September 2026
AI made attacks cheaper. Here is what changed, and what did not
Phishing that reads like your accountant, malware written by someone who cannot code, attacks that adapt in minutes. What that means for a business of thirty people, and the things that still stop most of it.
By Nate Weigel, Protection Director
A year ago a convincing phishing email took a criminal with decent English and an afternoon. Now it takes a prompt. The email that lands in your controller's inbox reads like your accountant wrote it, references a real invoice number, and arrives at the moment they are expecting one. The malware behind the link was written by someone who cannot program, using a tool that can. And when the first attempt is blocked, the next version is ready in minutes rather than weeks.
That is what changed. Attacks got faster to build, cheaper to run and easier to aim. People who could not have written an exploit last year are running campaigns this year. The volume is up, the quality is up, and the cost of trying is close to zero, which means everyone is a target, including a thirty-person insurance agency in Walworth County.
Here is what did not change. Most successful attacks still start with a stolen password, a missing update or a person who was tricked. AI made the trick better; it did not invent a new door. Multi-factor authentication on everything, conditional access that refuses a login from an unmanaged device, patching that actually happens, a backup that ransomware cannot reach, and staff who have seen a convincing fake before the real one arrives. Those five things still stop the large majority of what we see, and they are not expensive.
What a fast-moving threat does change is how your IT company has to work. It is not enough to have bought good tools in 2023. Somebody has to know each tool's gap, watch what the attackers are doing this month, and adjust before it reaches you. We have a team whose job is exactly that: staying ahead of threats, sometimes years ahead, so that when a new technique shows up in the wild, our clients are already covered, not reading about it in the news.
It also changes what you should expect from the relationship. When something happens that affects your business, a new attack on the software you run, a breach at a vendor you use, a change your insurer will ask about, you should hear it quickly, accurately, from a partner who is accountable to you. Not a newsletter, not a sales call, and not silence.
Three questions to ask whoever protects you today. Which of our security products has a known gap, and what covers it? What changed in the last ninety days, and what did you change because of it? If a convincing email reached our controller tomorrow, what would stop the payment? If the answers are slow, it may be time to ask us instead.
From people who chose local


Order the internet circuit the week the lease is signed. Carriers take six to twelve weeks. Nothing else on a move fails as often.
The relocation checklist Did you knowA backup that has never been restored is a hope, not a plan. Ask for the date of the last tested restore.
What to actually testGo deeper

"Great, great, great. Fast, prompt, knowledgeable. Thank you!"
Senada, insurance brokerageMore from the survey wall- A technician who knows your setup takes every request. Not a dispatcher, not a queue.
- Every closed ticket is surveyed and a partner reads every response.
- 99.5% of surveys come back positive.
- Family-owned since 2005. 21 years in the same corner of Wisconsin, not going anywhere.
"Tyler got to my request very quickly and resolved the issue within minutes."
Nichole, insurance brokerageTalk to a partner, not a sales script.
Tell us what is going on. A partner will call you back the same business day, look at what you have, and tell you honestly whether we are the right fit. No pricing pressure, no pitch deck.
