Sicra Header Logo
  • Careers
  • About us
  • People
EnglishNorsk
Talk to us
  1. Knowledge
  2. Insights
  3. Blog
Blog
24.09.2026
min read

The future of cybersecurity: More regulation and three AI risks

Cybersecurity increasingly has legal implications. This includes laws governing how organizations must protect themselves, the consequences of data breaches, contracts with partners, and insurance agreements. This is one of the reasons Sicra works with the law firm Thommessen. 
<span id="hs_cos_wrapper_name" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="text" >The future of cybersecurity: More regulation and three AI risks</span>
Editorial staff
Editorial staffAuthor

– Like Sicra, we prefer to help organizations before something goes wrong. That is the best outcome for everyone involved, both from a socioeconomic and a commercial perspective, says Hedvig Moe, partner and lawyer at Thommessen.

As part of Sicra’s 10th anniversary, we interviewed Hedvig Moe about the future of cybersecurity. Moe began her legal career at Thommessen in 2000 before continuing her career at, among others, Økokrim, the Norwegian National Authority for Investigation and Prosecution of Economic and Environmental Crime, and PST, the Norwegian Police Security Service. She returned to Thommessen in May 2023.

Along the way, she developed extensive expertise in areas including geopolitics, national security and foreign intelligence, political processes, and legislative work. At Thommessen, she heads the firm’s national security practice, providing legal and strategic advice in areas where national security is relevant to businesses and public-sector organizations.

  • Sicra turns 10: While you are reading this, data is being silently stolen from thousands of Norwegian companies. Read how our partner Arctic Wolf uses AI to combat AI-powered cyberattacks.
  • Sicra turns 10: Read our interview with Sicra CEO Gaute Lien on why security leadership is key to building a resilient organization.

National security is becoming relevant to more organizations

– When I returned to Thommessen in 2023, we saw that “national security” would become increasingly relevant to a growing number of organizations. At the same time, we expected more new legislation covering security, particularly digital security. I thought it was very interesting to be part of developing a new practice area, Moe explains.

In hindsight, there is little doubt that Thommessen was right. New legislation is coming both from the EU and at the national level. NIS2, which addresses cybersecurity and digital security, is on its way. The same applies to the CER Directive, which concerns physical security and the resilience of critical societal functions. In addition, “national security” applies to far more organizations than those most people immediately associate with “critical infrastructure,” such as energy companies. Moe gives a few examples:

– If we look at information security, organizations should consider the data they hold. Could it be of interest to foreign intelligence services? Could China or Russia be interested in what the organization is doing? Is the data valuable? Could the information be used to damage or sabotage something, either digitally or physically? Could information in the wrong hands be used to influence important decision-making processes? From this perspective, many organizations need to consider the requirements of the Norwegian Security Act, says Moe.

She adds that awareness of cybersecurity increased significantly following Russia’s full-scale invasion of Ukraine and the first Nord Stream incident.

– That was when many organizations realized that they needed to protect themselves against these kinds of actors, Moe says.

– How do you work with Sicra on cybersecurity? Who does what?

– Cybersecurity is most effective when the legal, strategic, operational, and technical aspects work together. We make sure organizations comply with the law and have the right agreements in place. We provide strategic advice, while Sicra handles the operational and technical aspects. We try to be practical and risk-based. We are very focused on not making the scope broader than necessary, but instead addressing what actually needs to be done. Security work must be simple and precise so that it meets the needs of the organization. You need to devote sufficient resources to security, but not more than necessary, says Moe.

Two areas of expertise: Digital due diligence

While Thommessen handles the legal and strategic aspects, Sicra ensures that the operational and technical elements are in place. In practice, this means that Sicra’s experts carry out what can be described as digital due diligence, a systematic review of an organization’s digital infrastructure, data flows, and vulnerabilities. Who has access to which data? Where is sensitive information stored? Which systems are exposed to the outside world?

This mapping is essential because effective security depends on understanding what needs to be protected. Sicra understands the data, systems, and networks and knows which measures will actually reduce risk for the specific organization. This knowledge makes it possible to translate the legal requirements identified by Thommessen into concrete technical solutions.

