Blog
Why Current Cyber Security is Vulnerable
Almost all digital communication – from banking transactions and email to digital ID systems – is built on cryptography that fundamentally relies on the difficulty of factoring large prime numbers or solving “the discrete logarithm problem.” RSA and Elliptic Curve Cryptography (ECC) have for decades formed the backbone of Public Key Infrastructure (PKI). A classical computer would need thousands of years to break these algorithms – but with a sufficiently powerful quantum computer, the same problems could one day be solved in minutes.
That means the foundation of our digital trust may lose its strength. And while quantum computers have not yet reached this capacity, we know that they will.

“Harvest Now, Decrypt Later” – Why the Threat is Already Here
One of the most misunderstood aspects of the discussion is the time dimension. It’s easy to dismiss quantum computers as a problem for the next decade. But cyber actors have already adapted. Through the strategy of harvest now, decrypt later, encrypted information is collected today, with the intent of decrypting it in the future once the technology makes it possible. This means that long-lived data – such as medical records, research results, intellectual property, and sensitive communications – is already at risk.
In other words: even if Q-day – the day when quantum computers can practically break today’s encryption – is still ten, fifteen, or twenty years away, the threat is already here. The data being recorded now could become a goldmine for future attacks.
Regulatory Initiatives That Change the Game
The global regulatory responses underline the seriousness. The U.S. Quantum Cybersecurity Preparedness Act requires federal agencies to begin the transition to post-quantum cryptography. NIST, after eight years of work, has introduced four new quantum-resistant algorithms (three for digital signatures and one for key exchange/encryption), which are already being validated and implemented into international standards.
The EU has published a joint policy roadmap – as part of its broader cybersecurity strategy and tied to the NIS2 directive – mandating that critical infrastructure and high-risk data should be migrated by 2030. Meanwhile, the UK’s NCSC has developed detailed timelines making it clear that organizations must begin their preparations now to avoid falling behind.
The message is clear: the transition is not optional. It will be driven by regulatory requirements, and organizations that fail to prepare risk both legal and business consequences.
The Practical Challenges – More Than a Technical Update
Changing encryption algorithms may sound simple in theory, but in practice it represents one of the largest technological shifts organizations have ever faced. Encryption is embedded in everything from business-critical applications and operating systems to cloud platforms, APIs, and supply chains.
The transition will therefore be a multi-year project that touches the entire ecosystem. Performance issues arise when new algorithms with longer keys are implemented. Legacy systems may lack support for updated libraries. During the migration period, hybrid solutions where classical and quantum-resistant methods coexist are often required. And even quantum-safe algorithms are not immune to threats – implementation flaws or side-channel attacks can create new risks.
This is precisely why cybersecurity experts speak of the need for crypto-agility: the ability to rapidly switch algorithms when standards change or new vulnerabilities are discovered. It is no longer about finding a “final” solution, but about building systems prepared for continuous adaptation.
What This Means for Decision-Makers
For CIOs, CSCOs, and CTOs, this brings a new strategic responsibility. The issue of quantum computing and cybersecurity cannot be handled solely by technical teams – it belongs on the executive agenda. Investments in digitalization, cloud migration, and data management risk being undermined if the cryptographic foundation collapses.
The decisions made today will determine how well an organization is prepared when quantum computers reach practical capacity. Waiting until the threat is here is not an option – because by then, it will already be too late. The data that should have been protected will already be exposed.
The Road Ahead
Preparing for the quantum era must increasingly become an integral part of how companies and societies protect their trust capital, intellectual property, and business models.
It requires risk assessments to understand which data is most vulnerable and has the longest lifespan. It requires planning and budgeting for a migration that will stretch over years. And it requires close collaboration between technology leadership, business operations, and regulatory requirements.
At HiQ, we see that companies who start preparing early not only reduce their risks – they also strengthen their position in a market where trust and cybersecurity are becoming key differentiators. Get in touch with us and we’ll tell you more.
Contact
Region
Alina Gehrmann
Marketing Manager
Alina is part of HiQ’s marketing team. She enjoys traveling to other countries or immersing herself in a good novel. Otherwise, you can also find her outdoors – hiking or in her garden.
How We Use ChatGPT Today
Most people use ChatGPT to save time in daily life. At work, it’s often about polishing texts: making emails more formal, shortening reports, or making presentations more compelling. In private life, it’s recipe ideas, travel planning, or a faster way of googling for facts.
That’s valuable, and for many, ChatGPT has already become an essential tool. But the use is still fairly basic and far from what the technology can actually deliver. We settle for the flashlight when the entire app ecosystem is waiting to be explored.

