Cyber Risk Starts With Us, Not With AI
Over the past two months I attended several events with C-suite executives and board members. In rooms like these, you quickly get 250-plus devices on the same Wi-Fi. Without a single attack, just from what devices broadcast openly into the room on their own, a precise picture forms within minutes: device type, operating system, and, combined with an attendee list, often the person behind it and their employer. This is only about signals that are visible to anyone in the room anyway, and that I neither read out nor store. It has nothing to do with anyone’s private content.
Blaming rising cyber risk on AI is easy and convenient. It is just not quite right.
AI is not the real problem
Fear of cyberattacks is growing, and AI gets named as the biggest danger more and more often. That danger is real and belongs on the agenda of every executive team and board. But the fixation on AI shifts attention away from where most attacks actually start: with us. Out of ignorance, out of convenience, out of an internal or external IT function that does not prioritise security, out of insufficient training and missing technology competence.
AI lowers the cost of an attack and raises its success rate. But we are the ones leaving the doors open. I want to open exactly one of those doors here: open Wi-Fi.
Open Wi-Fi: everyone connects, almost nobody questions the security
Hotel, train, airport or conference, the pattern is the same everywhere. A network is available, and most people connect without asking what sits behind it.
- Nobody knows the state a public Wi-Fi network is actually in, or what it logs. An event organiser or a hotel rarely has a well thought-out security setup.
- Anyone who connects to “Airport-Guest” has no guarantee that the airport or the airline is really behind it. An attacker sets up an inconspicuous access point, relays the traffic as a man in the middle, and reads along.
- The credentials sitting on the tables may well have been swapped out already, and the QR code may lead somewhere else entirely.
This takes no specialist knowledge and little effort. Anyone who knows how to capture network traffic can do it. It does not even require serious infrastructure; the necessary software runs on a mobile phone.
“Our data is encrypted” is true, and it still does not protect you
The most common objection runs: our traffic is encrypted, so we are safe. That is true, and misleading all the same. True, because the content itself is indeed often encrypted. Misleading, because the attacker is not interested in that content at this stage. All they need is the metadata for the next stages of the attack, things like the machine name, the operating system, running services or the MAC address.
Ransomware attacks, for instance, can be split into four phases: preparation, access, spread and infection. What becomes visible here is phase one in its purest form, preparation. Reconnaissance with no risk to the attacker, long before anything gets encrypted.
What devices actively give away on their own
The same patterns keep showing up in practice:
- Clearly identifiable devices: For roughly a third of devices, name, model and operating system are openly readable. For about a tenth, the device can be tied to a person as soon as the open device name is combined with an attendee list: Max Muster’s MacBook from XYZ AG. An excellent starting point for a targeted attack.
- Outdated systems: The openly visible device characteristics reveal which ones on the network run outdated or unpatched operating systems. The share is usually in the low single digits. Small, then, but not zero, and for a company it has to be a no-go regardless of whether the device is private or corporate.
- Open remote access: Remote access to laptops, screen sharing for instance, is repeatedly set up incorrectly and left open. The same goes for shared folders. Users are often unaware, and IT apparently has not looked into it.
- Mixing personal and business use: Max Muster’s personal phone has no place directly on the corporate network. There are ways to secure such devices. Skip that out of convenience, and the seemingly cheap option often turns expensive later, on both the privacy and the security side.
Why these individual signals become dangerous together
Each of these signals is harmless on its own. Combined, they are valuable.
An unpatched system can become a target the moment it is spotted. Device information paired with an attendee list produces a picture of the person and their employer, and an asset tag like “SampleCorp#4524” helps IT. It helps the attacker just as much. Anyone who knows a device name, operating system, person and company builds a spear-phishing or CEO-fraud attack vector with far less effort.
