support decision-making by analysing data and generating insights for your business.
You are likely already using AI in everyday business tools, including:
- chatbots and virtual assistants for customer service
- translation tools for communication
- platforms that recommend products or content
- tools that help you write emails, create plans or summarise information.
While these tools can be useful, you should use them carefully and understand the risks involved. You should avoid sharing sensitive business or customer information, such as passwords, financial details or confidential data. Many AI tools may store or use your data to improve their systems, so it’s important to know how your information is handled.
Before using an AI tool in your business, you should consider:
- whether the provider is reputable and trustworthy
- whether you really need to share the information requested
- how and where your data will be stored, used or shared
- what the provider’s privacy policy says
- whether you can verify and trust the outputs provided.
You should also be aware of privacy risks. AI systems often rely on large amounts of data, which can make them attractive targets for cybercriminals. Even if data is anonymised, there is still a risk it could be re-identified. This means you should treat AI tools like any other online service, helpful, but not always private or secure. To use AI safely in your business, you should:
Control your digital footprint
Use tools that allow you to delete history or limit data storage and consider separate accounts for testing new AI tools.
Watch for accuracy and bias
Do not rely on AI outputs alone. Always check important information, as results can be incorrect, incomplete or biased.
Prioritise security
Be cautious when using free or public AI tools, and follow any internal policies about sharing business information.
Be aware of data location
Understand where your data is stored and processed, especially if it is outside Australia, as different privacy laws may apply.
By taking a cautious and informed approach, you can benefit from AI while protecting your business, your customers and your data.
Be aware of AI-enabled scams
AI can be used by cybercriminals to create convincing phishing emails, fake invoices, impersonation messages, fake images and cloned voices. These techniques can make scams appear more legitimate and more difficult to identify.
Getting started
AI-generated content can be convincing and may be used to support scams, impersonation attempts or social engineering attacks. Train staff to recognise emerging AI-enabled threats and encourage them to question unexpected requests, even when messages appear professional, familiar or trustworthy.
Staff should also be aware of what information can and cannot be entered into AI systems, particularly business-sensitive, customer, personal or confidential information.
When assessing the legitimacy of a request, do not rely solely on the appearance, tone or quality of the message, and always confirm important actions through trusted communication channels.
Using AI agents securely in your business
Some AI tools can act on your behalf by completing tasks automatically, such as organising information, sending messages or interacting with other business applications. These are known as AI agents. While they can improve efficiency and save time, they can also increase security and privacy risks if they are given too much access or control.
As a small business owner, you should be mindful of how much authority you give these tools. AI agents can sometimes act quickly and independently, so it’s important that you stay in control of key decisions and sensitive actions.
You should only enable features that you understand and genuinely need for your business. Before setting up an AI agent, you should carefully review what systems, accounts or data it can access. Avoid giving it permission to make significant changes, such as approving transactions, sending communications or modifying business data, without your oversight.
To use AI agents safely, you should:
Use trusted tools and providers
Choose reputable platforms with clear security and privacy practices.
Limit access from the start
Only give the agent the minimum access required to perform its task.
Understand permissions
Check what apps, systems and data the agent can access before enabling it.
Maintain control over important actions
Avoid allowing AI agents to make critical decisions or changes without your review.
Review and adjust settings regularly
Periodically check permissions and disable anything that is no longer needed.