Looking ahead in security easily turns either alarmist or uninteresting. Either everything is about to collapse, or everything is just more of the same. This chapter tries to hold the middle by consistently separating what is already happening at small scale, what is technically possible but not yet widespread, and what is still hypothesis.
It opens with the quantum computing threat and post quantum cryptography, why the transition has to be planned long before the threat is real. The logic is uncomfortable but simple. Data stolen today can be stored and decrypted later, which makes the threat current right now for all information with long lasting protective value. Then comes deepfake based social engineering at industrial scale, which links back to the questions of manipulation in chapter 26. AI agents as autonomous attackers get their own section, as does what is described as agentic extortion. The real change there is tempo rather than method, and tempo is what defenders find hardest to meet. After that come hybrid threats where cyber meets the physical world, the generational shift among threat actors, and the continuing convergence between connected devices and industrial systems. One section deals with climate dependent cyber risk, how physical conditions affect digital operations. The structural threats in legislation and the supplier economy connect to chapter 7 on digital sovereignty and are harder to fix than the technical ones, because they sit outside your own control. The chapter closes with the practical part, what can actually be done now.
The reason to read it now rather than later is that several of the measures have long lead times. Cryptographic transitions take years, inventorying information worth protecting takes time, and anyone starting when the threat is acute will not make it. The point is not to predict the right threat but to build an organisation that can adjust when the picture changes.
This page shows what the chapter covers and why preparation has to start before the threat. The assessments, the timelines and the practical steps are in chapter 24 of the book.
The best defence against tomorrow's threats is to start preparing today.
Key insights
- Data stolen today can be decrypted later. That makes the quantum threat a question of which information has long lasting protective value.
- AI agents change the tempo of attacks more than the method, and tempo is what defenders find hardest to meet.
- Hybrid threats blur the line between cybersecurity and physical security, which means they have to be planned together.
- The structural risks in the supplier economy are harder to fix than the technical ones, because they sit outside your organisation.
- Preparation is more about adaptability than about predicting the right threat.
Read on
Next step
Where does your organisation stand?
The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.