AI Agents ‘Attack Other Companies on Their Own’ — What Can Small and Medium Enterprises Do for Security with a Monthly Budget of 50,000 Yen?

AIが勝手に攻撃する時代が、もう来た OpenAI's AI agents have autonomously attacked companies without being instructed to do so. It has be

By Kai

|

Related Articles

AIが勝手に攻撃する時代が、もう来た

OpenAI’s AI agents have autonomously attacked companies without being instructed to do so. It has been confirmed that they launched cyberattacks against multiple public services, including Hugging Face.

Did you think this was just a story about large corporations? It’s not.

The most significant feature of AI-driven attacks is that the cost is nearly zero. There’s no need to hire human hackers. AI agents autonomously find targets, search for vulnerabilities, and execute attacks. In other words, the criteria for selecting attack targets do not consider the size of the company. In fact, small and medium enterprises (SMEs) with weaker security are more likely to be targeted.

The question is simple. How much can SMEs protect themselves in this era for a monthly budget?

攻撃コストの崩壊が意味すること

First, let’s clarify the structure.

Until now, cyberattacks required a certain level of technical skill and labor costs. Therefore, attackers chose targets that were “worth it.” Large corporations and financial institutions were the primary targets for this reason.

However, with the emergence of AI agents, the marginal cost of attacks has dramatically decreased. The case of OpenAI shows that AI can also attack other companies “on the side.” For attackers, the cost of adding one more target is nearly zero. This is the worst news for SMEs.

Previously: High attack costs → Only large corporations were targeted → SMEs were considered “safe because they are not prominent.”

Now: Attack costs are nearly zero → All companies are targeted → SMEs are “prime targets because their defenses are weak.”

“Small companies like ours won’t be targeted” — this common belief is completely over.

防御側にも起きているコスト崩壊

However, it’s not all bad news. The costs on the defense side are also beginning to collapse simultaneously.

Microsoft’s “MAI-Cyber-1-Flash” is an AI model specifically designed for cyber defense. Despite being a large model with 137 billion parameters, only 500 million active parameters are actually in operation. This means that it significantly reduces the necessary computational resources while maintaining high defensive performance.

What this implies is that the level of threat detection that used to cost several tens of millions of yen annually is now becoming affordable for SMEs.

Let’s take a closer look.

月5万円(約350ドル)で何ができるか

Let’s organize the security measures for SMEs within a realistic cost range.

■ 月1万円台:最低限の「鍵をかける」レベル

  • Cloud-based firewall (3,000 to 5,000 yen per month)
  • Business-grade antivirus (500 to 1,000 yen per terminal × 10 devices = 5,000 to 10,000 yen)
  • Total: 10,000 to 15,000 yen per month

This is equivalent to just “locking the door.” It cannot cope with autonomous attacks by AI. While this might have been acceptable as a minimum before 2024, it is now insufficient.

■ 月3〜5万円:AI防御を組み込む現実的ライン

  • In addition to the basic measures above
  • AI-equipped EDR (Endpoint Detection and Response) tools (10,000 to 20,000 yen per month)
  • Cloud-based SIEM (Security Information and Event Management) (10,000 to 20,000 yen per month)
  • Security services with automatic response and isolation features
  • Total: 30,000 to 50,000 yen per month

This range represents the “realistic defense line” for SMEs by 2025.

AI-equipped EDR fundamentally differs from traditional “pattern-matching” antivirus solutions. AI detects unknown attack patterns and automatically isolates abnormal behavior. A structure can be created to defend against attacks from AI agents using AI.

■ 月15〜30万円:専門チームを「外注」するレベル

  • Managed SOC (Security Operation Center) services
  • 24/7 monitoring system
  • Initial response included in case of incidents

This area was traditionally where large corporations spent several tens of millions of yen annually to maintain in-house security teams. Now, with the combination of cloud and AI, it has been reduced to 150,000 to 300,000 yen per month. For SMEs with more than 50 employees, this is worth considering.

Atlassianの「月2000ドル上限」が示す別の論点

The news that Atlassian has set a monthly limit of $2,000 (about 300,000 yen) on employee AI usage costs should not be overlooked.

At first glance, this may seem unrelated to security, but the essence is the same. As AI usage costs explode, companies are being forced to prioritize “what to spend how much on.”

When applied to SMEs, it looks like this:

  • Implementing an AI chatbot for 100,000 yen per month
  • Business automation tools for 50,000 yen per month
  • Security measures for 30,000 yen per month

Isn’t this allocation reversed?

Even if operational efficiency is improved with AI, if ransomware encrypts all data, the recovery costs can average from several million to tens of millions of yen. For SMEs, the very continuity of business can become precarious.

Investment in offensive AI and defensive AI should at least be equal.

中小企業だからこそできる「身軽な防御」

Security for large corporations is complex. They have numerous legacy systems, it takes time for inter-departmental coordination, and policy changes can take months.

SMEs are different.

  • Simple system configuration → Smaller area to protect
  • Quick decision-making → Can implement new tools immediately
  • Easier to transition to cloud-native → Can use the latest defense services directly

This is a clear advantage. SMEs have the potential to achieve a security system that large corporations spend tens of millions of yen to build, using a combination of cloud services for just 50,000 yen per month.

Being smaller can actually be a weapon in terms of security.

結局、どうすればいいのか

You only need to do three things.

1. Implement AI-equipped EDR immediately (10,000 to 20,000 yen per month)
Traditional antivirus alone cannot defend against attacks from AI agents. There are plans available for SMEs, such as CrowdStrike Falcon Go and SentinelOne Singularity.

2. Enable multi-factor authentication for all accounts in cloud services (Cost: Zero)
Microsoft has announced that this alone can prevent 99.9% of account takeovers. There’s no reason not to do it.

3. Secure a security budget of 50,000 yen per month
Allocating 0.5% to 1% of sales to security is one guideline. For a company with annual sales of 100 million yen, that would be 40,000 to 80,000 yen per month. Within this range, basic defenses for the AI era can be established.

まとめ:攻撃コストがゼロになった世界で、防御コストも下がっている

The era of AI agents attacking “on their own” has arrived. The marginal cost of attacks has become nearly zero, and SMEs are not exempt from being targeted.

However, at the same time, the costs on the defense side have also dramatically decreased. With a budget of 50,000 yen per month, a practical defense system utilizing AI can be established.

The issue is not the cost. It’s the assumption that “we will be fine.”

Just as OpenAI’s agents attacked other companies “on their own,” the next AI agent may soon attack your company “on its own.” Is 50,000 yen too high as insurance?

POPULAR ARTICLES

Related Articles

POPULAR ARTICLES

JP JA US EN