Cybersecurity Risks

Explore top LinkedIn content from expert professionals.

  • View profile for Shawnee Delaney

    CEO, Vaillance Group | Keynote Speaker | Board member | Co-Host of Control Room

    40,337 followers

    Nation-states don’t exploit weak security. They exploit workplace dynamics. I know, because this is exactly how I recruited insiders. Espionage doesn’t start with secrets. It starts with validation. A compliment at the right moment. A shared frustration. Someone who listens when your company doesn’t. That’s not spycraft. That’s just a Tuesday at work. I never asked for sensitive information up front. I asked what was broken. Who made their job harder than it needed to be. What they would fix if anyone actually listened. They thought they were venting. I was mapping access, influence, and motivation. That’s called elicitation. Companies like to believe insider threats come from “bad actors.” They don’t. They come from good employees in very human moments: burnout, loyalty conflict, money stress, bruised ego, identity cracks, resentment that’s been quietly fermenting. And yes, your highest performers were always my favorite targets. They were trusted. They were visible. They had access. And they cared enough to talk. Remote work didn’t invent this. It removed friction. You trained people to network. We trained people to recruit. Same skills. Different intent. If your organization still treats espionage as a cyber problem or a personality flaw, you’re already behind. Because the easiest way into your organization was never through the firewall. It was through someone who finally felt understood. #InsiderThreat #HumanRisk #Espionage #TrustIsASystem #Cybersecurity #Leadership #HR *Photo of me back in the day, post deployment*

  • View profile for Usman Asif

    Access 2000+ software engineers in your time zone | Founder & CEO at Devsinc

    237,693 followers

    Three weeks ago, our Devsinc security architect, walked into my office with a chilling demonstration. Using quantum simulation software, she showed how RSA-2048 encryption – the same standard protecting billions of transactions daily – could theoretically be cracked in just 24 hours by a sufficiently powerful quantum computer. What took her classical computer billions of years to attempt, quantum algorithms could solve before tomorrow's sunrise. That moment crystallized a truth I've been grappling with: we're not just approaching a technological evolution; we're racing toward a cryptographic apocalypse. The quantum computing market tells a story of inevitable disruption, surging from $1.44 billion in 2025 to an expected $16.22 billion by 2034 – a staggering 30.88% CAGR that signals more than market enthusiasm. Research shows a 17-34% probability that cryptographically relevant quantum computers will exist by 2034, climbing to 79% by 2044. But here's what keeps me awake at night: adversaries are already employing "harvest now, decrypt later" strategies, collecting our encrypted data today to unlock tomorrow. For my fellow CTOs and CIOs: the U.S. National Security Memorandum 10 mandates full migration to post-quantum cryptography by 2035, with some agencies required to transition by 2030. This isn't optional. Ninety-five percent of cybersecurity experts rate quantum's threat to current systems as "very high," yet only 25% of organizations are actively addressing this in their risk management strategies. To the brilliant minds entering our industry: this represents the greatest cybersecurity challenge and opportunity of our generation. While quantum computing promises revolutionary advances in drug discovery, optimization, and AI, it simultaneously threatens the cryptographic foundation of our digital world. The demand for quantum-safe solutions will create entirely new career paths and industries. What moves me most is the democratizing potential of this challenge. Whether you're building solutions in Silicon Valley or Lahore, the quantum threat affects us all equally – and so does the opportunity to solve it. Post-quantum cryptography isn't just about surviving disruption; it's about architecting the secure digital infrastructure that will power humanity's next chapter. The countdown has begun. The question isn't whether quantum will break our current security – it's whether we'll be ready when it does.

