Amid all the headlines about AIpowered malware appearing and sophisticated malicious tools evading endpoint security tools, one cyber threat remains consistently overlooked: phishing.

Yes, AI tools, assistants, and chatbots are a new cybersecurity risk, but when ESET asked more than two thousand SMBs what caused cyber incidents they’d experienced, they mostly answered “phishing.” Despite their answers, only 26% consider it a major threat, according to the ESET SMB Cyber Readiness Index 2026.

The Index also highlights a simple truth: The best way to address threats targeting your employees is to train them. Most businesses (98%) surveyed in this report already do so, benefiting from the resilience and confidence that come with highquality cybersecurity training and phishing simulations.

Key points of this article:

  • ESET SMB Cyber Readiness Index 2026 shows phishing and social engineering cause the largest share of cyber incidents among SMBs, yet many businesses still don’t consider them their top concern.
  • Most breaches involve the human element, and many attacks begin with simple interactions like clicking on phishing emails, highlighting employees as a critical vulnerability.
  • AI-driven tools enable highly convincing scams, including deepfakes and personalized spear phishing messages, increasing both the effectiveness and volume of attacks.
  • Most SMBs now invest in training programs and phishing simulations, which improve resilience, reduce the impact of attacks, and help meet compliance and insurance requirements.
  • ESET not only created a highly effective training program but also designed it to be SMB-friendly – it can be led by personnel, even without technical experience.

Phishing is more prevalent, yet less recognized

Phishing and social engineering/impersonation combined are the leading causes of cyber incidents among SMBs, accounting for 43% of cases, according to the ESET SMB Cyber Readiness Index 2026. 

reaons of cyber incidents

At the same time, ESET telemetry confirms that phishing is the top threat detected, and the number of detections is rising. In 2025, 34% of all threats reported via ESET telemetry were phishing and phishing-related. Phishing is dominant also among email threats. 

phihisng number one

Yet, the surveyed businesses don’t view it as a particularly serious issue. Only 26% identified phishing or spear phishing as their top concern, and even fewer (12%) said they were most concerned about social engineering.

most concerning threats

Why businesses should be more concerned about social engineering and employee interaction with AI

Most intrusions start with phishing

Keeping up with news about increasingly complex malware and sophisticated scam tactics can give business leaders a misleading impression of what cyberattacks actually look like. The reality is that no matter how advanced the malware eventually deployed is, most attacks still begin with a simple human interaction – often a phishing email.

Phishing is not only the leading cause of incidents (as not every incident escalates into a data breach), but, according to IBM’s Cost of a Data Breach Report 2025, it is also the most common initial attack vector. Phishing was the starting point for 16% of all detected breaches, and, at an average cost of $4.8 million per breach, it was the third-costliest vector, surpassed only by vendor/supply chain compromise ($4.91 million) and malicious insider incidents ($4.92 million).

AIpowered phishing is dramatically more effective

A clear example is the rise of Nomani scams, an ESET-defined umbrella term for fraudulent ads promoting fake investment schemes, miracle products, and similar social mediadriven scams that began spreading widely in 2024.

ESET researchers have observed that deepfakes used as hooks for phishing websites or forms to fill out have significantly improved, through:

  • higher resolution
  • fewer unnatural movements
  • increasingly natural “breathing”
  • better audio/video synchronization

These advances make it far more difficult for potential victims to recognize a deception at first glance.

This threat is not only improving in quality but also growing in volume. ESET telemetry shows a 62% increase in Nomani detections between 2024 and 2025, amounting to hundreds of thousands of detections worldwide. In total, more than 64,000 unique URLs were blocked in 2025.

Expert comment

"AI has made everything faster. ESET telemetry shows that a majority of cyberattacks against businesses begin with phishing emails. Traditionally, phishing tricks people into revealing personal data or downloading malware. Spear phishing goes further, utilizing personalized messages after attackers gather details about a specific target. Today, AI automates this process, making spear phishing increasingly common.

For example, you might publish a post about attending a conference on social media, and the next day, you could receive a fraudulent email from a person claiming to have met you there, offering photos and wanting to connect with you. For a person lacking awareness, it is easy to get hooked and click on a malicious link."

- Július Selecký, ESET Solution Architect

Scams and phishing get more sophisticated

Cybercriminals not only utilize AI tools, but they are also willing to go the extra mile to increase their success rate.

For example, ESET researchers observed the Iranaligned threat group MuddyWater sending spear phishing emails internally from previously compromised inboxes within targeted organizations, a technique that significantly increases credibility and success.

Other phishing methods, such as SMS phishing (smishing) and voice phishing (vishing), have also evolved:

Expert comment

"Scammers continue to use familiar strategies, but, as public awareness grows, they are forced to adapt by refining their call center scripts and tactics to appear more convincing. A notable trend is the increasing use of native speakers as operators in scam call centers, which significantly boosts the credibility of fraudulent calls. Additionally, follow-up scams that exploit the names of reputable local or international law enforcement agencies, such as Europol, have become increasingly prevalent."

Ondřej Novotný, ESET Senior Detection Engineer

Human error remains a massive vulnerability

According to the Verizon 2025 Data Breach Investigations Report (DBIR), the human element played a role in about 60% of breaches, including social engineering actions (such as phishing for credentials), user errors, and interactions with malware.

