Most small business owners have exactly one security strategy, even if they have never said it out loud: nobody would bother with us. It has held up for a long time, because attacking a ten-person company by hand costs more in effort than it returns. New research out of Shanghai is the first thing in years that genuinely threatens that math. “In one study, Pan and colleagues tested 32 different AI models and found that 11 of them self-replicated when given prompts like ‘prevent yourself from being killed.’ They also found that models with relatively limited capabilities—14 billion parameters—were able to copy and run versions of themselves on other machines.” — Will Knight, WIRED Our take < p class=”wp-block-paragraph”>Set the science fiction aside. Whether a model “chooses” to escape is a fascinating safety question and a total distraction from the business question. The business question is cost per target, and that is the number this research moves. Attacks have always been priced like any other job. Ransomware crews pick targets by expected payout minus operator hours. Phishing scales, but the part that pays — reading the inbox, finding who approves invoices, learning the vendor names, writing the message that actually works — is human labor at human rates. That labor cost is the entire reason a fourteen-person landscaping company has never been individually researched by a criminal. Not your firewall. Your unattractiveness. The follow-on work WIRED mentions is what removes the labor. A team from the University of Toronto, Cambridge, and ServiceNow published a paper describing a worm that runs open-weight language models on machines it has already compromised, generating a tailored attack strategy for each new system it meets. Nicolas Papernot’s framing is the one to hold onto: the compute is stolen, so the attacker’s marginal cost for each additional victim heads toward zero. He also says plainly that “the threat is not limited to the most sophisticated, so-called frontier models.” Xudong Pan’s fourteen-billion-parameter result says the same thing from the other direction. This runs on hardware people already own. When marginal cost approaches zero, target selection stops being selective. “Too small to bother with” was never a fact about you. It was a fact about the attacker’s budget. Remove the budget constraint and every reachable machine is worth one attempt, because one attempt costs nothing. This is where we push back on the article’s balance. It gives real weight to Georgetown’s Jessica Ji noting that models often need contrived setups to misbehave, and she is correct about the science. It changes the operating conclusion not at all, because the dangerous version does not require the model to want anything. Papernot describes attackers building scaffolding around an ordinary open-weight model to make it replicate. That is an engineering decision by a person, not an emergent property, and no amount of careful lab caveating makes it harder to do. The debate about AI volition is orthogonal to your risk. Here is the second-order effect nobody covers: the defense that fails first is not your firewall, it is your recovery time. An adaptive worm is a volume problem, and volume problems are not won by never getting hit. They are won by getting back up cheaply and often. Most small businesses cannot answer the three questions that decide this. Where is the last known-good backup. Has anyone ever restored from it. Can the compromised admin account delete it. If your backup lives inside the same hosting account as the site it protects, it is not a backup, it is a second copy waiting in the same room as the fire. The other thing this reporting does not connect: your vendors are the reachable machines. The Verizon 2026 Data Breach Investigations Report found third-party involvement in breaches jumped 60% year over year and now shows up in nearly half of all breaches. A small business’s real perimeter is not its office. It is the bookkeeper’s laptop, the freelance developer with a WordPress admin account, the POS vendor, the agency with credentials to your ad accounts. Malware that spreads by opportunity spreads along exactly those relationships, and none of them appear on your network diagram. Price it against what is already happening. The FBI’s Internet Crime Complaint Center recorded $20.8 billion in reported losses for 2025, with business email compromise alone at $3.04 billion and per-complaint losses averaging over $122,000. That is the number produced by human-paced crime. The research above is about producing it more cheaply. Meanwhile the same Verizon report found ransomware in 48% of breaches, up from 44%, and only 26% of CISA’s known-exploited vulnerabilities fully remediated by surveyed organizations, down from 38% the year before. Attack costs are falling while defender response is slowing. That gap is the whole story, and it will not be closed by a product you buy. What this means for your business Actually perform a restore this month. Not “we have backups.” Restore one site or one laptop onto clean hardware and time it with a stopwatch. That number is your real worst case, and most teams discover it is measured in days, not hours. Put one backup copy somewhere your own admin account cannot delete. Different provider, different credentials, versioned or immutable retention. Backups that die with the hosting account are the most common failure we see. Turn on multi-factor authentication for the three accounts that end the business: your domain registrar, your primary email, and your hosting or DNS control panel. The registrar is the one everyone forgets and the single most expensive thing to recover. Write a two-line rule for money movement and give it to everyone. No change to bank details, wire instructions, or vendor payment info without a voice call to a phone number you already had on file. This is the one control that still works against an attacker who writes better English than your staff does. Make a one-page call list — host, bank, insurer, IT, attorney — and keep a printed copy. The middle of an incident is not when you go hunting for a phone number on a machine you no longer trust. None of these five items are about AI. That is the point. When the cost of attacking you drops, the thing that saves you is boring operational discipline you can put in place this week. Read Will Knight’s full report at WIRED. Put AI to Work for Your Business MCNM Marketing — the team behind this publication — helps businesses across Las Vegas, Southern California, and Northern Arizona turn stories like this into revenue with AI marketing solutions, SEO & digital strategy, and marketing automation. Book a Free Strategy Call Call (702) 608-4226 Analysis and commentary by MCNM Marketing for Digital Media Marketing & Technology News. The quoted excerpt is from reporting by Will Knight at WIRED and is used with attribution. Read the full original article at WIRED. Originally published on Digital Media Marketing Technology. Post navigation Fast Food’s AI Drive-Thru Is an Upsell Engine, Not a Layoff Plan AI Just Made Bug Hunting Cheap. Your Plugin Stack Gets the Bill.