By Ayomide Bode-Asa

 

Artificial intelligence is no longer something used only by large technology companies. A small shop owner can use AI to write an advert for Instagram. A family-run restaurant can use it to create a menu or respond to customer enquiries. Someone running an online fashion business from home can use it to improve product descriptions, prepare invoices or plan marketing campaigns.

For many small businesses across Africa, this is attractive because there may be no marketing department, IT team or dedicated administrator. Sometimes the business team is one person. Sometimes it is a husband and wife, siblings or a few employees running a shop together.

 

That same business may already depend heavily on technology. There is a smartphone for WhatsApp Business and banking, a POS terminal for customer payments, an Instagram or Facebook page, perhaps a laptop for records, and now AI tools being introduced into the mix.

AI can make running that business easier. But when so much of the business is already concentrated in a few devices and accounts, using AI without thinking about security can introduce risks that are easy to overlook.

 

Think About the One-Person BusinessI

 

Imagine a small shop owner in Lagos. She has two employees. Customers pay by cash, bank transfer, or POS. Orders sometimes arrive through WhatsApp Business. The shop’s Instagram account is logged into on her personal phone, which also contains her email and mobile banking apps.

She starts using an AI chatbot because it helps her write promotional posts and customer messages. One afternoon, she receives a long complaint from a customer and asks AI to help her draft a response. To provide context, she copies the customer’s entire WhatsApp message into the chatbot, including their name, telephone number and details of a payment dispute.

She wasn’t trying to expose customer information. She was trying to save time. That is what makes some of the risks surrounding AI difficult. They can arise from completely normal business behaviour.

 

Your POS, Phone and AI Are Part of the Same Business

A POS terminal may seem separate from AI, but from the business owner’s perspective they form part of the same digital environment. The POS handles payments. The phone may receive transaction notifications. WhatsApp handles customer enquiries. Email receives statements and invoices. Social media brings customers in. AI helps create content or complete administrative work.

If the business owner uses the same phone and email account across several of these activities, one compromised account or device can create problems elsewhere. For example, a criminal could send the owner a convincing AI-written message pretending to come from a payment provider: “We’ve detected a problem with your POS settlement. Please confirm your business account immediately to avoid suspension”. The message could contain the business name, sound professional, and create urgency. If the owner enters their details into a fake website, the problem started with a message, not the POS machine itself.

 

AI Can Make Fraud Look More Believable

Small businesses have always had to deal with fraud. AI can make some of it more convincing. Poor grammar and strange wording used to make certain scam messages easier to recognise. AI can now help someone create a professional-looking email, WhatsApp message or invoice in seconds. It can also help criminals personalise their approach using information already available online.

Imagine a family business where one sibling manages the shop and another handles payments. A WhatsApp message arrives appearing to come from the family member who normally approves purchases: “I’m with a supplier at the moment. Please transfer ₦350,000 to this account so we can secure the stock. I’ll explain when I get back.” When people already know each other well, familiarity can work against them. The employee may think, ‘That’s my brother. Why would I question him?’ For unusual payments, particularly changes to bank details or urgent requests, a quick phone call or another form of verification can prevent an expensive mistake.

 

Customer Information Still Needs Protecting

A small business may think, “We don’t really have sensitive data.” But consider what even a small retailer might hold: names, phone numbers, delivery addresses, order histories, payment confirmations, invoices and WhatsApp conversations.

A salon might have appointment information. A travel agent could have passport details. A small school or childcare business may hold information about children and parents. That information shouldn’t automatically be copied into an AI tool simply because the tool makes a task easier. Before entering customer or business information into AI, the owner or employee should ask a simple question: Does the AI actually need this information to complete the task?

Often, names, phone numbers, addresses, and account details can be removed first.

 

Sometimes the Risk Is Trusting AI Too Much

Not every AI risk involves cybercriminals. Sometimes AI simply gets something wrong. Imagine a family business asks AI to calculate pricing for a large customer order. The answer looks professional, so nobody checks the calculation before sending the quotation. Or an employee uses AI to write information about the company’s refund policy and sends the response to a customer without confirming that it matches the actual policy.

For a large company, someone else may have made mistake. In a three-person business, the person using the AI may also be the person approving and sending the work. That makes human judgement particularly important. AI can help prepare the work. It shouldn’t automatically be trusted to make every decision.

 

Basic Cybersecurity Still Matters

One danger with conversations about AI is that businesses start worrying about futuristic threats while ignoring simple problems they already have.

The shop’s laptop hasn’t been updated for months. Nobody knows whether important business records are properly backed up. All three employees know the password to the Instagram account. The former employee who left six months ago may still have access to WhatsApp or another business account. The owner’s phone doesn’t have a strong screen lock. A POS-related account is connected to an email address whose password has been reused elsewhere. AI doesn’t make these problems disappear. In some cases, it can add another service and another account to an already complicated situation.

For a small business, good cybersecurity can begin with very ordinary habits: keeping devices updated, protecting important accounts, using multi-factor authentication where available, backing up essential information, checking who has access and removing people who no longer need it.

 

What Happens When the Owner Is the IT Department?

This is an important reality for small businesses.

If you run a shop with two employees, nobody is going to call the cybersecurity department when something goes wrong. You are the cybersecurity department.

If the phone containing your business accounts is stolen, you need to know how to recover them. If an employee leaves, someone needs to remove their access. If your records disappear, you need a backup. If somebody claims your POS settlement account has changed, you need a trusted way to verify that claim.

As the business grows, these informal responsibilities need to become clearer. A family shop may eventually become three branches. Two employees become twenty. One POS terminal becomes ten. More people gain access to business accounts and customer information. The cybersecurity practices that worked when everybody sat behind the same counter may no longer be enough.

 

AI Should Help the Business, Not Control It

AI can be genuinely useful for small African businesses. For a one-person operation, it can almost feel like having an additional pair of hands. It can help write content, organise ideas, summarise information, and reduce the time spent on routine tasks.

That is worth embracing. But businesses should understand what they’re giving AI access to, avoid unnecessarily sharing customer information, check out important AI-generated work and remain cautious when unusual requests involve money or sensitive information.

And while exploring AI, don’t forget the basics. Keep the phone and computer updated. Protect the email account connected to the business. Secure the accounts used for payments and customer communication. Back up important information and make sure it can actually be recovered. Review who has access when employees leave.

 

For a one-person business, a family shop or a growing company, cybersecurity doesn’t have to start with expensive software.

Sometimes it begins with understanding one simple fact: Your phone, POS, email, WhatsApp, social media and AI tools may all be helping you run the same business. Protecting that business means thinking about all of them together.

 

About the Author

 

Ayomide Bode-Asa is a cybersecurity professional and researcher with an MSc in Cyber Security and Human Factors from Bournemouth University. His work focuses on cybersecurity risk, threat detection, security operations, AI-related cyber risks and practical approaches to helping individuals and small businesses improve their cybersecurity.

 

He is also the developer of the Security Posture Risk Assessment Toolkit, a web-based project designed to make cybersecurity risk assessment more accessible and practical for businesses.

 

Contact Details

Phone: +234 803 952 0120

Email: ayomidebodeasa@gmail.com

Website: securityposture.co.uk

GitHub: Ayomide Bode-Asa on GitHub

Research: Social Engineering & Cognitive Biases Research

Share.
Exit mobile version