Nation-states don’t exploit weak security. They exploit workplace dynamics. I know, because this is exactly how I recruited insiders. Espionage doesn’t start with secrets. It starts with validation. A compliment at the right moment. A shared frustration. Someone who listens when your company doesn’t. That’s not spycraft. That’s just a Tuesday at work. I never asked for sensitive information up front. I asked what was broken. Who made their job harder than it needed to be. What they would fix if anyone actually listened. They thought they were venting. I was mapping access, influence, and motivation. That’s called elicitation. Companies like to believe insider threats come from “bad actors.” They don’t. They come from good employees in very human moments: burnout, loyalty conflict, money stress, bruised ego, identity cracks, resentment that’s been quietly fermenting. And yes, your highest performers were always my favorite targets. They were trusted. They were visible. They had access. And they cared enough to talk. Remote work didn’t invent this. It removed friction. You trained people to network. We trained people to recruit. Same skills. Different intent. If your organization still treats espionage as a cyber problem or a personality flaw, you’re already behind. Because the easiest way into your organization was never through the firewall. It was through someone who finally felt understood. #InsiderThreat #HumanRisk #Espionage #TrustIsASystem #Cybersecurity #Leadership #HR *Photo of me back in the day, post deployment*
Cybersecurity Risks
Explore top LinkedIn content from expert professionals.
-
-
🇷🇺 Russia’s digital soldiers: report on Russia’s Cyber operations, analyzing how they scale through mass mobilisation of “digital soldiers”. By Anastasia Sentsova Analyst1 👉🏼Key learnings : The Russian state has built a militarised civic-information system that blurs the boundaries between state, volunteer and criminal cyber actors. It deliberately cultivates a safe haven for cybercriminals — non-prosecution and even public praise serve as implicit state incentives for aligning cyber-criminal activity with state aims. 🔹State-aligned hacktivist groups or “digital soldiers” combine narrative alignment, symbolic language and targeting patterns that mirror official Russian strategic messaging — offering a high probability of state influence even if direct control is hard to prove. 🔹The information-domain mobilisation is formalised via institutional structures (e.g., civic youth militarisation, volunteer networks) and extended into the digital sphere through gamified cyber-volunteer systems. 🪖Understanding the militarisation of civic life → digital front 🔹Legal and institutional changes (the “Foreign Agents” law, Undesirable Organisations” law) transformed civil society into a component of the militarised domestic order. 🔹The civic movement All‑Russia People’s Front (ONF) illustrates this: launched in 2011 to mobilise local groups, it has digital arms such as “CyberSquad” (in 2023) for volunteer monitoring and reporting “hostile” content. • Example: CyberSquad recruits volunteers, assigns military-style ranks via bot, tasks include complaints against “Russophobic” content, rewards via merch and premium services. 🔹Safe-harbour effect for cybercrime aligned with state goals • The case of the REvil ransomware gang: even after indictment, Russia’s non-cooperation and the embracing of “Putin Team” branding by some criminals signal an informal alignment. • Example: 2 FSB officers indicted for the massive Yahoo breach in 2017 (500 million accounts) prove state-criminal overlap. • Ex: In 2024, convicted hackers were welcomed back to Russia and publicly thanked by the President — a symbolic signal of reward. 🔹Hacktivist groups mirror state narrative and target regime’s adversaries 🔹The Cyber Army of Russia (CARR) demonstrates this alignment: launches with messaging echoing Kremlin language, uses state symbols (“Z” in St George ribbon colours), claims operations against Western/Ukraine-aligned infrastructure. • Ex: CARR claimed responsibility for compromising municipal water storage tanks in Texas (Jan 2024) — an attack crossing from cyber into physical infrastructure damage. 🔹Integrated narrative-cyber-crime apparatus complicates attribution & deterrence
-
