
AI and quantum computing: the new frontiers of cyber risk
Almost overnight, widespread AI adoption has disrupted the enterprise landscape, bringing a complex set of new vulnerabilities. Security analysts now track AI as a “dual threat”, multiplying the speed of incoming cyberattacks while simultaneously opening up a brand-new attack surface inside our own networks. In fact, AI-enabled adversary operations surged by nearly 90% over the last year, pushing the time it takes an attacker to move laterally down to just 29 minutes.
Add to this the looming reality of quantum computing preparing to break the encryption we rely on today, and we are facing a threat landscape that moves much faster than traditional governance. The combination of AI‑powered cyberattacks and emerging quantum computing cyber risk means the old playbooks simply don't cut it anymore.
the year the threat landscape shifted
2025 was a pivotal year for the cybersecurity landscape: threat actors moved from experimental use of AI to full operationalization.

everyday AI: you’re already running a shadow SOC
AI is no longer just a tool for developers. In practice, employees are quietly using several unsanctioned AI tools at work (typically 3–5 different AI apps per person each month) .This shadow usage has caused high-risk prompts that expose sensitive corporate data to double in just the last twelve months.
But defenders are using it, too. In security operations centres, AI natively sifts through high-volume logs, correlates events, and powers extended detection and response (XDR). This evolution is turning cybersecurity AI monitoring into an assisted, highly automated discipline that helps overstretched IT teams punch above their weight.
your AI agents are a hacker’s new playground
The nature of attacks is changing because AI has officially crossed from being a simple assistant to an active operator. Hackers are now using it to do the hands-on work during live intrusions, exploiting vulnerabilities directly in AI development platforms to establish persistence or drop ransomware. They are even injecting malicious prompts into legitimate GenAI tools to trick systems into handing over credentials and cryptocurrency.
We are also seeing a sharp rise in indirect prompt injections, turning well-meaning, overly privileged internal AI agents into liabilities. If an internal agent has broad data access and calls third-party APIs without tight governance, it becomes the perfect backdoor.
stopping the bleeding: how to secure workplace AI
You cannot protect what you cannot see. With nearly one in 17 AI interactions carrying a significant risk of data exposure, formal AI governance frameworks are mandatory (approved tools list, data classification rules, red-teaming). But keeping these systems safe doesn't mean reinventing the wheel. The secret lies in applying core data security fundamentals: knowing exactly where your data lives, classifying it accurately, and locking it down with strong encryption.
Surprisingly, only about a third of organisations treat security as a primary objective when rolling out AI projects. Getting this right means applying least-privilege access, segmenting environments, and running continuous adversarial testing. And since human error is still a massive factor, training teams to spot sophisticated deepfakes and AI-generated phishing is just as critical as patching your servers.
the next generation of AI-powered defence is already here
Fortunately, the industry is building better shields. Vendors are adapting their security stacks, allowing IT teams to register AI agents as standard identities to easily restrict their access and keep permissions under central control.
A great example of this is the recent launch of Cisco DefenseClaw, an open-source framework designed to scan AI agents, their plug-ins, and external resources for vulnerabilities. If a risk is detected, the system can block specific servers in seconds, revoking permissions and quarantining files without even needing to restart the agent.
Similarly, Palo Alto Networks just expanded its Prisma AIRS platform (AI Runtime Security) specifically to address agentic AI. It now includes "AI Runtime API" capabilities that act as a firewall directly inside the AI workflow, scanning prompts and model responses in real-time. If it detects a prompt injection, sensitive data leakage, or an agent attempting an unauthorized action, it intercepts and blocks the transaction before the AI can execute it.
Alongside tools like Cisco’s LLM Security Leaderboard and the independents AI Safety Leaderboards that rank language models by their resistance to malicious prompts, we’re seeing a major shift toward embedding automated AI threat detection directly into the platforms we use every day.
steal now, decrypt later: the quantum threat is already here
While AI is the immediate fire to put out, a much larger storm is brewing. We know that future large-scale quantum computers will compromise the cryptographic algorithms that currently protect our sensitive data. Because quantum mechanics can easily solve the math behind RSA and elliptic-curve cryptography, adversaries have adopted a strategy known as “store now, decrypt later.”
They are actively stealing and hoarding encrypted data today, knowing they will eventually have the keys to unlock it. Recent economic models show that retaining intercepted internet traffic is incredibly cheap for attackers, shifting the defensive mindset from preventing storage to making decryption as computationally expensive as possible. It is no surprise that this exact threat is now the top quantum concern for over 60% of security professionals.
building a quantum‑safe estate, not just quantum‑safe algorithms
Waiting for quantum computers to arrive before updating your encryption is a losing game. Standards bodies are already urging system administrators to transition to new quantum-resistant schemes, such as ML-KEM and ML-DSA, immediately.
The good news is that the industry is responding: for example, Cisco’s latest generations of C9350 switches are already post-quantum ready, so shifting to new generations of networking technology makes perfect sense if you want to ensure that you’ll be ready for what comes next. Furthermore, additional digital signature algorithms are actively being evaluated to give organisations more choices for securing their data. And the message is landing: nearly 60% of companies are already planning to prototype or evaluate post-quantum cryptography in the next 18 to 24 months. The priority now is taking a hard look at your entire estate to identify where vulnerable encryption is hiding.
behind the scenes: how we build secure environments in a changing world
From our point of view, the hardest part of managing these twin threats is not simply understanding them but turning that theory into secure, global technology environments that work every day. Because we specialise in IT lifecycle management and technology asset intelligence (TAI), we help clients build a live, accurate inventory of their hardware, workloads, and data flows. This visibility is the non-negotiable foundation for any AI governance or cryptographic migration.
In practice, we design infrastructures where AI workloads run on appropriately segmented platforms, aligning network paths and hardware configurations to each client's specific risk appetite. We also strategically plan hardware refresh cycles so that crypto-agile upgrades are staged logically rather than rushed in a panic.
Because we manage complex deployments worldwide, we know that applying our global reach, local touch approach is the only way to ensure these security controls work just as well on the ground as they do on paper. The journey to a secure AI and quantum-resilient environment always starts with a simple step: seeing what is really running where, and building up from there.
Interested in checking how we could help you build a secure environment for your organization? Get in touch with our team as soon as possible!
Enjoying this article?
Follow expert insights,
industry trends, and more
in our quarterly newsletter!
share with your network
click here to download

