A quick survey among 61 participants in the DAPA community showed that the biggest risk is not external attackers, but internal weaknesses. They identified outdated systems and technical debt as the key problem, which makes organizations vulnerable. Artificial intelligence at the same time accelerates attacks and erodes trust in what we see and how we make decisions.
The biggest threats: vulnerability from within
According to 57 % of respondents, the biggest threat is technical debt and outdated systems in organizations. This internal deficit opens the way to attacks, even when security defenses appear solid on the outside. Simply put: the attack comes from outside, but we often create the weakness ourselves.
Other frequently mentioned risks include deepfakes and social engineering, misuse of AI agents, cyberattacks on government services, and a shortage of security experts. What they have in common is that people and processes are decisive, not the technology itself. It is precisely unsystematic practices and missing competencies that amplify the impacts of incidents.
Slovak cybersecurity: improving, but slowly
Participants assess developments in Slovakia rather positively, but not convincingly. 34 % see improvement, a similar share perceive deterioration, and the rest remain between these poles. The trend is therefore moving in the right direction, but at a pace that does not keep up with the growing risks.
According to the survey, we are least prepared in protecting citizens from digital fraud and in responses to large-scale incidents. Weak spots also include the protection of government digital services, the safe deployment of AI, and the recurring shortage of experts. The key lesson: technology alone is not enough; what matters is people’s preparedness and the quality of processes.
AI, rules and sovereignty: trust as a fragile currency
With artificial intelligence, participants see the main risk in attackers adopting it faster and more effectively. There is also a risk that we will stop distinguishing reality from fakes, and organizations are not prepared for such a change. AI thus erodes trust: in human decision-making, in what we see, and in the effectiveness of rules.
Regulations are increasing, but most think they are too complex and that formalism threatens to come at the expense of real security; 31 % rate the rules positively. The prevailing view is therefore that rules are needed, but less can be more. In the debate on Europe’s digital sovereignty, skepticism prevails that we will catch up with the technological lead of the USA, and a strategy of reducing critical dependencies appears more realistic. The overall message is: we create weaknesses from within — at the level of the individual, the organization, the state, and the continent.