Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Companies. Show all posts

Most Enterprises Are Unprepared for AI and Quantum Threats, PwC Survey Finds

 



Most organizations around the world are spending more on cybersecurity than at any point in their history. Very few are spending it on the threats that are actually coming for them. That is the central tension running through PwC's 2027 Global Digital Trust Insights report, which drew responses from nearly 4,000 business and technology leaders spanning more than 70 countries.

Artificial intelligence sits at the core of the report's findings, and not in the way most organizations would prefer. Leaders surveyed identified attacks targeting their own AI systems as the single cyber threat they feel least prepared to handle. Over half of respondents, 53 percent, said they are not adequately defended against autonomous botnet attacks, where AI drives the probe and compromise of networks faster than human teams can respond. Adversarial attacks and data poisoning followed at 52 percent each, pointing to a defensive gap that has widened as attackers have adopted the same tools organizations are still trying to implement on the defense side.

Prompt injection sits squarely at the heart of this problem. Unlike conventional exploits that target code vulnerabilities, prompt injection manipulates the AI model itself, tricking it into leaking data, executing unauthorized commands, or acting entirely outside its designed purpose. OpenAI acknowledged in late 2025 that prompt injection, much like social engineering before it, is a problem that cannot be fully engineered away. The Open Worldwide Application Security Project has ranked it number one on its threat list for LLM applications for three consecutive updates, a position it has held since the list first debuted. The persistence of that ranking reflects not a shortage of incidents, but the structural difficulty of closing an attack surface that is, in effect, the model's own reasoning process.

Despite all of this, AI is simultaneously the security tool leaders trust most. The survey found it ranked first for threat detection and alerting across the respondent pool. The contradiction is in what comes next. Only 22 percent of leaders said they would let AI agents operate in cyber defense without requiring human sign-off on their actions. Fifty-five percent attributed this reluctance to reliability and maturity concerns, while 44 percent pointed to a skills shortage in AI oversight and governance.

That hesitation is not irrational, but it carries a cost. AI-driven attacks operate at a pace that leaves human response cycles behind. Requiring manual approval for every automated defensive action is, in practice, fighting a faster adversary at a slower speed. At some point, fully autonomous defense may not be optional. What makes that shift harder is that organizations have not settled on who would be accountable for it. The survey found that 29 percent of leaders placed AI security accountability with the CIO or CTO, 26 percent with a dedicated AI leadership role, and only 17 percent with the CISO. Eleven percent said responsibility was shared across multiple functions, which in most organizations means it belongs to no one in particular.

Budget signals at least suggest that leaders recognize the scale of the problem. Eighty-four percent of security and finance leaders said they expect cyber budgets to increase, with 58 percent naming AI as their top spending priority for the coming year.

The second major warning in PwC's report concerns quantum computing, and the picture there is, if anything, more concerning. Quantum computers capable of breaking the encryption that currently secures financial records, government communications, and enterprise data are not yet commercially operational. But the attack strategy does not require them to be. State-sponsored threat groups and other sophisticated actors are already collecting encrypted data now, banking on the ability to decrypt it once quantum capability matures. Most cryptography researchers put that window between 2030 and 2035, and the timeline for migrating large-scale cryptographic infrastructure is measured in years, not months. The National Institute of Standards and Technology finalized its first three post-quantum cryptography standards in August 2024, covering quantum-resistant key exchange and digital signatures, and told organizations explicitly that there is no reason to delay. PwC's survey found that only 21 percent of respondents are currently implementing those standards.

What makes this more urgent than a theoretical risk is that the harvesting is already underway. The FBI confirmed in August 2025 that a Chinese state-sponsored group tracked as Salt Typhoon had compromised more than 200 organizations spanning more than 80 countries, with nine major US telecommunications carriers among the confirmed victims. In at least one documented case, the group maintained undetected access to a telecom network for three years, collecting communications data throughout. That data, encrypted under today's standards, sits in storage waiting for the decryption capability that quantum hardware will eventually provide. Governments are beginning to respond with deadlines rather than guidelines. In June 2026, President Trump signed executive orders requiring federal agencies to migrate high-value systems to NIST-approved post-quantum cryptography standards by 2030 and 2031 respectively, with government contractors expected to follow. The private sector has no equivalent mandate, and PwC's survey makes clear that most organizations are not filling that gap on their own.

"Technology is moving incredibly fast, but the fundamentals of cybersecurity haven't changed," said Morgan Adamski, PwC's cyber, data and technology risk leader. "You can invest heavily in AI and the latest security tools, but if you don't have secure data, operational continuity, clear accountability and strong cyber hygiene underneath them, you're building on a weak foundation. The goal isn't to slow innovation down. It's to make sure your organization is resilient enough to keep up with it."

What the survey documents, across both AI and quantum, is the distance between knowing what needs to be done and actually doing it. The tools exist. The standards are published. The gap is operational, and the cost of that gap is rising by the month.