The result is two specialist teams working from different directions toward the same goal: ensuring that legal requirements are met, data is protected, and the organization is prepared to withstand a cyberattack.

The future of cybersecurity: More regulation and three AI challenges

Looking ahead, Moe expects legislation concerning digital security to become increasingly extensive. NIS2, the EU directive on cybersecurity, is already in force in the EU and will be incorporated into Norwegian law. The CER Directive is also likely to extend security requirements to more organizations than those currently covered by the Norwegian Security Act.

At the same time, Moe highlights three challenges related to artificial intelligence:

  1. Digital sovereignty. Do organizations have control over the AI services they depend on? What happens if, or rather when, export controls or geopolitical tensions cut off access to critical AI services? Dependence on AI in core business processes without a plan B represents a new and underestimated vulnerability. Does the organization have the resources and expertise needed to replace the AI services it depends on?
  2. Organizations’ own use of AI. Employees are already entering sensitive data into various AI tools that make processes and tasks more efficient and effective. How much control does the organization have over the use of AI? Is the data secure?
  3. AI is a powerful tool for cyberattacks. AI makes cyberattacks more effective, precise, and difficult to detect. Security measures therefore need to keep pace, including by incorporating AI tools into the organization’s defenses.

– AI must become part of an organization’s overall security efforts. If AI is treated as a separate area, there is a real risk that it will not be managed properly, Moe warns.

Prevention pays off: The numbers are clear

Cyberattacks are costly. On average, it takes 24 days to recover from a ransomware attack. That is equivalent to five working weeks. And the financial consequences are significant. According to an IBM report, the average cost of a data breach is more than NOK 40 million. For most medium-sized organizations, that represents a substantial impact on the bottom line.

On top of this come costs associated with GDPR and other regulatory violations, lost customer contracts, reputational damage, and more.

– The knock-on effects of a cyberattack can be significant. This is particularly true today, when organizations rely on long supply chains and complex digital structures, says Moe.

Thommessen is often contacted by organizations that have been affected by cyberattacks. At that point, they need assistance complying with regulatory requirements related to notifying authorities, customers, partners, and other stakeholders.

– If you are hit by a cyberattack, it costs a great deal of money. In addition to handling the attack itself, enormous amounts of time and resources are spent dealing with agreements and contracts relating to compensation and insurance. On top of that come reputational and often ethical issues. And you may not know whether information has fallen into the wrong hands or how it is being used, says Moe.

– That is why we are most concerned with the slightly less exciting part: trying to prevent organizations from being attacked in the first place. That is what we are working with Sicra to achieve. More and more organizations understand this, and the willingness to invest resources and money in preventive measures is increasing, Moe concludes.

Need Assistance?

We are happy to have a non-binding conversation. 
Contact us

Explore more

Cyberattackers use AI, so cyber defense needs AI too
Blog

Cyberattackers use AI, so cyber defense needs AI too

Arctic Wolf on how AI is changing cyberattacks and how organizations can respond.
Gaute Lien: What makes organizations resilient to cyberattacks?
Blog

Gaute Lien: What makes organizations resilient to cyberattacks?

Gaute Lien on the security work that builds digital resilience.
Digital sovereignty must be measured in recovery time, not by the flag on the vendor’s website
Blog

Digital sovereignty must be measured in recovery time, not by the flag on the vendor’s website

Digital sovereignty is measured by how quickly critical services are restored.
How to choose the right SOC services in 2026
Blog

How to choose the right SOC services in 2026

Seven questions to ask before choosing a SOC service and managed SOC provider.

Stay updated
Receive the latest news

Links
SustainabilityFAQPartnersCertifications and awardsCareerPress & brand
Contact
Tel: +47 648 08 488
E-mail: firmapost@sicra.no

Drammensveien 151, 0277 Oslo

Follow us on Instagram

Follow us on LinkedIn
Certifications
iso27001-white
ISO 27001 compliance
miljofyrtarnlogo-hvit-rgb
Eco-Lighthouse
iso9001-white-removebg-preview
ISO 9001 compliance
Sicra Footer Logo
Sicra © 2025
Privacy Policy