Updated October 2026. Originally published April 3, 2024.
Cyber threats against businesses keep getting more convincing. At the engineering firm Arup, a finance employee joined a video call with people he believed were the company's CFO and other colleagues. All of them were deepfakes, and he went on to transfer $25.6 million to the fraudsters over 15 transactions (Fortune). Attacks like this show why every business needs a defense plan built for how criminals operate today.
The threat picture in 2026
The latest data shows attackers gaining ground on several fronts:
Losses keep rising. Americans reported $20.877 billion in internet crime losses to the FBI in 2025, a 26% increase over 2024. Business email compromise alone accounted for more than $3 billion of that total (FBI IC3).
AI is now part of the playbook. For the first time, the FBI reported AI-related fraud on its own: 22,364 complaints and more than $893 million in losses in 2025 (FBI IC3).
Unpatched systems are the top way in. Exploitation of vulnerabilities is now the most common initial access vector, at 31% of breaches, and ransomware appeared in 48% of all breaches (Verizon DBIR).
People are still the target. The human element was present in 62% of breaches, and in phishing simulations, voice and text lures succeeded at a median rate 40% higher than email (Verizon DBIR).
Four strategies to combat cybersecurity threats
At Starfish Computer Corporation, our approach focuses on educating and equipping businesses with the right tools and knowledge to protect their operations. We build defenses around four strategies:
Awareness and vigilance. Train your team to recognize phishing, deepfake voice and video, and urgent requests for money or credentials. Set a firm rule that any request to send funds or change banking details is verified through a second, known channel, such as a call to a number already on file, no matter who appears to be asking.
Strong security tools, well managed. Patch internet-facing systems first, run endpoint detection and response on every device, and require multifactor authentication for email, remote access and financial accounts. CISA calls phishing-resistant MFA, such as FIDO security keys, the “gold standard” and urges organizations to make it a high priority (CISA).
Comprehensive disaster recovery plans. Keep backups that attackers cannot reach or alter, test your restores, and write down who does what during an incident. In Verizon's 2026 data, 69% of ransomware victims did not pay a ransom (Verizon DBIR); reliable, tested backups are what make that choice possible.
Regular assessments and updates. Threats change every year, and your defenses should too. The NIST Cybersecurity Framework 2.0 gives businesses a common structure built on six functions: govern, identify, protect, detect, respond and recover. NIST also publishes quick-start guides written for small businesses (NIST).
Strengthen your defenses with Starfish Computer
Starfish Computer Corporation offers a full range of services to strengthen your cybersecurity posture, from an initial assessment of your current security measures to implementing layered defenses and building a disaster recovery plan you have actually tested. Contact Starfish Computer to review your defenses against today's threats, including deepfakes and payment fraud, and to build a plan that keeps your business protected.
Protect your business: start with an assessment
The question isn’t whether your business will face a cyber threat, but whether you’ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:
Assess current security posture and risk
Plan a cybersecurity roadmap aligned to NIST CSF 2.0
Implement the right tools and processes for your size and budget
Train your team on today’s threats, including AI-driven scams
Support and improve your security over time
Call (440) 808-0468 or visit starfishcomputer.com to schedule a security assessment.
About the author
R.J. Arhar is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of Attack or Defend – When is Enough Cybersecurity Enough?
This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.

