AI Security as a Growth Driver for SMEs
Small and medium-sized enterprises around the world are adopting AI tools at an unprecedented pace—often without the necessary security measures in place. David Meister, Global Head of MSP & MSSPs at Check Point Software Technologies, explains on International SME Day why cybersecurity is not a cost factor for SMEs, but rather a strategic competitive advantage.

Every year on June 27, the world celebrates the International Day of Micro, Small, and Medium-Sized Enterprises, which the United Nations established as MSME Day. This year’s theme, «Empowering MSMEs through Innovation and Sustainable Industrial Development,» could not be more timely. In many places, SMEs are simply being overlooked in the global race for artificial intelligence—even though the numbers speak for themselves.
Data from the WEF SME Resource Hub shows that there are an estimated 400 million SMEs worldwide. They account for about 90 percent of all businesses globally, create an estimated 70 percent of jobs—and are all vulnerable to cyberattacks.
SMEs Are Rapidly Catching Up in AI Adoption
The JPMorgan Chase Institute found in a recent study that small businesses achieved an AI adoption rate of 10 percent within about six months. A comparable study from 2019 found that it took more than six years to reach the same milestone. The Office of Advocacy of the U.S. Small Business Administration (SBA) also reports that the gap between large and small businesses has nearly closed: Large companies once adopted AI at nearly twice the rate of small businesses—but by the end of 2025, that lead had all but disappeared.
This is not a slow catch-up process. The smaller end of the market is setting the pace. A Thryv survey of small businesses found that AI adoption among companies with 10 to 100 employees rose by 21 percentage points to 68 percent within a year. This is no longer just experimentation—it’s a dependency that’s evolving faster than the safeguards surrounding it.
The risk lies not in AI itself, but in its uncontrolled adoption
A company with 30 employees can often adopt new technologies more quickly than a large organization. However, it may have a smaller budget and fewer specialized staff to assess and manage the associated cyber risks. David Meister, Global Head of MSP & MSSPs at Check Point Software Technologies, illustrates this with concrete examples from everyday life.
A marketing employee enters the entire customer list into a chatbot to «clean it up»—afterward, this data is stored in a location that the company does not control and from which it can no longer be retrieved. An accountant processes a payment because she receives a request to do so in a Teams or Slack message—increasingly, this comes in the form of a deepfake voice note from a «supplier» or a multilingual invoice that is indistinguishable from the original. An office manager connects an AI assistant to the shared inbox and calendar so that it can «take over scheduling»—thereby granting a third-party system constant access to every conversation within the company.
None of this sets off any alarms. Most of it doesn't cause any damage—until the day it finally does.
Shadow AI: Risks That SMEs Did Not Agree To
One of the biggest risks for SMEs is not the AI that the company itself uses, but rather the AI that employees use without anyone noticing. Employees use AI assistants to write emails, summarize documents, create slides, and draft code. The productivity gains are real—but so are the side effects: Sensitive customer data, financial records, intellectual property, and confidential plans are being uploaded to public AI platforms without anyone noticing.
Often, a company monitors its AI spending but completely overlooks the risks associated with AI. The tools are approved just like any other software subscription: a line item in the budget, a quick nod—and that’s it. What is never recognized as a decision, however, is the fact that employees enter customers’ financial data into these tools to speed up the monthly closing process.
SMEs are particularly affected, as attackers target them specifically. The latest Verizon report on security breaches confirms this: The proportion of attacks on small businesses is significantly higher than that on large ones. They are targeted not in spite of, but precisely because of, their small size. Even if a company seems too small to be a target, it is almost certainly part of another company’s supply chain—and attackers know this, too.
Time windows are shrinking dramatically
In the age of AI, the average time from the disclosure of a vulnerability to a working exploit has shrunk from years to hours. It is projected to fall below one hour by the end of 2026. The emergence of Frontier AI models demonstrates just how quickly AI can detect software flaws—and these capabilities will not remain limited to patching forever. That is why no company can afford to delay patches, rely on manual processes, or adopt a reactive approach to security.

Security as a driver of growth, not a cost factor
SMEs should view cybersecurity not as a cost but as a driver of growth. For years, it was seen as a kind of fee paid to minimize risks. In an AI-driven economy, this dynamic is reversed: Cybersecurity is the prerequisite for using AI with confidence, winning larger clients, qualifying for more extensive supply chains, complying with new regulations, and protecting the trust that has been built up over the years. Customers, regulators, insurers, investors, and partners are beginning to ask critical questions before partnering with a company—in an AI-driven economy, trust has quietly become a competitive advantage.
Companies that integrate security into their AI strategy from the outset generally make faster progress. According to the UN Sustainable Development Group, SMEs account for 90 percent of all businesses, create up to 70 percent of jobs, and generate half of global GDP. For many SMEs, AI-powered security is the first realistic opportunity to adequately protect their business without having to hire a large number of staff.
Since attackers strike within minutes rather than weeks, a preventive approach is more important than ever. The next generation of SMEs will succeed not because they have the largest budgets or the most extensive IT teams, but because they can innovate faster, act more intelligently, and defend themselves more effectively in an AI-driven world.
More information: https://www.checkpoint.com
