Key Takeaways
- Small and medium-sized businesses (SMBs) must take simple-to-solve vulnerabilities more seriously, including the lack of multi-factor authentication (MFA).
- The increasing use of artificial intelligence (AI) poses new threats, including the potential for AI to be used to find and raise grievances with bosses.
- Changes in global regulations, such as the implementation of digital business identity systems, will require SMBs to adapt and integrate seamlessly with new ID frameworks.
- Governance and oversight of AI tools must be a top priority for SMBs to avoid compliance breaches, data leakage, and reputational damage.
- Preventing costly payouts and outages or disruptions will require SMBs to understand their risk, have adequate insurance in place, and invest in digital tools to automate tasks and free up IT teams.
Introduction to the Challenges of 2026
As we transition into a new year, small and medium-sized businesses (SMBs) are turning their attention to planning for 2026 and beyond. This involves identifying the tech problems on the horizon as much as the opportunities they can take advantage of. Throughout 2025, businesses were plagued by many issues, from successful hacking attacks to struggles over how to integrate AI into their operations. Looking ahead, experts suggest that both will continue to cause trouble alongside other new or re-emerging potential pitfalls. To counter this, SMBs must start to take simple-to-solve vulnerabilities more seriously, according to Simon Hodgkinson, a former CISO at multinational energy giant BP.
The Importance of Multi-Factor Authentication
Hodgkinson points to the lack of multi-factor authentication (MFA) among SMBs as a simple but growing risk area that he perceives is becoming a major threat. He explains that the vast majority of SMBs are leaving themselves wide open to the most basic forms of attack, and that MFA has been compromised only by extremely sophisticated forms of attack. However, MFA will protect SMBs from 90% of drive-by attacks. Hodgkinson advises that greater resilience is important, and it must be built into operations during 2026 to deny such attempts. He also emphasizes that the application of controls can significantly reduce risk and, in the long run, the costs of containment.
New Threats from AI Use
Problems with growing levels of artificial intelligence (AI) being used internally have been well-documented, from the cybersecurity risks it throws up to the poor advice it might give. Phil Coxon, managing director at Breathe HR, points to an even more underestimated and under-the-radar AI issue he feels will be problematic in 2026. This issue highlights how technology is increasingly being used to find and raise grievances with bosses – and it’s this controversial role for AI that could spark rising troubles. Coxon explains that employment tribunal cases are on the rise, with lawyers noting signs of AI use by claimants. ChatGPT will no doubt serve up more grievances next year as workers look to assert new rights coming into effect as part of the hotly anticipated Employment Rights Bill.
Changes in Global Regulations
When it comes to leadership and resilience, former England Rugby Captain Martin Corry knows a thing or two about facing down the biggest challenges. Corry cites a continued push among some governments worldwide to implement plans for digital business identity systems as a challenge to watch for in 2026. He explains that businesses risk being left behind if they don’t integrate seamlessly with new ID frameworks or if they mishandle sensitive customer data. Corry adds that the solution is to view identity management not as back-office admin, but as a strategic capability. SMBs that adopt government-approved digital verification tools are better positioned to save costs, stay compliant, and deliver the secure, user-friendly experiences customers expect.
The Importance of Governance and Oversight
Chris Weston, senior technology consultant at NashTech, suggests that governance when adopting AI tools must now be at the top of leaders’ minds. He explains that the temptation is to roll out assistants or coding tools quickly to boost productivity, but without clear oversight, they risk compliance breaches, data leakage, and reputational damage. Weston argues that governance should be a first step rather than an afterthought, as this will ensure systems are “auditable, secure, and explainable” before SMBs are ready to scale. He adds that this will allow SMBs to unlock the benefits of AI without creating risks they can’t afford to manage.
Preventing Costly Payouts and Outages
James Tumbridge, data protection partner at Keystone Law, says that SMBs need to understand their risk, have adequate insurance in place, and invest in digital tools to automate tasks and free up IT teams. He explains that in today’s world, SMBs need to think about their system security and their insurance cover, or the lesson can be very painful. Tumbridge adds that SMBs must be able to justify their setup with legal advice, and if not, they might have a regulatory headache too. Another aspect that may cost SMBs money in 2026 is not preparing well enough or hard enough for outages or disruptions, whatever the cause.
The Importance of Transparency and Honesty
Planning for 2026 should involve transparency as much as possible, say many experts, who see honesty among SMBs as a powerful tool to drive productivity and profit. Ben Strawson, CTO at Future Platforms, advises that SMBs must ensure their employees are kept up-to-date on what is happening across the business – and crucially, why it is happening. This is especially true for the introduction of AI, as it can prevent challenges arising from colleagues who fear being replaced by the technology. Strawson emphasizes the importance of involving employees early in AI initiatives, providing training and upskilling where possible, and keeping information flowing about how and where AI is being used.