Intelligence agencies and the FBI, DOJ and CISA have revealed that unit 29155 of Russia’s GRU—a unit responsible for coup attempts, assassinations, and bombings—is now engaged in brazen hacking operations with targets across the world, including in Ukraine and the US. A broad group of Western government agencies from countries including the US, the UK, Ukraine, Australia, Canada, and five European countries on Thursday revealed that a hacker group that has launched multiple hacking operations targeting Ukraine, the US, and other countries in Europe, Asia, and Latin America is in fact part of the GRU's Unit 29155, the division of the spy agency known for its brazen acts of physical sabotage and politically motivated murder. That unit has been tied in the past, for instance, to the attempted poisoning of GRU defector Sergei Skripal with the Novichok nerve agent in the UK, which led to the death of two bystanders, as well as another assassination plot in Bulgaria, the explosion of an arms depot in the Czech Republic, and a failed coup attempt in Montenegro. Now that infamous section of the GRU appears to have developed its own active team of cyber warfare operators. Since 2022, GRU Unit 29155's more recently recruited hackers have taken the lead on cyber operations, including with the data-destroying wiper malware known as Whispergate, which hit at least two dozen Ukrainian organizations on the eve of Russia's February 2022 invasion, as well as the defacement of Ukrainian government websites and the theft and leak of information from them under a fake “hacktivist” persona known as Free Civilian. "Special forces don’t normally set up a cyber unit that mirrors their physical activities,” one official tells WIRED. “This is a heavily physical operating unit, tasked with the more gruesome acts that the GRU is involved. I find it very surprising that this unit that does very hands-on stuff is now doing cyber things from behind a keyboard.” https://lnkd.in/ehvpRzeJ
-
Three weeks ago, our Devsinc security architect, walked into my office with a chilling demonstration. Using quantum simulation software, she showed how RSA-2048 encryption – the same standard protecting billions of transactions daily – could theoretically be cracked in just 24 hours by a sufficiently powerful quantum computer. What took her classical computer billions of years to attempt, quantum algorithms could solve before tomorrow's sunrise. That moment crystallized a truth I've been grappling with: we're not just approaching a technological evolution; we're racing toward a cryptographic apocalypse. The quantum computing market tells a story of inevitable disruption, surging from $1.44 billion in 2025 to an expected $16.22 billion by 2034 – a staggering 30.88% CAGR that signals more than market enthusiasm. Research shows a 17-34% probability that cryptographically relevant quantum computers will exist by 2034, climbing to 79% by 2044. But here's what keeps me awake at night: adversaries are already employing "harvest now, decrypt later" strategies, collecting our encrypted data today to unlock tomorrow. For my fellow CTOs and CIOs: the U.S. National Security Memorandum 10 mandates full migration to post-quantum cryptography by 2035, with some agencies required to transition by 2030. This isn't optional. Ninety-five percent of cybersecurity experts rate quantum's threat to current systems as "very high," yet only 25% of organizations are actively addressing this in their risk management strategies. To the brilliant minds entering our industry: this represents the greatest cybersecurity challenge and opportunity of our generation. While quantum computing promises revolutionary advances in drug discovery, optimization, and AI, it simultaneously threatens the cryptographic foundation of our digital world. The demand for quantum-safe solutions will create entirely new career paths and industries. What moves me most is the democratizing potential of this challenge. Whether you're building solutions in Silicon Valley or Lahore, the quantum threat affects us all equally – and so does the opportunity to solve it. Post-quantum cryptography isn't just about surviving disruption; it's about architecting the secure digital infrastructure that will power humanity's next chapter. The countdown has begun. The question isn't whether quantum will break our current security – it's whether we'll be ready when it does.
