Cybersecurity, AI, Data Centers and the Quantum Transition
STORY INLINE POST
For years, cybersecurity was treated as a technical function.
Firewalls, passwords, antivirus software, backups and monitoring systems appeared to belong almost exclusively to the IT department. Boards could ask whether the company was “protected,” approve a budget and assume that specialists would manage the rest.
That vision is no longer sufficient.
Artificial intelligence is increasing the speed, scale and sophistication of certain cyber risks. Quantum computing is forcing governments and companies to review the cryptographic systems on which digital transactions depend. Data centers have become the physical layer that supports cloud services, AI workloads, identity systems, backups, payment infrastructure and security operations.
The risk is not that quantum computers will break every encryption system tomorrow.
The more immediate risk is that many organizations do not know what information must remain confidential for years, where critical data is stored, which cryptographic systems protect it, what suppliers operate the underlying infrastructure or who is responsible for preparing the transition.
Cybersecurity is no longer only an IT function.
It is becoming infrastructure for trust, continuity and competitiveness.
This connection between emerging technology and legal architecture is not new to me. Nearly two decades ago, I explored the legal implications of teleportation based on quantum physics, when the subject still appeared distant from ordinary legal and business practice. The lesson has remained consistent: technology does not wait for legal systems, companies or institutions to feel ready.
Today, that lesson is no longer theoretical.
Know What You Need to Protect
The first obligation is visibility.
Before a company discusses artificial intelligence, quantum computing or advanced data centers, it must understand which digital assets are truly critical. Not all information has the same value, the same legal sensitivity or the same useful life.
A customer database, an industrial formula, a merger file, a payment system, a cloud-based ERP, a CRM, a set of credentials, a legal archive or a confidential contract may require very different levels of protection.
The question is not only what data the company owns. It is where that data lives, who can access it, how long it must remain confidential and what would happen if it became unavailable, altered or exposed.
This is particularly relevant for information with long-term sensitivity. In some cases, data stolen today may retain value for five, 10 or even 20 years. A short-term operational file and a long-term strategic asset should not be treated as identical risks.
Boards do not need to classify every file. They do need to ask a better question:
What are our most valuable digital assets, where are they stored and how long must they remain confidential?
Map Cryptographic and Infrastructure Dependencies
What cannot be mapped cannot be migrated. What cannot be located cannot be protected.
The quantum discussion makes this principle unavoidable. Public-key cryptography is embedded in many parts of corporate life: VPNs, digital certificates, banking platforms, electronic signatures, APIs, cloud services, identity systems, software updates, encrypted communications and archived files.
Many companies depend on encryption every day without maintaining a real inventory of where it is used or who controls it.
The same problem exists with infrastructure. Critical workloads may operate in private data centers, third-party facilities, cloud regions or hybrid environments. They may depend on telecommunications providers, energy supply, cooling systems, backup facilities, contractual service levels and cybersecurity controls managed by third parties.
The cloud is not above us.
It is housed, powered, cooled, connected and protected somewhere.
The International Energy Agency estimates that data centers consumed around 415 TWh of electricity globally in 2024, approximately 1.5% of global electricity consumption. Under its base case, that consumption is projected to reach around 945 TWh by 2030. This should not be used to create alarm. It should be used to understand that digital resilience also depends on energy, location, cooling, redundancy, connectivity, physical security and legal certainty.
The board-level question is direct: Where do we use encryption, where do our critical workloads actually run and which systems would need to migrate to post-quantum standards?
Treat AI as Both a Defensive Tool and an Attack Multiplier
Artificial intelligence is not automatically good or bad for cybersecurity.
It is a multiplier.
Defenders can use AI to analyze logs, detect anomalies, classify alerts, identify suspicious behavior, accelerate incident response and reduce the burden on security teams. In complex organizations, this can improve speed and prioritization.
Attackers can also use AI. Phishing can become more credible. Social engineering can become more personalized. Deepfakes can support fraud. Malware development, vulnerability research and automated attacks may become easier for less sophisticated actors.
In many cases, AI does not create entirely new risks. It makes existing risks faster, cheaper and more scalable.
This has a direct implication for governance. A company cannot evaluate its AI strategy without evaluating the infrastructure and controls that support it. AI workloads require computing power, storage, chips, energy, connectivity and data centers. Security tools also depend on the integrity of the systems they monitor.
A company using AI defensively while ignoring identity management, access controls, vendor risk or infrastructure resilience may be building sophistication on top of fragility.
The right question is: How are we using AI defensively, how are attackers using it offensively and how resilient is the infrastructure that supports our AI and security operations?
Make Digital Resilience a Board-Level and Rule-of-Law Issue
Boards do not need to become cryptographers, data center engineers or incident-response technicians.
They do need to govern digital resilience.