  • View profile for Kay Daskalakis

    Identity Security → Attack Paths → Adversary Tradecraft → Reach Everyone

    5,241 followers

    Four attacks. Four actors. Four targets. One pattern. Midnight Blizzard hit Microsoft in January 2024. A Russian state actor password-sprayed a forgotten test tenant without MFA, pivoted through a legacy OAuth app with elevated privileges, and walked into production Exchange mailboxes. No zero-day. No malware. A path through identity relationships no one was watching. M&S, April 2025. Scattered Spider impersonated an employee and convinced IT to reset their credentials. From there, lateral movement, ransomware, and a seven-week shutdown of online operations. £££M in lost profit. No technical exploit. A phone call. Shai-Hulud 2.0, late 2025. A self-propagating worm compromised npm maintainer credentials, trojanized packages, and harvested tokens at scale. 750+ packages infected. 33,000+ secrets exposed. The attack surface was npm tokens, GitHub PATs, and cloud credentials. Identity all the way down. Stryker, March 2026. An Iran-linked group gained access to the Microsoft Intune management console and remotely wiped 200,000 devices across 79 countries. Laptops. Phones. Servers. BYOD devices. Gone. No firewall breach. No exploit. They used legitimate admin features. They didn't break in. They became the admin. Four different actors. Four different industries. Four different attack surfaces. Same underlying failure: exploitable identity paths that no one was looking at. The industry called these "sophisticated attacks." None of them required a novel technique. They required a path. From one compromised credential to everything it could reach. Most security programmes don't start here. They start with controls. With compliance. With techniques and countermeasures. The path layer, what can an attacker actually reach if one thing fails, comes later. If it comes at all. That's the gap. When four unrelated breaches share the same root cause, that's not coincidence. It IS a signal. The foundational control isn't a tool. It's an approach: layering risk analysis on identity attack paths first. Before hardening. Before controls. Before anything else. The teams doing this aren't chasing techniques. They're eliminating adversary options. The ones who aren't are fighting a wildfire with a napkin. #IdentitySecurity #AttackPaths #MidnightBlizzard #Stryker #SupplyChainSecurity #AttackPathManagement

  • View profile for Vanessa Hung

    E-commerce Ecosystem Strategist | Amazon & Marketplaces Operations | Top Retail Expert - RETHINK Retail

    26,529 followers

    One wrong word can suppress your listing, or even flag your account. Most Amazon sellers focus on SEO and conversions when optimizing their listings. But here’s what many overlook: Amazon has hundreds of restricted keywords, phrases, and claims that can instantly trigger suppressions, warnings, or even account suspensions. This isn’t just about obvious things like “CBD” or “THC.” Words like “guaranteed,” “safe,” “eco-friendly,” “anti-bacterial,” “relief,” “detox,” and even holiday references like “Labor Day” can all get your listing flagged if they’re not properly substantiated. Amazon’s compliance models are getting smarter and more aggressive: ➡️ Product titles now have stricter formatting rules and keyword limits. ➡️ Health, safety, and eco-friendly claims must be supported by third-party certifications. ➡️ Promotional terms, trust claims, and subjective language are automatically scanned and suppressed. ➡️ High-risk categories like supplements, cosmetics, and pesticides have zero tolerance for unsupported claims. And here’s the problem: most sellers don’t know which words are forbidden until they get flagged. That’s why I put together a detailed list with hundreds of prohibited and high-risk keywords, along with explanations for why they’re risky, so you can audit your listings before Amazon does. If you'd like a copy, simply drop a “LIST” in the comments and I’ll send it over. #Amazon #Compliance #ListingOptimization #EcommerceStrategy

  • View profile for Sélim Chidiac

    Independent Board Director | Former Global CEO | Building & Scaling Businesses through Growth, Innovation and Fit-for-Purpose Governance | Digital Transformation & AI | Advisor to Founders, Chairs and CEOs