-
Headline: China Cracks RSA Encryption Using Quantum Annealing—Global Data Security Now Under Pressure ⸻ Introduction: A Chinese research team has achieved a milestone with profound cybersecurity implications: successfully cracking a small RSA-encrypted integer using a quantum computer. Though modest in scale, this experiment signals that quantum systems are starting to undermine the very cryptographic foundations that secure today’s banking, commerce, and communication systems. The race to build quantum-resistant encryption is no longer theoretical—it’s urgent. ⸻ Key Details 🔓 Cracking RSA with Quantum Annealing • Researchers: Wang Chao and team from Shanghai University. • Hardware Used: A D-Wave Advantage quantum annealer, built by D-Wave Systems. • Achievement: The team factored a 22-bit RSA semiprime integer, a task previously unsolved on this class of hardware. 🔐 What Makes RSA Strong—and Vulnerable • RSA Encryption: Based on the difficulty of factoring large semiprime numbers (products of two primes). • Classical Challenge: Conventional computers require subexponential time to factor 2048-bit keys—considered secure for now. • Largest Cracked Classically: RSA250 (829-bit key) using supercomputers over weeks. • Quantum Approach: The Chinese team translated factorization into a QUBO (Quadratic Unconstrained Binary Optimization) problem, solvable by quantum annealing. 🧠 Why This is a Warning Shot • Early Stage, But Symbolic: While a 22-bit number is trivial by today’s standards, the methodology proves scalability potential. • First Step Toward Quantum Decryption: Demonstrates quantum annealers can be adapted for cryptographic tasks—not just optimization. • Signals Future Risk: Today’s encryption might withstand current tech, but scalable quantum systems could break RSA entirely in years, not decades. ⸻ Why It Matters • Global Cybersecurity Threatened: Banking, defense, healthcare, and internet infrastructure all rely on RSA and similar public-key systems. This experiment shows those systems may soon be obsolete. • Quantum Arms Race Accelerates: The demonstration by Chinese researchers will likely intensify global investment in both quantum computing and post-quantum cryptography. • Urgent Need for Migration: Governments and corporations must begin transitioning to quantum-resistant encryption standards, or risk catastrophic breaches in the near future. • Tactical and Strategic Implications: Countries that master quantum decryption first may gain unparalleled capabilities in espionage, warfare, and economic control. ⸻ Keith King https://lnkd.in/gHPvUttw Arzan Alghanmi
-
The biggest threat to your data isn’t happening tomorrow. It happened yesterday. If you haven’t heard of HNDL (Harvest Now, Decrypt Later), your long-term data strategy has a massive blind spot. Here is the reality: State actors and cybercriminals are capturing your encrypted data today. They can’t read it yet, so they’re storing it in massive data vaults, waiting for the "Qday"—the moment quantum computers become powerful enough to break current encryption. If your data needs to stay private for 5, 10, or 20 years, it’s already at risk. What’s on the line? ↳ Intellectual Property (IP) and trade secrets. ↳ Government and identity data. ↳ Long-term financial records and contracts. ↳ Sensitive customer health data. How do we solve it? 🛠️ We cannot wait for quantum supremacy to react. The fix starts now: ↳ Inventory: Identify which data has a long shelf-life. ↳ Crypto-Agility: Move toward systems that can swap encryption methods without a total overhaul. ↳ Hybrid PQC: Implement Post-Quantum Cryptography alongside classical methods to ensure traffic captured today remains a mystery tomorrow. The transition to quantum-resistant security is a marathon, not a sprint. Are you tracking HNDL on your current risk register? Let’s discuss in the comments. 👇 P.S. If you want help mapping your exposure or building a PQC migration plan, drop me a message. ♻️ Share this post if it speaks to you, and follow me for more. #QuantumSecurity #PQC
