Thales | Security for What Matters Most
More About This Author >
Thales | Security for What Matters Most
More About This Author >
Cybersecurity Awareness Month is a campaign that raises awareness about online safety and empowers individuals and businesses to protect themselves from cybercrime. This year, the campaign is built around one simple challenge: make life difficult for cybercriminals.
Staying safe online was never about one perfect decision. It comes down to small habits, repeated consistently, in the ordinary moments that make up a working day. The technology keeps changing. The fundamentals have not.
We asked people across Thales, from sales and marketing to engineering and leadership, spanning the whole world, what that looks like. Their answers follow.
Enterprise data now resides across multiple disparate environments, many of them outside of an organization’s direct control. To make life harder for cybercriminals, our experts argue for focusing on the data itself, not the infrastructure it lives in.
Tushar Haralkar, Director of Sales Engineering, India & SAARC, is particularly assured on this point, noting that “every control we built over the last twenty years assumed one thing: that we own the ground the data sits on. We do not anymore. Which means protection must be attached to the data itself, not to the place it happens to be sitting.”
To implement that protection, Tushar advocates for a three-step approach:
Celestine Heng, Enterprise Account Manager (APJ), echoes this point, arguing that “the most effective practice is acknowledging that infrastructure defense is insufficient on its own. Organizations should secure their operations by encrypting critical data assets directly, neutralizing threats by rendering stolen information useless to attackers.”
Ai Qi Pek, Business Development Representative, ASEAN (APJ), drills down on the issue as it relates to mobile devices. She believes that people underestimate that, for attackers, phones are a gateway to both digital services and security. But it’s not enough to just secure apps.
“In APJ, where mobile banking, payments and digital services are part of everyday life, attackers can exploit identities or applications to ultimately reach valuable data,” she said. “Don’t just ask how you’re protecting the app, instead, ask what data sits behind it, who can access it, and whether that data remains protected wherever it moves or resides.”
For many of our experts, understanding and controlling their cryptographic environment is one of the most important steps towards making life difficult for attackers.
Benjamin Longuechaud, Sales Engineering Lead, United States, looks at the problem from a quantum perspective, noting that “quantum computing has moved from ‘not a priority’ to an active line item in client planning, especially in healthcare and finance.”
He recommends starting a cryptographic inventory that maps “where RSA and ECC are used across your environment and how long that data needs to stay protected. Visibility into your cryptographic assets is usually the hardest step, and the one that matters most.”
Rob Stott, Regional Sales Manager, United States, meanwhile, would like to see more organizations being proactive, addressing foundational data protection concerns before infrastructure loses support, migration forces a redesign, an audit exposes gaps in database monitoring, or new regulatory requirements make encryption more urgent.
“When organizations finally address foundational data protection, the conversation becomes broader. They stop treating encryption, keys, certificates and sensitive data as separate projects and start thinking about how to protect data consistently across their environment,” he said.
Making life difficult for attackers is all about inserting friction into the attack path. The harder it is for a cybercriminal to steal your data, the more likely they are to move onto their next target and, crucially, away from you.
Rob Stott argues that attackers are getting much better at making an email, text or login page look legitimate, and AI is making that process even easier.
He advises that if “your bank, employer or another service sends something unexpected, open the application or website directly rather than using the link. That small pause removes one of the easiest paths an attacker has to your credentials.”
Similarly, Rob advocates for making it “difficult for cybercriminals to pretend to be you. Use multifactor authentication wherever it is available, use unique passwords and be skeptical when a message creates urgency. You do not need to understand cybersecurity technology to make yourself a much harder target.”
Ravi Verma, Senior Technical Lead PS Consultant, takes a similar view, arguing that Cybersecurity Awareness Month is an opportunity to initiative to upskill our workforce and foster a culture of shared responsibility, whether staff are technically minded or not.
When speaking to my sister who is a gynecologist, I deliberately strip away the industry jargon and keep the advice fundamentally simple ‘Never reuse passwords’,” he said.
“I advise her to adopt a reliable password manager and enable multi-factor authentication for banking applications, crypto wallets or anything else that matters and try to adopt FIDO standard security like passkeys wherever available,” he continued. “Far too often, individuals face devastating personal and professional breaches simply because a single compromised site exposed a password they used across multiple platforms.”
Tom Henault, Channel Account Manager, meanwhile, argues that consumers should never use a debit card online. “Not as payment behind an app, not for anything that touches the web. Credit cards have fraud protection and limits to your exposure. With a debit card, if attackers get to your $, that money is gone and you have no recourse,” he said.
For Kyle Ramsey, Regional Sales Manager, United States, making yourself a harder target for email attackers can be as simple as slowing down a little. “Take a deep breath, step back, be meticulous,” he said. “Email is our lives, but taking the extra second to have discipline and review the sender, text, links, makes all the difference in the world from a breach perspective.”
Guido Gerrits, VP of IAM Sales, Europe suggests putting Digital Sovereignty more prominently on the agenda for Cybersecurity Awareness Month, particularly from a European perspective.
“Cybersecurity has traditionally been framed around the CIA triad: Confidentiality, Integrity and Availability. In recent years, the focus has been heavily weighted towards confidentiality and integrity, while availability has received comparatively less attention,” he said.
“Given the rapidly changing geopolitical landscape, I believe Availability is becoming a strategic cybersecurity issue again, in the form of Digital Sovereignty,” he continued. “Organizations need to ask themselves: who ultimately controls our ability to operate?”
This Cybersecurity Awareness Month, don’t make it easy for attackers. Take the small steps that make life that little bit harder for them. A little effort now can prevent major disasters later.
Later this month, we’ll be publishing a three-part fictional series that shows the difference Thales solutions can make in the real world. So, watch this space…