    3,854 followers

    In many boardrooms, the agenda is expanding faster than the structure and resources can adapt. This week offered another reminder: U.S. Treasury Secretary Scott Bessent summoned major American bank CEOs to a meeting in Washington amid concerns over the cyber risks posed by Anthropic’s latest AI model: Claude Mythos! When risks escalate this quickly, Board overload accelerates and reduces focus on valuable growth topics. 𝗙𝗲𝘄 𝘀𝗶𝗴𝗻𝗮𝗹𝘀 𝗮𝗿𝗲 𝗵𝗮𝗿𝗱 𝘁𝗼 𝗶𝗴𝗻𝗼𝗿𝗲:   • Independent director time commitment has risen from 250 to over 300 hours a year the last 5 years   • 49% of audit committees report concerns about oversight gaps in cybersecurity and AI   • 70% of directors say Board work now takes more time than before Boards do not solve overload by only working longer. They solve it by working smarter, delegating to specialized Committees and upskilling! Here are few suggestions: ✅ 𝗥𝗲𝗮𝗹𝗹𝗼𝗰𝗮𝘁𝗲 𝗼𝘃𝗲𝗿𝘀𝗶𝗴𝗵𝘁   • Create dedicated committees with the right talent   • Move cyber, AI and digital out of crowded audit agendas   • Review committee charters annually and remove overlaps ✅ 𝗘𝗻𝗵𝗮𝗻𝗰𝗲 𝘁𝗵𝗲 𝗮𝗴𝗲𝗻𝗱𝗮 𝗱𝗲𝘀𝗶𝗴𝗻   • Shift time from backward reporting to forward-looking growth focus   • Use consent agendas for routine approvals   • Reserve time in every meeting for future risks and strategic shifts ✅ 𝗕𝗿𝗶𝗻𝗴 𝗶𝗻 𝗼𝘂𝘁𝘀𝗶𝗱𝗲 𝗲𝘅𝗽𝗲𝗿𝘁𝗶𝘀𝗲   • Invite external experts twice a year on cybersecurity, AI and geopolitics   • Run one annual deep-dive workshop on disruption and fast-moving risks   • Use short expert briefings before major decisions (don’t assume Directors understand all Technical dimensions) ✅ 𝗨𝗽𝘀𝗸𝗶𝗹𝗹 𝗕𝗼𝗮𝗿𝗱 𝗰𝗮𝗽𝗮𝗯𝗶𝗹𝗶𝘁𝗶𝗲𝘀   • Run a rigorous annual Board assessment   • Map Board skills against future needs and close the gaps   • Ensure Directors carry or develop the skills required for the company’s future agenda Strong Boards do not just absorb more pressure. They upskill and redesign how they work. 💡 𝗛𝗼𝘄 𝗶𝘀 𝘆𝗼𝘂𝗿 𝗕𝗼𝗮𝗿𝗱 𝗿𝗲𝗱𝘂𝗰𝗶𝗻𝗴 𝗼𝘃𝗲𝗿𝗹𝗼𝗮𝗱 𝘄𝗵𝗶𝗹𝗲 𝗶𝗺𝗽𝗿𝗼𝘃𝗶𝗻𝗴 𝘁𝗵𝗲 𝗾𝘂𝗮𝗹𝗶𝘁𝘆 𝗼𝗳 𝗼𝘃𝗲𝗿𝘀𝗶𝗴𝗵𝘁? #BoardDirectors #CorporateGovernance #Leadership #Strategy #RiskManagement #AI #BoardEffectiveness

  • View profile for Kay Pang

    Tech Lawyer & Senior Accredited Board Director | Commercial & cross-border deals, technology & AI governance | Kay Pang Law Practice LLC

    10,871 followers

    ⚠️ 𝗕𝗼𝗮𝗿𝗱𝘀 𝗵𝗮𝘃𝗲 𝗯𝗲𝗲𝗻 𝗽𝘂𝘁 𝗼𝗻 𝗻𝗼𝘁𝗶𝗰𝗲. 𝗧𝗵𝗲𝘆 𝗼𝘄𝗻 #AI 𝗮𝗻𝗱 #cybersecurity 𝗿𝗶𝘀𝗸𝘀 - not IT teams. *** I wrote previously on Anthropic's release of its latest AI model, 𝗠𝘆𝘁𝗵𝗼𝘀, a powerful AI cyberhacker, and the dangers it can unleash to critical information infrastructures the world over. In the wrong hands, critical systems can be attacked: • Governments and banks • Hospitals and healthcare infrastructures • Power grids and public services    Initially limited to a handful of trusted companies, there are reports that other actors have now gained unauthorised access to it. While the Singapore government does not have access to Mythos, it is working with partners who do to better understand its capabilities and implications. *** ✅ 𝟱 𝗿𝗲𝗰𝗼𝗺𝗺𝗲𝗻𝗱𝗲𝗱 𝗮𝗰𝘁𝗶𝗼𝗻𝘀: 1️⃣ Update cybersecurity risk assessments of IT systems 2️⃣ Maintain full visibility of asset inventory 3️⃣ Shift to continuous monitoring, automated detection and response 4️⃣ Govern AI tools and their use ⭐ 5️⃣ Deploy AI actively as defence *** 🔍 𝗕𝗼𝗮𝗿𝗱𝘀 𝗮𝗿𝗲 𝗮𝗹𝘀𝗼 𝗲𝘅𝗽𝗲𝗰𝘁𝗲𝗱 𝘁𝗼 𝗰𝗼𝗺𝗺𝗶𝘀𝘀𝗶𝗼𝗻 𝗮 𝗿𝗲𝘃𝗶𝗲𝘄 𝗰𝗼𝘃𝗲𝗿𝗶𝗻𝗴: 1️⃣ Are AI-enabled threats in your risk assessments? 2️⃣ Do you have full visibility over critical systems & third-party dependencies? 3️⃣ Is your incident response fast enough? 4️⃣ Is your use of AI tools properly governed? ⭐ 5️⃣ Where can AI strengthen your defences? Where gaps are found, management must remediate and resource accordingly. *** ⭐ As a #lawyer and #board director who has worked at the intersection of #technology, #governance and #risk mitigation for some time now, I see AI, cybersecurity and regulatory risks already converging on boardroom tables. The boards that navigate this well will not necessarily be the ones with the biggest IT budgets. They will be the ones with the right people around the table - directors who understand law, regulation and digital systems well enough to ask the hard questions. #governance #law #tech #AI #board Singapore Institute of Directors Cyber Security Agency of Singapore (CSA) 📸 Link to this The Business Times article below:

  • View profile for Dr. Rajesh Dhuddu, Ph.D

    Partner & Emerging Tech Leader, Leadership Team @CEDA, PWC| Forbes Blockchain 50| Most Inspiring Web 3 Leader| CXO Innovator of the Year| Tedx Speaker| Author| Passionate about Connecting People & Ideas|

    35,191 followers

    Lets Learn #Quantum – Post #16: Post-Quantum Cryptography (PQC) The Invisible Safe: Why Hackers Are Stealing Data They Can't Read Yet The biggest short-term impact of quantum computing isn't what it can create. It is what it can destroy. Right now, our digital world relies on encryption algorithms like RSA to protect banking, emails, and cloud data. Standard supercomputers would take thousands of years to crack them. But quantum computers change the rules. Running Shor’s Algorithm, a quantum computer could break today's encryption in hours. The Threat Happening Right Now Why care today if full-scale quantum computers are still year away? Because cybercriminals are actively executing a strategy known as Harvest Now, Decrypt Later (HNDL). Imagine a thief stealing a locked titanium safe. They cannot open it today, so they hide it in a basement and wait. Years from now, a new tool is invented that pops that safe open instantly. That is HNDL. Bad actors are intercepting and archiving sensitive enterprise data today, waiting for the day a quantum computer can unlock it. If your data needs to remain secret for the next decade, it is already at risk. Enter PQC: Upgrading the Locks Post-Quantum Cryptography (PQC) is the defense. It is a new generation of math shields designed to resist attacks from both conventional and quantum computers. The breakthrough? PQC runs seamlessly on your current servers, smartphones, and cloud platforms. Think of it as swapping out a traditional door lock for a multi-dimensional biometric scanner. The house stays the same; only the lock changes. Instead of traditional math, PQC relies on Lattice-Based Cryptography. Think of it like a maze with thousands of overlapping dimensions instead of two. Even a quantum computer gets completely lost trying to find the exit. The Strategic Reality You cannot swap out the security architecture of a global enterprise overnight. Migrating infrastructure takes years, which is why forward-thinking leaders are already auditing networks and testing PQC algorithms today using a hybrid approach. The quantum threat is not a future IT issue. It is a current strategic risk. The question for leadership is no longer: "When will a quantum computer be built?" The real question is: "Will our data still be secure when it arrives?" #QuantumTechnology #PostQuantumCryptography #PQC #QuantumSecurity #CyberSecurity #QuantumComputing #DigitalTransformation #DataProtection #TechnologyLeadership Co-authored with Atul Tripathi Sundar Ram, Sachin Arora, Himanshu Ghawri, Azizur Rahman, Shivendra singh, Prasun Nandy, Jaydeep Sarkar, Joydeep Roy, Arihant Garg, Amit Kumar, Hetal Shah, Arun Rangaraju, Sayantan Chatterjee, Rajesh Kumar Ojha, Dr. Raghav Manohar Narsalay, Praveen Sasidharan, Sundareshwar K (Sundar), Manu Dwivedi, Venkat Nippani, Himadri Ganguly, Ritesh Jain, Abhijit Chakraborty, Sumit Srivastav, Anit Shanker #soyoucan

  • View profile for Mark K.

    Founder & CEO, Cobalt Academy Inc | Combat Veteran | Field Artillery Officer | Counter-UAS (C-UAS) & Drone Warfare Experienced | UAS Operator | FAA Part 107 | Operation Inherent Resolve Veteran