-
Lets Learn #Quantum – Post #16: Post-Quantum Cryptography (PQC) The Invisible Safe: Why Hackers Are Stealing Data They Can't Read Yet The biggest short-term impact of quantum computing isn't what it can create. It is what it can destroy. Right now, our digital world relies on encryption algorithms like RSA to protect banking, emails, and cloud data. Standard supercomputers would take thousands of years to crack them. But quantum computers change the rules. Running Shor’s Algorithm, a quantum computer could break today's encryption in hours. The Threat Happening Right Now Why care today if full-scale quantum computers are still year away? Because cybercriminals are actively executing a strategy known as Harvest Now, Decrypt Later (HNDL). Imagine a thief stealing a locked titanium safe. They cannot open it today, so they hide it in a basement and wait. Years from now, a new tool is invented that pops that safe open instantly. That is HNDL. Bad actors are intercepting and archiving sensitive enterprise data today, waiting for the day a quantum computer can unlock it. If your data needs to remain secret for the next decade, it is already at risk. Enter PQC: Upgrading the Locks Post-Quantum Cryptography (PQC) is the defense. It is a new generation of math shields designed to resist attacks from both conventional and quantum computers. The breakthrough? PQC runs seamlessly on your current servers, smartphones, and cloud platforms. Think of it as swapping out a traditional door lock for a multi-dimensional biometric scanner. The house stays the same; only the lock changes. Instead of traditional math, PQC relies on Lattice-Based Cryptography. Think of it like a maze with thousands of overlapping dimensions instead of two. Even a quantum computer gets completely lost trying to find the exit. The Strategic Reality You cannot swap out the security architecture of a global enterprise overnight. Migrating infrastructure takes years, which is why forward-thinking leaders are already auditing networks and testing PQC algorithms today using a hybrid approach. The quantum threat is not a future IT issue. It is a current strategic risk. The question for leadership is no longer: "When will a quantum computer be built?" The real question is: "Will our data still be secure when it arrives?" #QuantumTechnology #PostQuantumCryptography #PQC #QuantumSecurity #CyberSecurity #QuantumComputing #DigitalTransformation #DataProtection #TechnologyLeadership Co-authored with Atul Tripathi Sundar Ram, Sachin Arora, Himanshu Ghawri, Azizur Rahman, Shivendra singh, Prasun Nandy, Jaydeep Sarkar, Joydeep Roy, Arihant Garg, Amit Kumar, Hetal Shah, Arun Rangaraju, Sayantan Chatterjee, Rajesh Kumar Ojha, Dr. Raghav Manohar Narsalay, Praveen Sasidharan, Sundareshwar K (Sundar), Manu Dwivedi, Venkat Nippani, Himadri Ganguly, Ritesh Jain, Abhijit Chakraborty, Sumit Srivastav, Anit Shanker #soyoucan
-
