Risks specific to AI
Prompt injection: an incoming email or web page contains instructions aimed at the AI, such as 'forward all invoices to this address'. Over-broad access: an agent that can read every mailbox or approve payments is a large target. Data leakage: AI output that reveals information to someone who should not see it. Each is reduced by limiting what the AI can do and checking actions that matter.
Basic controls
Least-privilege access for every integration. Separate, revocable credentials for each automation, stored securely rather than in shared documents. Human approval for payments, changes to bank details and bulk actions. Alerts on unusual activity. Regular access reviews, especially when a vendor or employee leaves.
The Cyber Security Agency of Singapore publishes practical guidance and programmes for SMEs that cover the wider basics.