Back to blog

AI found a crypto flaw humans hunted for two years – and why that is good news for small organisations

Håkon Berntsen ·
AI found a crypto flaw humans hunted for two years – and why that is good news for small organisations

This week’s big AI story sounds like science fiction: Anthropic’s most powerful model found, in 60 hours, a weakness in a quantum-safe encryption scheme that human experts had scrutinised for two years. The scheme, HAWK, is a candidate to become a US federal standard. The model also invented an entirely new attack technique against a weakened research variant of the AES encryption standard.

The first reaction for many running a small organisation: "Is our data safe?" Short answer: yes. Nothing in use today has been broken – HAWK is not deployed anywhere, and the attacked AES variant was deliberately weakened for research purposes. You do not need to change your passwords, and you do not need new tools.

But the story is a rare good occasion to tidy up something most small organisations postpone: basic data security. Because the bigger picture is real enough – AI means flaws and weaknesses in all kinds of systems will now be found much faster, by defenders and, eventually, attackers. In that world, those with the basics in order win.

The security starter pack for small organisations

None of the items below cost money. Together they stop the vast majority of attacks small organisations actually face – phishing and guessed passwords, not quantum computers.

1. Turn on two-factor everywhere

Email, banking, member systems, social media. Two-factor authentication (a code on your phone in addition to the password) stops most account takeovers, even when a password has leaked. It is the single most important measure a small organisation can take – and it takes one evening to roll out.

2. Let systems update themselves

This week’s AI findings show the pace at which flaws are now uncovered. The fixes arrive as updates – but only for those who install them. Enable automatic updates on your website (WordPress core and plugins!), computers and phones. Outdated WordPress plugins remain the most common way into small organisations’ websites.

3. A password manager instead of reuse

One strong, unique password per service, stored in a password manager. Reused passwords are why one leak in one place becomes break-ins in five others.

4. Know where your personal data lives

Member lists and donor data belong in established systems with encryption and a data processing agreement – not in spreadsheets on private laptops. Established cloud providers handle encryption for you (including the transition to quantum-safe encryption, when it comes); that is precisely the point of using them.

The bigger picture: AI as watchdog

Note the sign of this week’s news: the weakness was found by researchers, in a scheme not yet in use, and disclosed responsibly – so it can be fixed before anyone is harmed. That is how AI-driven security work should function, and small organisations will benefit from the same in more everyday form: tools that find holes in websites and configurations before attackers do. Combined with the ground rules we wrote about earlier this week, the message is consistent: the technology is getting more powerful at high speed – and the organisations that benefit most are those that keep the basics in order.

More to read

Related Articles

Stay updated

Subscribe to our newsletter for news about open source, AI, and digital innovation.