So Much More Is Possible
To move from flashlight to full iPhone functionality, we need a higher level of ambition. Some examples of how ChatGPT can be used more powerfully:
- Agentic Workflow: Many companies struggle with time-consuming manual processes. ChatGPT can act as a process engine orchestrating other systems. The value: freed-up time, fewer errors, and scalability.
- Decision-support copilot: Management teams often lack quick, high-quality decision input. ChatGPT can analyze data and create scenarios. The value: faster and better decisions.
- Hyper-personalized customer interactions: Customers often face generic messages. ChatGPT can create tailored communication based on customer data. The value: higher conversion, loyalty, and customer lifetime value.
- Compliance & contract watchdog: Lawyers and auditors are overwhelmed by agreements and regulations. ChatGPT can review and flag discrepancies. The value: reduced risk and lower compliance costs.
- Internal training and onboarding: New hires and teams often struggle to get up to speed. ChatGPT can function as an interactive coach and training partner. The value: shorter onboarding times and a more consistent knowledge level across the organization.
What We Risk Missing
If we don’t raise our ambitions, we miss the real potential. According to research, generative AI could already today create welfare gains equivalent to hundreds of billions of dollars each year. But that requires moving beyond small efficiency gains in the inbox and instead using the technology for deeper analysis, better decisions, and stronger innovation.
It’s in the strategic, creative, and long-term use that the big difference emerges. Seeing AI as more than a digital assistant, and instead as a partner in how we learn, develop, and make decisions, is the way forward.
From Flashlight to Full Functionality
To level up, we need a new perspective on technology. We must start seeing ChatGPT not just as a service for quick answers but as a partner in our thinking. Once we do that, we can use it to drive processes, strengthen decision-making, and develop new ways of working.
When we limit ourselves to the flashlight, we never see what the phone can really do. But when we unlock the full ecosystem – the apps, the camera, the communication – it reveals its full potential. The same goes for generative AI. It’s only when we use it to support research, innovation, strategic decisions, and learning that we see the true power we have access to.
Conclusion
ChatGPT is like an iPhone: packed with capability and built to transform how we work and live. But as long as we settle for just switching on the flashlight, we miss what makes the technology revolutionary.
In short, it’s about raising our level of ambition. We must look beyond short-term time savings and start using AI as a powerful partner in both creative and analytical work. Only then can we move from flashlight to full functionality and unlock the real power of AI.
Want to talk about how to maximize business value with AI? Get in touch!
Contact
Region
Alina Gehrmann
Marketing Manager
Alina is part of HiQ’s marketing team. She enjoys traveling to other countries or immersing herself in a good novel. Otherwise, you can also find her outdoors – hiking or in her garden.
When AI Becomes Both Defense and Weapon
AI has already begun to redefine cybersecurity. Cybercriminals use generative models to create convincing phishing emails, deepfakes, and large-scale automated fraud campaigns. Tools that once required advanced technical skills are now commercially available for just a few dozen dollars a month.
AI is also used to develop and modify malicious code, discover vulnerabilities, and manipulate existing AI systems – all with increasing precision and speed.
“We are seeing in practice how the same AI technology is used on both the attacking and defending sides. As we strengthen our security capabilities, new ways for attackers to exploit the technology emerge.”
– Pernilla Rönn, Head of Cybersecurity, HiQ
But AI is not just a threat. As cybersecurity solutions become more intelligent, AI is used to detect and stop intrusions far faster than before. In Security Operations Centers, up to half of all incidents are now handled with the support of AI, which analyzes logs, identifies anomalies, and prioritizes threats in real time.