The installed software is especially sensitive. If a device runs a VPN client from a vendor with a known, unpatched vulnerability, it takes little to strike. This is not a theoretical scenario. According to Switzerland’s federal cybersecurity office (BACS), the ransomware group “Akira” specifically exploited SonicWall devices in Switzerland in the second half of 2025, targeting a vulnerability from 2024 that had not been consistently patched everywhere. For scale: in that half-year alone, BACS logged 29,006 voluntary reports and 145 mandatory cyber-incident reports. From my own observation, I would add: this affects self-managed devices just as much as those looked after by an external IT provider. That is exactly where monitoring urgently needs work.
You have to accept that there is no fairness between attack and defence. An attacker only needs to find the one gap, which in many cases is even a known one. Defence has to close a thousand gaps, and design the architecture to cover “unknown unknown” scenarios on top of that. Put differently: the bar for defence sits far higher than the bar for attack.
My recommendation
I do not connect to public Wi-Fi, at home or abroad. If it is ever unavoidable, in an enclosed space or with poor reception, then only over my own VPN connection and on a device free of the vulnerabilities described above. Mobile data is cheap today; a free Wi-Fi network, by contrast, can turn out expensive. Anyone using open Wi-Fi instead of mobile data is cutting costs in the wrong place. And yes, mobile data networks are not automatically secure just because a telecom provider stands behind them. As a rule, though, they are safer than open Wi-Fi. The point is to set the bar as high as possible, because absolute security is a dangerous illusion.
No visible device or user information, neither on the device nor in network traffic. Asset tags and company logos are convenient, but they help the attacker too.
All infrastructure gets the necessary updates promptly. Nearly ten per cent outdated devices in a room of 250-plus is a large attack surface. One of the bigger cybersecurity challenges tied to AI is the speed of attacks. Where a system once had days or weeks to be secured after a vulnerability became known, it often has only hours today. Gaps are increasingly exploited actively even before they become public. Speed is therefore a decisive factor.
Correct configuration by IT or the IT provider. Remote-support software being convenient to install, and often misconfigured as a result, does not make a device secure. The attacker gladly accepts that invitation.
The image of the attacker
Talking to executives, I often sense a particular image of the attacker: a teenager in a dark room with an energy drink and instant noodles, or a gang in some notorious country in the east. In practice, that image does not carry far enough.
The attacker can just as easily sit next to you in a suit, at the airport, on the train or at the conference, drawing out information from you, actively or passively, that is worth little on its own but a great deal in sum. It might be the pleasant conversation partner you enjoyed talking to, who now knows your weak points.
Cybercrime is a billion-dollar business and therefore economically attractive. Accordingly, attackers invest in know-how, people and infrastructure. The attacker only needs to find a single gap; the defence has to close thousands. This asymmetry works against companies. Today the main problem lies in insufficient awareness and poorly configured, poorly maintained systems, not yet in AI. That is uncomfortable, because it points back at us. It is also the good news, because this is exactly where we hold the lever.
The board’s role
The board carries overall supervision, and under Art. 716a para. 1 no. 5 OR that duty cannot be delegated. That does not mean the board has to review Wi-Fi configurations in a specific case. It means the board puts the topic on the agenda, sets the risk appetite, demands meaningful reporting, and satisfies itself that devices, IT providers and training are genuinely under control. Anyone who simply accepts the reassuring summary is not exercising their supervisory duty. Anyone left in the dark here should urgently consider a cybersecurity audit and commission the executive team to carry it out. The matter also hits the board very personally. As the top governing body, it sets an example and typically also holds access to commercially sensitive data, making it an attractive target in its own right.
The executive team is responsible for implementation: binding rules for Wi-Fi and VPN, functioning patch and device management, bringing mobile and personal devices in through a suitable platform, hardening configurations, managing IT providers and regular training. It is equally responsible for giving the board a realistic picture rather than a flattering one. In practice, you often hear instead that the organisation needs to focus on operations and has quite different problems than cybersecurity. The pattern is familiar: eventually an attack forces the company, at the worst possible moment, to invest exactly that time after all, and it usually costs far more than serious preparation would have.
The board and the executive team have to work together on this, because the attacker is simply waiting for nobody to take responsibility.