This week:

3 – That annoying drone in the sky could be the start of a cyber attack.

2 – US’ “Move Fast and Break Things” vs Europe “Move Slowly and Protect Things”.

1 – Why charities need to do more to protect their data and their money.

 


 

3 – That annoying drone in the sky could be the start of a cyber attack

“When it comes to opportunities for bad guys to use drones for cyberattacks, the sky’s the limit.”

Source: Computerworld

What’s the story? Drones are emerging as useful tools for warfare and cybercriminals, capable of deploying malware, intercepting data, and executing attacks. This recent article in Computerworld highlights how drones have been used to compromise computer networks, and describes an incident where a financial firm was targeted via drones (equipped with hacking tools) that were landed onto the roof of the office building.

Did you know you can buy a drone for about €950 that can travel autonomously for up to 20km and follow a car that is travelling at over 50 km/h (all while avoiding any obstacles in its path)?

So what? Yep. Not only do we need to worry about all the old ways that the bad guys try to get at us, and how AI is making this harder. We also need to think about drones as potential risks. 

 


 

2 – US’ “Move Fast and Break Things” vs Europe “Move Slowly and Protect Things”

“If certain companies cannot guarantee that their AI products respect the law, then consumers are not missing out; these are products that are simply not safe to be released on the E.U. market yet.”

Source: TechRepublic

What’s the story? The European Union’s stringent AI regulations have led tech giants like Google, Meta, and Apple to delay or limit the release of AI products within the bloc. For instance, Meta’s Llama 4 AI models and Google’s AI Overviews experienced significant delays in their European rollouts due to compliance challenges. While these companies argue that such laws (impact their monstrous profits) hinder innovation, civil society groups contend that the regulations are essential for ensuring user privacy and safety.

So what? The EU’s firm stance on AI regulation underscores its commitment to prioritising user rights and safety over (risky) rapid technological deployment. In reality, a lot of this ‘red tape’ in the EU is not because of new AI regulation. It’s because of well-established data protection and privacy regulations – You may have heard of GDPR! In any case, as I said in a recent interview with the Irish Times, there’s clearly an emerging conflict between the US’s ‘move fast and break things’ approach and Europe’s ‘move slowly and protect things’ approach. These are two ends of a spectrum.

While each society figures out its preferred place on the spectrum, I personally feel we should be closer to Berlin than Boston on this one.

 


 

1 – Why charities need to do more to protect their data and their money

“Just over four in ten businesses (43%) and three in ten charities (30%) reported having experienced any kind of cyber security breach or attack in the last 12 months.”

Source: ​UK’s Home Office (via Risky.Biz)

Summary: The 2025 Cyber Security Breaches Survey by the UK’s Home Office “provides a comprehensive overview of the cyber security landscape for UK businesses and charities”. It reveals that 30% of charities in the UK (which converts to 61,000 charities) experienced some sort of cyber breach or attack in the past year, with phishing being the most common (reported by 86% of charities). In terms of what these charities are doing to reduce the dangers, about 65% have not adopted Multi-Factor Authentication and over 90% do not check the security of their service providers.

So what? These findings suggest the majority of charities need to do a lot more to understand and reduce the risks of a cyber attacker getting their hands on their data or their money.

Many of my clients are charities and non-profits, so perhaps I’m biased. But that doesn’t mean I’m wrong.