AI tools create new attack surfaces

At the same time, it’s also true that broadening use of AI has introduced new risks. ESET data shows that AI tools are widely (73%) integrated by SMBs while a majority of respondents (70%) also acknowledge that it introduces new risks.

And the risks are real: AI agents can be misconfigured and bypass security layers, or be directly abused by attackers to steal data.  

SMB-ai-tools-risks

Businesses invest in cybersecurity awareness trainings

The high level of confidence among U.S. businesses in their ability to handle phishing and social engineering likely stems from their investment in cybersecurity awareness programs. While many businesses detect phishing attempts as incidents, these often do not escalate into breaches or cause tangible harm, thanks, in part, to trained employees.

The vast majority (87%) of globally surveyed SMBs consider cybersecurity training and awareness critical or very important for preventing attacks, while the numbers are even higher (93%) in cases of North American businesses.

 importance of training

And they are true to their word, with 72% of them claiming to have comprehensive, high-quality training programs, including phishing simulations. Another 22% (often smaller companies under 100 seats) have at least basic programs.

Also, a majority of businesses (67%) conduct training courses more than once a year.

 training situatoin and frequency

It’s important to note that cyber awareness training is now routinely required by insurance companies and is essential for meeting various cybersecurity compliance regulations. ESET data shows that 86% of surveyed businesses have cyber insurance, and many of them must comply with a range of regulatory or industry standards.

 cyber insurance

 

How ESET can train your employees 

ESET understands that human error is one of the most serious threat vectors, going far beyond jokes about problems being “between the chair and the keyboard.” As such, human error should be addressed just like any other layer of cybersecurity defense:

Training should be effective first and foremost – If your employees are bored during a training session and cannot recall anything an hour after answering compulsory test questions, the entire effort is meaningless. As with any type of learning, cybersecurity training should be engaging, creating lasting memories and associations.

Address the latest threats – Just like your endpoint security, awareness training should cover the latest threats, including AI-generated phishing content, deepfakes, and advanced scams.

Easy to onboard and manage – SMBs have limited resources, and IT personnel cannot guide every employee step by step toward cybersecurity awareness. The training program should be easy to deploy and manage, provide full visibility into employees’ knowledge levels, and allow phishing simulations to be launched in just a few clicks.

Support compliance – Because cybersecurity training is not just about ticking compliance boxes, it should also help meet cyber insurance and regulatory requirements to support smooth business operations.

ESET Cybersecurity Awareness Training is a comprehensive solution to effectively train your employees without placing unnecessary strain on your IT administrators.

It consists of interactive modules, including role-plays and challenges, covering phishing, malware, password management, data privacy, AI/ChatGPT risks, social engineering, and more. To avoid repetition, ESET updates training sessions frequently. The phishing simulator enables organizations to conduct unlimited phishing tests using hundreds of regularly updated templates. Employees who complete the gamified training receive an industry-recognized certification and a LinkedIn badge, boosting their professional credibility.

At the same time, the training is business friendly. ESET Cybersecurity Awareness Training is designed to be set up by anyone, even without technical experience. It integrates with many popular cloud-based services, including Microsoft 365, Google Workspace, and Slack, and it includes a user-friendly dashboard for easy employee enrollment, real-time reporting, scheduling and progress monitoring—even at the level of individual employees.

Description: 2026 ECAT ESET Cybersecurity Awareness Training demo

Knowledge is key, practice makes perfect

SMBs live in a world where a weak password can be cracked in milliseconds, deepfakes can be unrecognizable and automated phishing campaigns can catch any employee off-guard, even those with IT education.

The AI revolution means that old threats are still present, but more dangerous, and novel ones are often neglected, increasing probability that an employee will make a mistake leading to a data breach.

Prepare your employees for today’s cyber threat landscape with ESET Cybersecurity Awareness Training.

Frequently asked questions (FAQs)

Why is phishing still among the biggest cybersecurity threats for SMBs?

Phishing remains the leading cause of cyber incidents because most attacks start with human interaction, such as clicking a malicious link or sharing sensitive information. Even though advanced malware gets more attention, phishing is responsible for the largest share of incidents, and it continues to grow in volume and sophistication.

Has AI made phishing attacks more dangerous?

Yes. AI has significantly improved phishing effectiveness by enabling highly personalized spear phishing messages, realistic deepfakes, and automated attack campaigns. These enhancements make phishing attempts harder to detect and more convincing for victims.

How does cybersecurity awareness training help reduce risk?

Training reduces risk by teaching employees how to recognize and respond to threats like phishing and social engineering. Organizations with strong training programs and phishing simulations are likely to experience fewer incidents escalating into serious breaches, improving overall resilience. For example, considering that an average breach cost reaches USD 4.44 million, cybersecurity training decreases this number by more than USD 192,000, according to the Cost of a Data Breach Report 2025 from IBM and Ponemon Institute.

What makes an effective cybersecurity awareness training program?

An effective program should be engaging and up to date with the latest threats (including AIdriven attacks), and it should utilize realworld simulations. From an SMBs perspective, it is also important to have a training program that is easy to manage, with measurable progress tracking and supportive of compliance requirements.