Sam Peters, Chief Product Officer at ISMS.online: “You may not think that AI is part of your role, but that’s not to say that it can’t and shouldn’t be used”  

When we last interviewed Sam Peters, we had one focus: security. And that makes sense. Sam has nearly 20 years’ experience in information security, becoming the ISMS.online Chief Product Officer in 2021.  

This time, our focus is on the future of IT. And just as Sam had strong views on keeping organisations safe, he isn’t short of opinions about the technologies about to disrupt our lives.

Take quantum computing. “While AI is advancing rapidly, quantum computing really has the potential to make that speed of progress look truly modest,” he said. “As soon as there is widespread adoption of quantum computing, we could face an industry-wide encryption crisis akin to a modern-day Y2K, but with far greater stakes.”

Naturally, we couldn’t resist asking him about the impact of AI on security as well. On one hand, Sam explains, it will help as AI “underpins new tools and technologies that can help defend an organisation, such as analysing network traffic and understanding where an attack might be originating”. On the other hand, he adds, “…AI will continue to open up whole new attack paths and further democratise cybercrime in ways that otherwise wouldn’t have been possible.”

Our huge thanks to Sam for his thorough and thought-provoking answers. We hope you enjoy reading his take on the future of IT.

What do you think will be the most significant changes in the IT industry over the next 5-10 years?

We’re poised for a major transformation in how IT is delivered, especially around development and security.

Already, tools like GitHub CoPilot and WindSurf AI are changing how people can engage with the task of building apps through their incredible ability to write code and generate user interfaces. The entire development process is being reshaped, and that in turn is bringing about a rethink as to how we go about structuring dev teams.

To understand what the industry might look like in the future, we need to really step back and think clearly about our purpose as IT teams.

A key role of IT has always been about meeting the specific goals of employers or customers – understanding the job that needs to get done, and how technology can improve that. However, if we’re now at the point where anyone can leverage AI to fix a gap or build an app, then IT will need to evolve to support organisations’ goals in new ways.

To achieve this, I believe the makeup of IT teams will simply need to evolve. As AI steps in to help with the heavy lifting of repetitive tasks, departments will need to be reshuffled, and a bright spotlight will be shone on skills.

That process of discovery, of specialism and understanding problems in detail, will become ever more crucial.

How do you envision the role of IT professionals evolving in the future?

I think we will see the increasing importance of specialisation.

In a world where organisations will benefit from ever-greater access to a variety of technologies and tools that are good at app development, or good at enterprise security, then IT professionals really need to think about how they can offer not just good but excellent services.

An expert in a specific field delivering a solution will be quite different to the outcome that a company might get to by purely relying on AI. If technology can now get an enterprise 80% of the way there, then the specialists that can provide that additional 20% of value will be in high demand – particularly among those companies that really want to push the boundaries or excel in the industries they are in.

That goes for everyone – developers, network engineers, support staff, and beyond. Specialists with the knowledge, understanding and capabilities to add significant value, well beyond generic offerings, will thrive. However, it’s worth bearing in mind that this value or specialisation won’t necessarily solely come from purely technical expertise.

Moving forward, human skills such as empathy and understanding will need to complement technologies rather than compete with them. Therefore, organisations will be looking to build teams comprising diverse personality types and characteristics, with a greater focus on soft skills such as critical thinking.

Which emerging technologies do you think will have the biggest impact on IT in the coming decade? 

For me, quantum computing is a really exciting one.

While AI is advancing rapidly, quantum computing really has the potential to make that speed of progress look truly modest. Rapid may become ludicrously rapid, and that could open up a new world of opportunities for IT. However, we must also be cognizant of the potential challenges.

Think about encryption. As soon as there is widespread adoption of quantum computing, we could face an industry-wide encryption crisis akin to a modern-day Y2K, but with far greater stakes. Suddenly, vast swathes of personal, sensitive and financial data protected by the cryptography methods that we’ve all come to rely upon may become vulnerable overnight.

We’re not there yet, but IT teams need to be ready for this kind of alarm.

Generative AI is a clear example of how quickly things can change. For years and years, we had a theoretical technology that sounded like it was something out of science fiction, yet today it’s now a tool that everyone has access to via their browser.

The key is to stay ahead of the curve; to proactively adapt where possible. Of course, in the world of emerging technologies, you can only do so much to prepare. But those who invest early will be in a stronger position to both capitalise on the opportunities and mitigate the challenges of these new technologies as and when they evolve.