In many boardrooms, the agenda is expanding faster than the structure and resources can adapt. This week offered another reminder: U.S. Treasury Secretary Scott Bessent summoned major American bank CEOs to a meeting in Washington amid concerns over the cyber risks posed by Anthropic’s latest AI model: Claude Mythos! When risks escalate this quickly, Board overload accelerates and reduces focus on valuable growth topics. 𝗙𝗲𝘄 𝘀𝗶𝗴𝗻𝗮𝗹𝘀 𝗮𝗿𝗲 𝗵𝗮𝗿𝗱 𝘁𝗼 𝗶𝗴𝗻𝗼𝗿𝗲: • Independent director time commitment has risen from 250 to over 300 hours a year the last 5 years • 49% of audit committees report concerns about oversight gaps in cybersecurity and AI • 70% of directors say Board work now takes more time than before Boards do not solve overload by only working longer. They solve it by working smarter, delegating to specialized Committees and upskilling! Here are few suggestions: ✅ 𝗥𝗲𝗮𝗹𝗹𝗼𝗰𝗮𝘁𝗲 𝗼𝘃𝗲𝗿𝘀𝗶𝗴𝗵𝘁 • Create dedicated committees with the right talent • Move cyber, AI and digital out of crowded audit agendas • Review committee charters annually and remove overlaps ✅ 𝗘𝗻𝗵𝗮𝗻𝗰𝗲 𝘁𝗵𝗲 𝗮𝗴𝗲𝗻𝗱𝗮 𝗱𝗲𝘀𝗶𝗴𝗻 • Shift time from backward reporting to forward-looking growth focus • Use consent agendas for routine approvals • Reserve time in every meeting for future risks and strategic shifts ✅ 𝗕𝗿𝗶𝗻𝗴 𝗶𝗻 𝗼𝘂𝘁𝘀𝗶𝗱𝗲 𝗲𝘅𝗽𝗲𝗿𝘁𝗶𝘀𝗲 • Invite external experts twice a year on cybersecurity, AI and geopolitics • Run one annual deep-dive workshop on disruption and fast-moving risks • Use short expert briefings before major decisions (don’t assume Directors understand all Technical dimensions) ✅ 𝗨𝗽𝘀𝗸𝗶𝗹𝗹 𝗕𝗼𝗮𝗿𝗱 𝗰𝗮𝗽𝗮𝗯𝗶𝗹𝗶𝘁𝗶𝗲𝘀 • Run a rigorous annual Board assessment • Map Board skills against future needs and close the gaps • Ensure Directors carry or develop the skills required for the company’s future agenda Strong Boards do not just absorb more pressure. They upskill and redesign how they work. 💡 𝗛𝗼𝘄 𝗶𝘀 𝘆𝗼𝘂𝗿 𝗕𝗼𝗮𝗿𝗱 𝗿𝗲𝗱𝘂𝗰𝗶𝗻𝗴 𝗼𝘃𝗲𝗿𝗹𝗼𝗮𝗱 𝘄𝗵𝗶𝗹𝗲 𝗶𝗺𝗽𝗿𝗼𝘃𝗶𝗻𝗴 𝘁𝗵𝗲 𝗾𝘂𝗮𝗹𝗶𝘁𝘆 𝗼𝗳 𝗼𝘃𝗲𝗿𝘀𝗶𝗴𝗵𝘁? #BoardDirectors #CorporateGovernance #Leadership #Strategy #RiskManagement #AI #BoardEffectiveness
-
⚠️ 𝗕𝗼𝗮𝗿𝗱𝘀 𝗵𝗮𝘃𝗲 𝗯𝗲𝗲𝗻 𝗽𝘂𝘁 𝗼𝗻 𝗻𝗼𝘁𝗶𝗰𝗲. 𝗧𝗵𝗲𝘆 𝗼𝘄𝗻 #AI 𝗮𝗻𝗱 #cybersecurity 𝗿𝗶𝘀𝗸𝘀 - not IT teams. *** I wrote previously on Anthropic's release of its latest AI model, 𝗠𝘆𝘁𝗵𝗼𝘀, a powerful AI cyberhacker, and the dangers it can unleash to critical information infrastructures the world over. In the wrong hands, critical systems can be attacked: • Governments and banks • Hospitals and healthcare infrastructures • Power grids and public services Initially limited to a handful of trusted companies, there are reports that other actors have now gained unauthorised access to it. While the Singapore government does not have access to Mythos, it is working with partners who do to better understand its capabilities and implications. *** ✅ 𝟱 𝗿𝗲𝗰𝗼𝗺𝗺𝗲𝗻𝗱𝗲𝗱 𝗮𝗰𝘁𝗶𝗼𝗻𝘀: 1️⃣ Update cybersecurity risk assessments of IT systems 2️⃣ Maintain full visibility of asset inventory 3️⃣ Shift to continuous monitoring, automated detection and response 4️⃣ Govern AI tools and their use ⭐ 5️⃣ Deploy AI actively as defence *** 🔍 𝗕𝗼𝗮𝗿𝗱𝘀 𝗮𝗿𝗲 𝗮𝗹𝘀𝗼 𝗲𝘅𝗽𝗲𝗰𝘁𝗲𝗱 𝘁𝗼 𝗰𝗼𝗺𝗺𝗶𝘀𝘀𝗶𝗼𝗻 𝗮 𝗿𝗲𝘃𝗶𝗲𝘄 𝗰𝗼𝘃𝗲𝗿𝗶𝗻𝗴: 1️⃣ Are AI-enabled threats in your risk assessments? 2️⃣ Do you have full visibility over critical systems & third-party dependencies? 3️⃣ Is your incident response fast enough? 4️⃣ Is your use of AI tools properly governed? ⭐ 5️⃣ Where can AI strengthen your defences? Where gaps are found, management must remediate and resource accordingly. *** ⭐ As a #lawyer and #board director who has worked at the intersection of #technology, #governance and #risk mitigation for some time now, I see AI, cybersecurity and regulatory risks already converging on boardroom tables. The boards that navigate this well will not necessarily be the ones with the biggest IT budgets. They will be the ones with the right people around the table - directors who understand law, regulation and digital systems well enough to ask the hard questions. #governance #law #tech #AI #board Singapore Institute of Directors Cyber Security Agency of Singapore (CSA) 📸 Link to this The Business Times article below: