For many people, AI means ChatGPT: the application that answers questions quickly, secretly handles homework and makes work a little faster and more efficient. Then there is the smaller group already using Copilot and Claude Cowork extensively. These users realise how powerful the tools are, how much work they take off their hands and how much of an advantage early adopters still enjoy. Finally, there are developers using Claude Code to varying degrees. This group is still surprisingly small. Many companies still prohibit AI-assisted development and want to consider whether to embrace it first.
Looking at the criminal side of society, however, we see people immediately exploiting every opportunity these new tools offer to pursue their malicious plans. You can already see it in the large number of data breaches and ransomware incidents in recent weeks, and the expectation is that there will be many more this summer. Neither cost nor effort is spared in acquiring as much data as possible.
The problem is that AI can search code for weaknesses at enormous speed. Several weaknesses that individually do little harm can turn out to be a major problem in combination. Criminals also run automated scripts, searching for a possible entry point at every hour of the day.
At 42, we are also seeing a striking rise in attempts to break into our applications. What used to happen from time to time is now practically continuous, coming from all corners of the world. Fortunately, my colleagues stay on top of this to ensure those attempts fail.
What can you do yourself? As a business, quite a lot. Do you have old applications that have not been maintained for some time? The first question is whether they are accessible from outside. Internal applications have a smaller attack surface and are less exposed. If they are accessible externally, assess whether they contain personal data or whether an outage would seriously harm your business. If either answer is yes, have the code reviewed — or, better still, have the application rebuilt.
It is also important to allocate enough maintenance budget. This is always a difficult discussion because, at first sight, you receive little in return except security. Where vulnerabilities could once be reviewed monthly or weekly, developers now need to stay on top of them constantly and act as soon as one is published. Criminals read these announcements too, and when something appears online, they can immediately try to exploit it.
Staying alert matters in your private life too. Use a different password everywhere, do not click links you do not trust and, if your instinct says something is odd, take a moment to check whether it is genuine. I have heard plenty of examples of internal emails that looked authentic but were fake. My sister, for example, was contacted by finance to check whether she really wanted to change her bank account just before payroll — she did not, thanks to an attentive colleague. It is wonderful that people without technical knowledge can now build apps, but I would think twice before using a homemade application for sensitive data.
The Dutch Cybersecurity Act is nearly a reality, and many companies will then be required to act (want to know whether your business is covered? Check here). Even if you are not required to act, it is sensible to stay on top of this. Few things are as unpleasant as the negative publicity following a data breach. You want to be able to show that you did everything possible to prevent it. The smart approach is therefore to follow the same rules and document how your organisation has arranged things.
Need help? We are happy to advise. Email info@42.nl or visit the website of our new NIS2 application https://normatik.nl/.