Switzerland’s New Law Proposal Could Put VPN Privacy at Risk


Switzerland is thinking about changing its digital surveillance laws, and privacy experts are worried. The new rules could force VPN companies and secure messaging services to track their users and give up private information if requested.

At the center of the issue is a proposed change that would expand government powers over online services like email platforms, messaging apps, VPNs, and even social media sites. These services could soon be required to collect and store personal details about their users and hand over encrypted data when asked.

This move has sparked concern among privacy-focused companies that operate out of Switzerland. If the law is approved, it could prevent them from offering the same level of privacy they are known for.


What Could the New Rules Mean?

The suggested law says that if a digital service has over 5,000 users, it must collect and verify users’ identities and store that information for half a year after they stop using the service. This would affect many platforms, even small ones run by individuals or non-profits.

Another part of the law would give authorities the power to access encrypted messages, but only if the company has the key needed to unlock them. This could break the trust users have in these services, especially those who rely on privacy for safety or security.


Why VPN Providers Are Speaking Out

VPN services are designed to hide user activity and protect data from being tracked. They usually don’t keep any records that could identify a user. But if Swiss law requires them to log personal data, that goes against the very idea of privacy that VPNs are built on.

Swiss companies like Proton VPN, Threema, and NymVPN are all worried. They say the law could damage Switzerland’s reputation as a country that supports privacy and secure digital tools.


NymVPN’s Warning

NymVPN, a newer VPN service backed by privacy activist Chelsea Manning, has raised strong objections. Alexis Roussel, the company’s Chief Operating Officer, explained that the new rules would not only hurt businesses but could also put users in danger—especially people in sensitive roles, like journalists or activists.

Roussel added that this law may try to go around earlier court rulings that protected privacy rights, which could hurt Switzerland’s fast-growing privacy tech industry.


What People Can Do

Swiss citizens have time to give feedback on the proposal until May 6, 2025. NymVPN is encouraging people to spread the word, take part in the consultation process, and contact government officials to share their concerns. They’re also warning people in other countries to stay alert in case similar ideas start appearing elsewhere.

The Growing Danger of Third-Party Security Risks

 


A new study has surfaced a major cybersecurity concern for businesses: security vulnerabilities from third-party partners. According to a recent report by SecurityScorecard, more than a third of all data breaches in 2024 were linked to third-party service providers.


Underreported Threats

The research examined 1,000 cybersecurity incidents across different industries and regions. It found that 35.5% of breaches were due to third-party security weaknesses. However, experts believe the real number may be even higher due to many incidents being misclassified or not reported.


High-Risk Sectors

The report also revealed that the nature of these attacks is changing. In 2025, fewer third-party breaches involved technology services than in previous years. Only 46.75% of such breaches were linked to tech-related businesses, a decline from 75% the year before. This means cybercriminals are targeting a broader range of industries.

Among the most affected industries were retail and hospitality, which experienced the highest rate of third-party security breaches at 52.4%. The technology sector followed closely at 47.3%, while energy and utility companies saw a 46.7% breach rate. Even though the healthcare industry had a lower percentage of breaches (32.2%), it faced the highest total number of attacks, with 78 incidents recorded.


Global Hotspots for Third-Party Breaches

Certain countries saw a higher frequency of breaches. Singapore reported the most third-party cyber incidents, with 71.4% of breaches originating from external vendors. The Netherlands followed at 70.4%, while Japan recorded 60%.

The report also pointed out that ransomware groups are increasingly exploiting third-party connections to gain access to their targets. More than 41.4% of ransomware attacks now originate through a compromised third-party vendor. The notorious Cl0p ransomware gang has been particularly active in using this method.


Strengthening Security Measures

Cybercriminals favor third-party breaches because they allow access to multiple organizations at once. Security experts warn that businesses need to move away from occasional security checks of their vendors and instead implement continuous monitoring. By keeping a close watch on external partners' security measures, companies can reduce the risk of cyber threats before they escalate into major breaches.





Google’s Quest for AI Dominance: Challenges and Opportunities


Google’s Diversification and Investment in AI

In its early days, Google was primarily known as a search engine, but it has since diversified into many areas of tech and dominates some of them to an extent that sometimes troubles anti-competition regulators. 

Google has made significant investments in AI, including the acquisition of DeepMind, a leading AI research company. The company has also developed its own AI technologies, such as Google Assistant and Google Translate. These technologies have the potential to revolutionize the way we interact with technology and access information.

Competition and Challenges in the AI Race

However, some experts say that Google has already fallen behind in the AI race. Companies like Amazon and Microsoft have made significant strides in developing their own AI technologies, and there is concern that Google may not be able to keep up. 

Despite these concerns, Google remains optimistic about its future in AI. The company has announced plans to invest heavily in AI research and development, with the goal of becoming a leader in the field.

Ethical Implications of AI

As Google looks towards its future in AI, there are many challenges ahead. The field of AI is rapidly evolving, and there is fierce competition among tech companies to develop the most advanced technologies. There are also concerns about the ethical implications of AI, such as the potential for job displacement and the need for transparency and accountability.