AI is making it possible for small and medium-sized enterprises (SMEs) to build customer-facing software without a traditional development team. As more business owners use the technology to create booking systems, customer portals and online stores, securing the software they put in front of customers has become their responsibility.
Research released by Kaspersky in August found that 78% of South African SMEs experienced a cybersecurity incident in the past year, with weak or stolen login details accounting for 18% of incidents.
Anton Moulder, Head of Product at HyperDev AI, says a business owner can now use AI to build a working application in days, often without the technical knowledge to identify security weaknesses in the code behind it.
“That app could be holding customer names, phone numbers, booking details and, in some cases, payment information,” he adds. “AI will build what you ask it to build, but if security isn’t part of the brief, you can’t assume it has been taken care of.”
The tools carry risks of their own. Kaspersky also recorded a tenfold increase in security vulnerabilities in AI services during the first half of 2026, most commonly in access controls and authentication. Veracode’s 2026 GenAI Code Security Report, released in July, found that leading AI models produced code containing a known security flaw in 44% of tasks where security was relevant.
An application can work perfectly while a security weakness sits unnoticed behind it. Moulder suggests business owners ask their AI tool four questions before putting an application in front of customers:
- “Could someone get into my account, or a customer’s, by guessing or stealing a password?” Your own login controls the whole app, so protect it with a long, unique password and a one-time code sent to your phone. Customer accounts should limit wrong password attempts.
- “Can a customer see anyone else’s information?” Each customer should only ever see their own bookings, orders and details.
- “Are the codes that connect this app to my payment and email accounts hidden?” These codes work like the keys to your business accounts. Anyone who finds them can take payments, send emails or run up charges as if they were your business.
- “What security problems can you find in what you’ve built?” AI tools can miss flaws in their own work, so treat the answer as a starting point. If the app handles payments or personal details, get someone with security experience to check it before launch.
“None of these questions requires a business owner to become a software developer,” says Moulder. “The time to ask them is before launch, while fixing a problem still costs you nothing but time.”
If a business suspects its app has been breached, he advises acting straight away: change passwords and connection codes, take the affected part of the app offline if needed, and keep a record of what happened and when. Under the Protection of Personal Information Act (POPIA), a business must also notify the Information Regulator and affected customers as soon as it is reasonably sure customers’ personal information has been compromised. Reports to the Regulator must be made through its online eServices portal.
Moulder says none of this should put small businesses off building. “AI has put tools within reach that used to cost a development team and months of work. For a small business, that’s a real advantage over bigger competitors. The businesses that hold on to it will be the ones customers trust with their details.”






