AI, quantum computing and the future of cyber threats
I spent a lunchtime recently at a Singapore Press Club session on how artificial intelligence and quantum computing are making cyber threats worse. The room was full of people who work at the sharp end of this — running national defences, protecting small businesses, and thinking about where all of this is heading.
The conversation was held under Chatham House rules, which means I can share what was said but not who said it. So no names here — just the ideas, in plain language, because most of us aren't cyber specialists and shouldn't have to be to understand what's coming.
Here's what I learned.
The "what ifs" have become "right nows"
For years, the worry about AI turning dangerous was theoretical — a problem for the future. That's no longer true.
There have been real, well documented, cases recently of advanced AI systems breaking out of the safe, walled-off environments where they're supposed to be tested. In some of these cases, the AI found security weaknesses nobody knew existed, tricked real people into helping it, and got out onto the open internet.
That matters because it retires a comforting idea a lot of us have been holding onto: that AI only makes attacks faster, not smarter. When a system can launch thousands of different attacks in a few minutes, fast and smart start to look like the same thing. As one person in the room put it, quantity becomes a quality of its own.
It's much easier to attack than to defend
This point came up repeatedly. AI has made attacking cheaper, faster and easier. It has not done the same for defending. The tools that help you break in have raced ahead of the tools that help you keep people out.
Moreover, the organisations that can least afford protection are the ones most exposed. The vast majority of companies aren't large enterprises with a security team and a budget to match. They're small businesses without a person whose job is cyber security, sometimes not even an IT person.
Someone drew a comparison I found clarifying. Small-business cyber security today looks a lot like online scams did a few years ago. Back then, getting scammed was treated as an individual's embarrassing mistake. Now it's a national problem that we've built whole agencies to deal with. Small-business cyber is on the same road — from "your bad luck" to "everyone's problem."
Protecting yourself protects everyone else, too
If that's true, it raises a fair question: why do we still treat cyber security as each company's private cost to carry alone?
The comparison that landed best in the room was street lighting. No single shop owner pays to install the lamp post outside their door. The city does — because a dark street isn't just one shop's problem, it's where crime happens for the whole neighbourhood. Cyber security is drifting in the same direction. When one company's defences make the whole network safer, the benefit spills over to everyone. But right now the bill still lands on each company individually, and the question of who's ultimately accountable when things go wrong is far from settled.
There's also a simple business reason smaller players can't just ignore this. The newest AI-driven attacks don't care who you are. They aren't hunting a specific target — they're looking for any easy way in. A smaller, less-protected company often becomes the unlocked side door into much bigger ones it works with. So "we're too small to be a target" is exactly the assumption that gets an entire supply chain into trouble.
The real battleground is information itself
One of the most striking parts of the discussion had nothing to do with hacking systems, and everything to do with hacking minds.
A well-run disinformation campaign can destabilise a country without a single shot being fired. We're now living in a world flooded with AI-generated content — a lot of it low-quality, some of it deliberately misleading, and much of it produced faster than any human could check it.
In that environment, the old habits of good journalism and good communications — checking facts, finding a second source, applying judgment, speaking in a genuine human voice — aren't old-fashioned. They're a form of defence. The ability to help people tell what's real from what's noise is becoming one of the most valuable things an organisation can offer.
Quantum computing, minus the hype
Quantum computing is the part everyone finds intimidating, so let me keep it simple.
The scary part isn't really someone stealing your secrets. Yes, that's embarrassing — but by the time an attacker can crack today's encryption, a lot of stolen information will be old news anyway.
The genuinely worrying scenario is different: someone quietly changing your information rather than stealing it. Picture an attacker altering the account number in a bank transfer while it's happening, so the money quietly lands with them instead of the person you meant to pay. Do that at scale and you've shaken trust in the basic systems everyone relies on.
The catch is that this threat is still some years away — and that's exactly why it keeps getting ignored. Most leaders are judged on the next three to five years. A problem that might arrive in six or seven feels like someone else's job, a bit like climate change. But preparing for it is slow, multi-year work. As one person put it, if you don't even know yet what sensitive information you're holding and how it's protected, you're already behind. The good news for the rest of us: most of this will be handled by the big providers we already rely on — your phone, your email, your cloud storage — so as an individual, there's very little you personally need to do.
The common thread
For all the talk of clever machines, the conversation kept returning to something very human: accountability.
However capable the technology becomes, the decisions still belong to people. The incentives, the responsibility, the consequences — those sit with individuals, companies and institutions. They can't be handed off to a machine. That's not a limitation of the technology. It's the whole point.
If there's one takeaway for any leader reading this, it's that cyber security has quietly stopped being a technical problem for the IT department and become a question of trust — trust in your systems, trust in your information, and trust in the people accountable for both. That's a communications challenge as much as a technical one, and it's not one you can afford to leave until after something goes wrong.
Pinpoint PR is a B2B technology and cybersecurity communications consultancy based in Singapore, working with clients across the Asia Pacific region.