Three Ways AI Is Transforming Cyber Threats
- Attackers scale up with generative AI. Hyper-personalized phishing emails, voice clones, and deepfakes no longer require advanced tools – only access to ready-made solutions.
- The attack surface expands rapidly. AI generates new code, finds vulnerabilities, and bypasses defenses in real time.
- Defenders become smarter. AI strengthens detection, analysis, and response – but requires proper implementation to avoid new risks.
A Growing Attack Surface and New Vulnerabilities
As AI becomes integrated into more parts of the organization, both efficiency and complexity increase. New attack surfaces emerge in data flows, code, and decision-making processes. At the same time, we see a growing phenomenon known as shadow AI – AI tools used within the organization without approval, risk assessment, or testing.
“Without standardized and secure AI solutions, employees turn to their own tools. The result is a shadow-AI landscape with fragmented data, low traceability, and increased compliance risks.”
– Sofie Perslow, Head of AI, HiQ
Preventing shadow AI requires three things:
- Clear ownership of AI – with a central authority coordinating strategy, risk assessment, and guidelines.
- A culture of awareness – where employees understand both the value and risks of AI, and receive training on proper tool usage.
- Good and approved alternatives – secure platforms that are as smooth and useful as open tools, so employees don’t feel the need to bypass the organization.
When these elements are missing, invisible risks arise around data leakage, bias, and lack of transparency. This is where governance and culture become crucial – not just to avoid incidents, but to enable sustainable, business-driven AI adoption.
AI as Part of the Cyber Defense
At the same time, AI enables entirely new defensive capabilities.
- Detection and response: AI-driven XDR/NDR solutions identify anomalies in networks and endpoints in real time.
- Incident analysis: Generative models summarize incidents, triage cases, and help security teams and SOC analysts act faster and more effectively.
- Threat intelligence: AI-based knowledge graphs map leaked data, trends, and dark web activity before attackers exploit them.
“AI can make security more accurate, but only if it is built the right way. It’s about combining technological innovation with clear governance and meaningful human oversight.”
– Pernilla Rönn
How to Build Secure AI – Without Slowing Innovation
HiQ’s approach to secure AI is built on three core principles:
- Privacy: Secure data handling through anonymization, traceability, and awareness of bias.
- Resilience: Continuous testing, misuse detection, and rollback mechanisms built into the architecture.
- Transparency: Logging, traceability, and human-in-the-loop – critical both for the AI Act and for trust.
A key insight within resilience: AI systems integrated into critical environments rarely have a simple off switch.
“When AI is used in critical systems, it’s often technically impossible to simply turn it off. Instead, you need rollback mechanisms, misuse detection, and operational kill switches that can be activated in real time without shutting down the entire operation.”
– Sofie Perslow
The goal is not to slow development, but to build systems that remain controllable and recoverable – even under pressure.
“Security shouldn’t slow innovation – it should enable it. When security is part of the design from the start, you create an environment where AI contributes to both efficiency and safety.”
– Sofie Perslow
From Protection to Strategy
AI and cybersecurity are no longer separate disciplines – together they shape how organizations develop, automate, and innovate. For future digital solutions to be sustainable, security must be integrated from the beginning, not added on afterward.
HiQ helps companies and public organizations build AI-driven solutions where security, business value, and innovation go hand in hand. There may be no off switch for tomorrow’s innovations – but there are ways to build them securely.
Contact
Region
Alina Gehrmann
Marketing Manager
Alina is part of HiQ’s marketing team. She enjoys traveling to other countries or immersing herself in a good novel. Otherwise, you can also find her outdoors – hiking or in her garden.
About Lively Apps
Founded in Munich, is a small team of just eight. Yet they have helped over 3,000 companies worldwide streamline collaboration and boost productivity since joining the Atlassian Marketplace in 2013. Their apps extend Atlassian’s core products, transforming Confluence into an active and vibrant workspace for their users.With tools like for effortless data integration and for engaging internal communication, Lively Apps shows how a passionate, small team can make enterprise software feel personal and dynamic.
In this blog post, we welcome you into our internal hub to show you how we use Lively Blogs to turn Confluence into a dynamicplace for announcing company-wide news.
The Challenge: Making News Get Read
As HiQ continued to grow, it became harder to keep internal communication aligned. From marketing campaigns and HR updates to leadership announcements, there wasn’t a single place where employees could reliably find the latest news.
The team needed a solution that would:
- centralize all latest info in Confluence
- make important updates stand out
- encourage contributions from different departments

The Solution: A Custom Dashboard with Lively Blogs
HiQ tackled this challenge by using Lively Blogs for Confluence.
This setup transformed the homepage into a company-wide news channel. Team members across departments, not just Marketing, now use Lively Blogs to share updates, big and small. Whether it’s a new HR policy, a leadership announcement, or a campaign launch, everything flows into one accessible stream.
“It’s become a natural habit,” Alina says. “When people want to know what’s going on, they check the dashboard. It’s right there.”
Highlighting What Matters
To make key information stand out, HiQ uses our favourite feature. With our “important” label, you can pin any post you want at the top of the Confluence. This ensures leadership messages, time-sensitive HR updates, or strategic changes don’t get lost in the flow of regular updates.

Lively Blogs has become our go-to tool for internal news. As the marketing team, we use it to share updates and internal events. Especially with the pins option we make sure everyone knows about the latest updates. It really brings everything together in one place.
Why HiQ Loves Lively Blogs
By embedding Lively Blogs into their dashboard, HiQ created more than a blog, they built a shared communication space that fosters transparency and a sense of community across the company.
Reaching the whole team, no matter where they are, isn’t just important – it’s essential for building a strong, unified culture.
Contact
Region
Alina Gehrmann
Marketing Manager
Alina is part of HiQ’s marketing team. She enjoys traveling to other countries or immersing herself in a good novel. Otherwise, you can also find her outdoors – hiking or in her garden.