Advanced AI can help attackers find and combine software weaknesses faster. Businesses now have less time to patch systems and contain an incident. A slow decision can disrupt customer work, invoices, payroll, payments, and cash.
Why this matters
Small firms often depend on cloud accounts, suppliers, and a few key people. An urgent alert can stall when nobody can approve downtime or block an account. In 2025, 13% of businesses with 2 to 10 workers used at least ten of twelve surveyed measures. The figure was 86% for firms with 250 or more workers. Since 15 August 2026, organisations covered by the law must manage cyber risks and report significant incidents. Their boards approve the measures and oversee the work.
Example
An installation company receives an urgent patch warning at 08:20. Installing it will stop the planning system for two hours. The founder is with a customer. The office manager cannot approve downtime, and the IT provider needs permission. The patch waits. An attack could deny technicians access to addresses, work orders, and customer notes. Completed jobs cannot be checked, so invoices are delayed. Staff rebuild the day from messages and memory. Named authority would avoid that delay.
XTROVERSO tips
- Name the decision-makers. Record who may approve an urgent patch, disable an account, or accept temporary downtime. Appoint a backup for every critical decision.
- List the systems that keep cash moving. Identify systems needed for sales, planning, payroll, invoices, payment approval, and customer service. Record the owner and supplier for each system.
- Review privileged access. Request a current list of administrator accounts and remote-access routes. Remove access for former staff and suppliers who no longer need it.
- Set clear supplier duties. Agree who monitors alerts, installs patches, keeps logs, tests backups, and reports incidents. Put these duties in the contract or service file.
- Test one recovery route. Restore a critical file, account, or system. Check whether recovery works without relying on one person’s memory.
- Verify unusual payment requests. Confirm bank-detail changes and unexpected payments through a known, separate contact route. Do not rely on email, chat, or a familiar voice alone.
Need clear cyber decision rights, supplier duties, and recovery steps? We can put them in one practical control file
The data, sourcing, and analysis behind this article were conducted by Paolo Maria Pavan. AI was not used to identify sources, build the factual basis, or produce the analytical judgment contained here. AI was used only as a drafting aid. The final English text was personally reviewed, edited, and approved by Paolo Maria Pavan before publication.
References
- AFM — Snellere AI-aanvallen vragen om sterkere weerbaarheid
- De Nederlandsche Bank — Krachtiger AI-modellen en cyberrisico’s
- Rijksoverheid — Cyberbeveiligingswet en bestuurlijke verantwoordelijkheid
- CBS — Cyberincidenten en weerbaarheid van bedrijven
- CBS — Gebruik van AI-technologie door Nederlandse microbedrijven
- AFM — Risicobeheersing, DORA en uitbestede ICT
- AFM — Financiële stabiliteit en AI-ondersteunde fraude


