The same password for everything, a fake invoice “from the director” and a former colleague who can still log in. This is not a film. This is Tuesday.
Security is the department that only exists once things go wrong. Until then it is a password in a shared Excel sheet, a backup that is “running”, and a colleague pasting customer data into a free chatbot. AI changes two things here at once: attackers get better because of it, and you can use it to automate the tedious security chores that currently get left undone. The basics remain the basics: two-factor authentication, backups you have tested, and calling back when a bank account number changes.
// A feature at a fictional trading company with 22 employees, Microsoft 365, an external IT partner “for when things break”, and a director who has his email on three devices without two-factor authentication. The company is fictional, the situations are real: we run into them again and again.
Sound familiar?
- The same password for everything, written down in a shared Excel sheet.
- No two-factor authentication on the director’s mailbox, “because it is a hassle”.
- The fake invoice email “from the director” with a changed bank account number that was almost paid.
- The former employee whose account keeps working for months.
- The backup that is “running”, but has never been restored. The NAS sits next to the server.
- The colleague who pastes customer data into free ChatGPT to write an email.
- “Which folder is the contract in?” Five versions in mail, Drive and Dropbox.
- A major customer asks whether you can demonstrate that you work securely. Nobody knows what to answer.
What usually runs here
The software we come across here most often. It does not have to go; we build around it and in between.
A day in it, security & data: now and next
On the left, the day as it usually runs now. On the right, the same day once the dull parts are automated and AI does the groundwork. Watch what changes: not the people, but where their time goes.
- 08:20AdminEmail “from the director”: urgent payment to a new bank account number, he is in a meeting. She hesitates, but the tone sounds right. She prepares the payment.
- 09:15DirectorLogs in to his email from a hotel wifi. Password: the same as for the webshop and the bank.
- 10:30Sales repPastes a customer list with names and email addresses into a free chatbot to write a “personal” mailing.
- 13:00Office managerLooks for the contract with a supplier. Finds version 2 in the mail, version 3 in Dropbox, version “final” nowhere.
- 14:30IT partnerCalls back about the backup: “it runs every night.” It has never been restored. The NAS sits next to the server.
- 16:00HRAn employee who left in June turns out to still have access to SharePoint. The account was “forgotten”.
- 17:00DirectorMajor customer emails: “Can you provide a security statement for our supplier assessment?” He doesn’t know where to start.
- 08:20AdminThe email “from the director” is flagged: unusual sender, new bank account number, time pressure. The payment can’t go through without calling back on the known number. The director was indeed in a meeting. Nothing was paid.
- 09:15DirectorLogging in from an unknown network prompts the authenticator app on his phone. Passwords are in a vault; a different one for every account.
- 10:30Sales repUses the business AI environment: EU hosting, no training on data, the customer list stays inside. Free chatbots are blocked for company data, and he knows why.
- 13:00Office managerAsks the knowledge base: “latest contract with supplier X”. Answer with a source reference to the single, final document. Versions have been cleaned up.
- 14:30IT partnerThe backup was automatically restored to a test environment last night; the report says: 100% readable, 41 minutes recovery time. A copy is kept off-site and cannot be overwritten.
- 16:00HR“Left the company” in the HR system closed all accounts the same day in June. The log shows it.
- 17:00DirectorClicks “security statement” in the portal: the basic principles, the measures and the latest recovery test are in it. Sends it the same day.
Where AI makes the difference here
Per use case: what the automation does, what a person keeps doing, and whether it is proven or still promising. We say which one honestly.
The basics, enforced
Two-factor authentication, password vault, device management and updates. No AI, but the biggest lever: almost all account takeovers disappear with it.
Still human: sticks to it; we make it the easiest route.
Payment requests and account changes put on hold
Rules and AI flag unusual senders, new bank account numbers and time pressure; the payment can only go through after verification via a second channel.
Still human: calls back on the known number.
Access that moves with your workforce
Joining, changing role, leaving: accounts and rights follow the HR system automatically, with a log.
Still human: approves exceptions.
Backups that are proven to work
Automatic recovery tests, alerts when something is off, and a copy that cannot be overwritten or encrypted.
Still human: goes by the report, not by hope.
Shadow AI replaced by your own AI environment
A business AI workplace with EU hosting, no training on your data, and agreements on what is and is not allowed. Free tools blocked for company data.
Still human: works with it as before, but securely.
Search in your own documents
AI search across SharePoint or Drive with source references; versions cleaned up; a knowledge base that keeps up.
Still human: manages ownership and clean-up.
Honestly: what AI does not do here
- AI isn’t a security product. Without two-factor authentication, a password vault and tested backups you are buying an alarm for a house without a door.
- Phishing training on its own barely works: in a large study it made a difference of less than two percentage points. Technology and process before awareness.
- You don’t stop fraud with software. The call-back rule is the security; software makes sure nobody can skip it.
- A security statement isn’t a certificate. We help you get the basics in order and make them demonstrable; an audit or ISO track is a separate choice.
The objections we hear — and whether we can close them off
We looked them up and heard them from clients. For each objection we say whether it is really solvable, partly solvable, or a risk that stays and that you accept knowingly.
Can it be closed off: no, this stays a risk. CEO fraudsters are shifting their focus precisely to small organisations, and 1 in 5 small businesses takes no measures at all. Being small doesn’t make you invisible; it makes you easy.
- 01Week 1: core session with management and the IT partner; we go through the five NCSC basic principles and test one backup recovery.
- 02Week 1: two-factor authentication everywhere, password vault, call-back rule for payments. Immediately, no build required.
- 03Weeks 2 and 3: access linked to the HR system (joining, changing role, leaving) with a log; automatic recovery tests of backups.
- 04Weeks 3 and 4: business AI environment instead of free chatbots; knowledge base with AI search and source references.
- 05Week 4: security statement for customers; measure: accounts without two-factor authentication (zero), open accounts of former employees (zero), latest successful recovery test (this week).
First the free AI scan, then a core session on your floor (a half-day of 4 hours, €596 excl. VAT and travel costs) with a core report and an honest go/no-go. We build on a project basis with fixed hours: €110 per hour for straightforward work, €165 for complex development.
More hours only with your written approval. If we cannot deliver, you pay nothing for what was not delivered.
Want to know what this means for your it, security & data?
Take the free AI scan or book an intro call with someone who builds it themselves. A reply within one working day, no slides, no obligations.
Most businesses start with the tool and then get stuck. It is better to start with one piece of work that comes back every week and nobody enjoys.
The build costs are usually the easiest part of the bill. The surprises are in the clean-up beforehand, the monthly usage and the maintenance afterwards.
- Microsoft, How effective is multifactor authentication at deterring cyberattacks? (2023)
- Microsoft Digital Defense Report 2025 (2025)
- Computable (ABN AMRO/MWM2), SMEs use AI but lack a policy (2026)
- Fraudehelpdesk, CEO fraudsters shift focus to small organisations (2025)
- Dutch government, Alert Online 2025: cybercrime affects three in four Dutch people (2025)
- Ho et al., Understanding the Efficacy of Phishing Training in Practice (IEEE S&P) (2025)
- NCSC, 5 basic principles of secure digital business (2025)
- Dutch government, Cybersecurity Act in force from 15 August 2026 (2026)
- The Register (LayerX), Employees paste company secrets into ChatGPT (2025)
- Veeam, Ransomware Trends 2025 (2025)
- Accountant.nl, Dutch DPA sounds the alarm over data breaches caused by AI (2025)