A cyber incident is no longer only a technical failure. It can become a legal, operational, financial, reputational and even energy-continuity event. The consequences may involve regulators, customers, banks, insurers, suppliers, employees and shareholders.
This is particularly important in countries where the energy framework is evolving.
In June 2026, Mexico published guidelines for the voluntary and expedited migration of self-supply and cogeneration electricity permits to the legal figures provided under the Electricity Sector Law. The official agreement covers permits associated with power plants, as well as related contracts, agreements and load centers. Specialized legal analysis has described it as a temporary and exceptional migration procedure, with several implementation stages extending into 2028.
That development should not be interpreted as an automatic threat to energy supply. It should be understood as a reminder that the digital economy depends on legal predictability.
A data center may have excellent firewalls, biometric access controls, redundant servers and advanced monitoring tools. But if its energy procurement model, interconnection conditions, qualified-user status, legacy contract structure, backup arrangements or supply costs change materially because of a regulatory transition, the risk does not come from a hacker.
It comes from the rules of the game.
This is also why legal education in technology matters. My time at William & Mary Law School’s Center for Legal and Court Technology reinforced a practical point that has become even more relevant today: the most important legal questions often appear before institutions have a mature vocabulary to address them.
For boards, this changes the cybersecurity conversation. Governance should include regular reporting, scenario testing and clear accountability for management. But it should also include vendor oversight, cloud governance, data-center contracts, power-purchase arrangements, service-level agreements, energy redundancy and regulatory monitoring.
The board’s role is not to manage the firewall. It is to understand the dependencies that could make the firewall irrelevant during a crisis.
The question is: Who owns digital resilience at the highest level of the organization, and how often do we test the systems, suppliers, energy arrangements and regulatory assumptions on which we depend?
Start the Post-Quantum Transition Before It Becomes Urgent
Quantum readiness does not require panic. It requires preparation.
In 2024, the US National Institute of Standards and Technology released its first three finalized post-quantum cryptography standards. That does not mean current systems have already been broken in a practical and generalized way. It means the migration process has begun.
The challenge is that cryptographic transitions are slow. Certificates, protocols, applications, hardware, suppliers, contracts and legacy systems cannot be replaced overnight.
The Nobel Prize in Physics 2022 helped bring quantum information science, entanglement and quantum teleportation into a broader public conversation. For companies, however, the practical lesson is not to speculate about science fiction. It is to understand that ideas once considered remote can eventually become operational, regulatory and commercial questions.
Companies should begin by creating a cryptographic inventory, classifying data according to its required confidentiality period, identifying critical systems, monitoring standards, coordinating with suppliers and testing migration pathways. Contracts with cloud providers, software vendors and data centers should also evolve to reflect post-quantum readiness, incident notification, data location, resilience obligations and security responsibilities.
The concept of “harvest now, decrypt later” deserves particular attention. If sensitive encrypted information is stolen today and remains valuable for many years, a future cryptographic breakthrough could create future exposure from a past breach.
The board should ask: What information stolen today could still harm us if decrypted five, 10 or 20 years from now, and what infrastructure would keep us operating if our digital supply chain is disrupted?
Mexico’s Trust Opportunity
For Mexico, this discussion is not futuristic.
Nearshoring, advanced manufacturing, financial services, tourism, healthcare, energy, infrastructure and digital commerce all depend on trust. Competitiveness will not be determined only by geography, labor costs or trade agreements. It will also depend on the ability to protect information, maintain continuity and operate securely across digital and energy supply chains.
Mexico has an opportunity to approach cybersecurity as infrastructure rather than compliance.
That requires four layers of preparation: software and data; cryptography and cybersecurity; data centers, energy and connectivity; and the rule of law required to make those systems reliable.
This last layer is often underestimated.
A cloud service may appear intangible to the user, but it ultimately depends on land, electricity, cooling, permits, contracts, interconnection, transmission capacity and enforceable legal arrangements. If regulatory changes alter the economics or continuity assumptions of energy supply, digital resilience can be affected even without a cyberattack.
In that scenario, the vulnerability is not malware.
It is legal uncertainty.
Companies that adopt serious digital governance before it becomes mandatory can differentiate themselves. Suppliers that can demonstrate cyber resilience, energy continuity and regulatory discipline may become more attractive to multinational clients. Data-center operators, cloud providers, legal advisers, insurers, banks and boards can help build a more trusted digital economy.
The quantum age does not demand fear.
It demands that companies understand their dependencies before those dependencies are tested.
The next competitive advantage will not belong only to the companies that adopt AI fastest or migrate to new technologies first. It will belong to those that understand that digital trust must be engineered, powered, regulated and protected before it is needed.






By Luis Miguel Ramirez Ruggeberg | Managing Partner -
Mon, 08/31/2026 - 07:30