What role do you foresee for edge computing and IoT in shaping IT infrastructure? 

Edge computing and IoT have the potential to play a huge role.

In a world where nation-states want to maintain data sovereignty, and corporations seek reassurances about how and where their data is used and shared, I see a very real possibility that a blend of cloud and edge computing will become the new normal.

Hybrid setups could begin to emerge which see businesses storing and managing their data locally, at the edge, to ensure sovereignty and compliance, while still leveraging external cloud-based SaaS tools to run applications.

That ‘blurring’ of concepts could offer businesses the means to mitigate risks in their supply chains. By retaining ownership and control of their data, they will be able to reduce exposure to third-party vulnerabilities and comply with regulations like NIS2 and DORA. However, at the same time, IT teams will also be able to leverage the scalability and flexibility of cloud-based SaaS applications which are essential for modern operational success.

It’s about ensuring that your data is secure, without sacrificing the advantages offered by new technologies, something that this hybrid combination could provide.

It will be interesting to see how regulations like the EU AI Act and standards such as ISO 42001 shift the dial. It’s almost inevitable that these frameworks will lag a bit behind where we are as an industry, but what they will do is establish universal principles and shape the basis of best practice.

The foundations are being laid regarding what is expected from any organisation using AI – be it those that are creating the tools, or those that are integrating them within their operations. And I think we’ll start to see these regulations and standards move towards the kind of prevalence and ubiquity that we’ve seen with GDPR compliance and ISO 27001 in recent years.

However, addressing all the challenges related to cybersecurity is an incredibly large task.

There’s no avoiding the fact that AI is a double-edged sword. Yes, it underpins new tools and technologies that can help defend an organisation, such as analysing network traffic and understanding where an attack might be originating by identifying and flagging unusual behaviour. That speed of detection is vastly superior to human capabilities. However, AI will continue to open up whole new attack paths and further democratise cybercrime in ways that otherwise wouldn’t have been possible.

IT and cyber professionals can use AI, but so too can cybercriminals.

What ethical considerations do you believe will become more critical as IT continues to advance? 

If we think about ethics as being defined by the culture in which we live, then it’s really interesting to consider that there are two quite different approaches taking shape as we speak.

On the one hand, we have the EU introducing legislation focused on managing technology to ensure digital safety and the protection of individual data rights. And then on the other, we have a new US administration that’s focused on deregulation and removing what it considers to be barriers to business and innovation.

That polarised combination is becoming a major source of debate. We’ve seen that with the controversy surrounding Meta’s decision to end third-party fact-checking and adopt community notes in its place.

In the case of IT, it also presents a challenge for any company that operates in different geographies and legislative environments.

How can they tread the line between the different expectations of these markets? Perhaps IT teams will need to be prepared to adopt and manage multi-tiered systems in which products work in different ways in different environments.

Just a few months back Apple delayed the launch of three new artificial intelligence features in Europe, citing “regulatory uncertainties due to the EU’s Digital Markets Act” as the reason. So, perhaps this thinking is already starting to emerge.

What skills do you think will be most valuable for IT professionals in the future?

I was recently speaking to someone at an event, telling them that it would be helpful if I could just hire an AI expert. When we were having that chat, he said to me that he felt I was thinking about things in the wrong way.

He explained that, right now, AI is at the very forefront of the hiring process for IT teams: If a candidate can’t tell you how they would use AI in their job, they’re probably not the person you want to be bringing into your business. If you’re in that group that can use AI, you’re eminently more employable.

It’s an interesting take, to say that, while AI is so nascent in terms of our understanding, already you have those who are embracing it and those who are resisting it. And to be ready for the future, you ultimately need to be in the former camp.

I’ve considered that conversation and now look across our organisation, thinking about how we can ensure our employees understand what AI can do for them.

You may not think that AI is part of your role, but that’s not to say that it can’t and shouldn’t be used. The key is to be curious about new technologies. How could it work in your role? What could you offload to it to become more productive? It sounds really simple, but an EY survey shows that just 54% of people currently use generative AI, and that means there are a lot of people that haven’t.

You might also be interested

About The Author

Avatar photo
Tim Danton

Tim has worked in IT publishing since the days when all PCs were beige, and is editor-in-chief of the UK's PC Pro magazine. He has been writing about hardware for TechFinitive since 2023.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.