    5,423 followers

    A U.S. drone just vanished over the Strait of Hormuz and nobody can clearly explain what happened, and that should immediately raise concern across the defense, drone warfare, and national security community. According to reporting from Forbes, an advanced American unmanned aerial system went dark in one of the most strategically monitored regions in the world without a confirmed shoot down, recovery, or mechanical failure. That detail matters because in modern drone warfare the most dangerous outcome is not destruction, it is denial. Electronic warfare, GPS spoofing, and signal disruption are rapidly emerging as the preferred methods to neutralize high value ISR platforms, allowing adversaries to disable U.S. drone operations without triggering escalation. If a drone loses communication, navigation, or data transmission, the mission is already over, and that reality is beginning to expose critical vulnerabilities in how the United States operates unmanned systems in contested environments. This incident signals a much larger shift in modern warfare where expensive, high end drones are increasingly vulnerable to low cost countermeasures, creating a dangerous cost imbalance that favors adaptation over dominance. From firsthand experience operating in air defense environments and engaging hostile drone threats, the most dangerous moment is not when a drone is detected, it is when it disappears from the feed entirely. That loss of visibility creates hesitation, uncertainty, and risk across the entire battlespace. This is exactly why Cobalt Academy LLC is focused on preparing operators for contested drone warfare environments where jamming, signal loss, and degraded communications are the baseline, not the exception. The future of drone warfare will not be defined by the most advanced platform, but by the systems and operators that can continue to function when everything starts to fail. #DroneWarfare #UAS #CounterUAS #ISR #ElectronicWarfare #AirDefense #DefenseTech #MilitaryTechnology #NationalSecurity #CobaltAcademy

  • View profile for Sanjay Katkar

    Co-Founder & Jt. MD Quick Heal Technologies | Ex CTO | Cybersecurity Expert | Entrepreneur | Technology speaker | Investor | Startup Mentor

    35,989 followers

    I’ve spent 3 decades building security products for Indian businesses, audited 100s of setups, and spoken to 1000s of IT heads, business owners, and CIOs. Still, I keep hearing the same lines before or after things break. Here are the 7 costliest cybersecurity assumptions I hear in Indian mid-sized companies: (1) “That vendor contract includes incident response.” Most don’t. They’ll patch systems. Not lead breach comms at 2 AM. (2) “We have backups, so we’re safe from ransomware.” Until the ransomware encrypts your backups too. (Yes, that happens. Often.) (3) “Our firewall blocks exfiltration.” Firewalls are great. But data doesn’t always leave via the front door. (4) “We’re not a target. No one’s interested in our data.” Your vendor access, email server, or tax filings say otherwise. (5) “We use X tool. It’s very advanced.” Tools don’t save you. People and processes do. (6) “Our developer used SSL. So it’s secure.” That’s like saying “I locked the front door,” while leaving the back gate wide open. (7) “We’ll worry about compliance later.” In India, you’ll likely worry after the media finds out. Most mid-sized businesses don’t need 100 tools. They need less overconfidence, more visibility. And sometimes, just asking “What are we assuming is true, but we’ve never actually tested?” …can save you months of chaos. What’s the most dangerous security assumption you’ve seen firsthand? (Photo from a recent fireside chat at CyberCred Conference.) Quick Heal Seqrite #CyberSecurity #InfoSec #CyberAwareness #Ransomware #DataProtection #IndianBusiness #Leadership #SecurityCulture

  • View profile for 💡 Jerod Brennen
    💡 Jerod Brennen 💡 Jerod Brennen is an Influencer

    Cybersecurity Executive | Board Advisory | CISSP | 25 Years Translating Risk into Business Strategy | CEO & Co-Founder of Aetos One

    31,522 followers

    𝗪𝗵𝗶𝗹𝗲 𝘄𝗲'𝗿𝗲 𝗮𝗹𝗹 𝘁𝗮𝗹𝗸𝗶𝗻𝗴 𝗮𝗯𝗼𝘂𝘁 𝗔𝗜... Two research papers published last week put the quantum threat timeline closer than anyone planned for. Specifically, Google has set a 2029 target for migrating its systems to post-quantum cryptography, ahead of NIST's 2035 deadline. The prior industry assumption was ten years, minimum. Google and a startup called Oratomic published separate analyses pointing to a much shorter window. Cloudflare said publicly it was "very concerned" and still working through the findings. This isn't a defense contractor problem or a cryptocurrency problem. The encryption protecting your data in transit, your authentication systems, your stored credentials: it's built on RSA and elliptic curve. The same math these papers say is breakable. Post-quantum cryptography standards exist. NIST finalized them. Still, most organizations haven't even started migration planning. For most mid-market security programs, the fact is you don't know where all your cryptographic dependencies are. You haven't inventoried which systems rely on which algorithms. And "we'll deal with that when it's closer" got a lot less defensible last week. Crypto agility is what separates organizations that will handle this transition from ones that won't. Not a full migration right now, but rather the ability to swap algorithms without rebuilding your infrastructure from scratch. The first step is the inventory. Know what you're running. Nothing else matters until that work is done. https://lnkd.in/g7msPXBP

Explore categories