Have we become so used to data breaches that we no longer stop to think about what they actually mean for the people affected?
In this episode of Tech Talks Daily, I speak with Simon Pamplin, CTO at Certes, about why cybercrime remains one of the biggest threats facing businesses and consumers alike. While headlines about ransomware attacks and data breaches appear almost every day, Simon argues that too many organizations are still treating cybersecurity as a technology problem rather than a business risk with real human consequences.
Our conversation begins with a simple but powerful question. Why are so many companies still focused on protecting networks when attackers are really after the data itself? Simon explains why traditional perimeter-based security approaches are struggling in a world where information moves between cloud environments, devices, applications, and partners far beyond the boundaries organizations once controlled.

We also discuss the personal cost of cybercrime. Behind every breach announcement are real people whose financial records, personal details, healthcare information, and digital identities may have been exposed. Simon shares why the impact often extends far beyond resetting a password, creating financial, emotional, and reputational consequences that can last for years.
Another major theme is the growing concern about quantum computing and the rise of harvest-and-decrypt attacks. While fully realized quantum computing may still be in the future, cybercriminals are already collecting encrypted data with the expectation that future technology will eventually unlock it. Simon explains why businesses need to think about protecting sensitive information today rather than waiting for tomorrow's threats to become reality.
The conversation also examines the growing pressure from regulations such as GDPR, DORA, and NIS2. With larger penalties and increased regulatory scrutiny, organizations are facing greater accountability for how they handle and protect customer information. Simon argues that trust has become one of the most valuable assets a business can possess and one of the easiest to lose.
Of course, no cybersecurity discussion would be complete without addressing AI. We explore how AI is making attacks faster, cheaper, and more accessible while also creating opportunities for defenders. Simon shares his thoughts on why businesses must rethink long-held assumptions and prepare for a future in which cybercriminals can automate many techniques that once required significant expertise.
Throughout our discussion, Simon returns to a consistent message. Attackers target data because it has value. Organizations that focus their efforts on protecting that data, wherever it travels, will be in a far stronger position than those relying solely on traditional defenses.
If you are responsible for cybersecurity, risk management, compliance, or digital transformation, this episode offers a timely discussion of what businesses should prioritize as threats continue to evolve. Customer trust becomes harder to earn and easier to lose.
When the next breach makes headlines, will it simply be another news story, or a reminder that every piece of stolen data belongs to a real person whose life could be affected?
Useful Links
Connect with Simon Pamplin
Please check the partners of the Tech Tech Talks Network
Learn more about the NordLayer Browser

[00:00:00] - [Speaker 0]
As someone that records 65 plus interviews a month, I've personally seen a huge increase in browser based attacks over the past year, whether that be phishing, malicious extensions, account takeovers. The list is long, And it's all happening where people spend most of their time inside the browser. So NordLayer's new business browser, that's built to address exactly that. It blocks malicious sites before they load. It limits risky behaviors like uncontrolled downloads or data sharing and gives you visibility into how your team interacts with web apps.
[00:00:36] - [Speaker 0]
And it also helps you stay compliant by controlling access and enforcing policies without the need to rely on multiple disconnected tools. So for anyone listening that is thinking seriously about reducing risk in SaaS heavy environments, this feels like a smarter and more focused approach. And you can learn more about it by visiting nordlair.com/browser. Let me know what you think. But now, let me introduce you to today's guest.
[00:01:06] - [Speaker 0]
What if the real target of most cyber attacks out there is not the network but the data that moves through it? Well, today on Tech Talks Daily, I'm joined by Simon Pamplin, CTO at Certus. We're gonna discuss why cybersecurity leaders might need to rethink how they protect their organization in an era of AI powered attacks, quantum risk, insider threats, and increasingly personalized cybercrime. And my guest will argue today that many companies are still built around perimeter based security even though data now moves across clouds, devices, partners, remote teams, and systems that those traditional controls were never designed to fully protect. I will talk about why breaches have become so normalized now, and we almost become desensitized to them, and why the real world impact on consumers is often underestimated.
[00:02:03] - [Speaker 0]
And I also wanna touch on why Harvest Now, Decrypt Later should be taken seriously long before quantum computing becomes widely available. And if we've got time, we'll also discuss post quantum cryptography, data centric security, the regulatory pressure that comes with it, and AI enabled cybercrime. And why making stolen data useless could become one of the most important shifts in modern cybersecurity. But enough from me. Let me introduce you to my guest now.
[00:02:37] - [Speaker 0]
So a massive warm welcome to the show. Pleasure to have you join me today. For everyone listening, can you tell them a little about who you are and what you do?
[00:02:45] - [Speaker 1]
Yeah. So, Neil, good to meet you as well. So I'm Simon Pamplin. I'm the chief technology officer at CertiZ. We're one of the leading post quantum cryptography data centric security companies.
[00:02:57] - [Speaker 1]
Been established for many, many years, really focused on protecting the subject of pretty much every network breach, which is data.
[00:03:06] - [Speaker 0]
It's a pleasure to have you join me. I've had a few people on from the company over the years. And when I was doing a little research on you, one of the things that I read that was that you've argued that many organizations are still focusing on protecting networks instead of protecting the data itself. And that that is incredible, especially at a time where every tech conference I go to, they say no no data, no AI. So why do you think the industry has struggled to make that shift despite so many years of high profile breaches that we we've all seen when doom scrolling down our phones?
[00:03:39] - [Speaker 1]
Yeah. I don't think it's natural, really. I mean, let's face it. We all come from well, certainly, have a background of data and storage networking, traditional firewalls, routers, you know, traditional ways of protecting perimeters and identity. That was ingrained into us for years because we've always assumed that if you protect the perimeter, you protect what's on the inside of the perimeter.
[00:04:01] - [Speaker 0]
Yeah.
[00:04:01] - [Speaker 1]
Unfortunately, the world has changed, and data no longer lives just on prem in your data centers. It it goes everywhere. Places that you can control and places that you can't control. More likely places you can't control. And as we've seen with breaches that we've seen recently with Jaguar Land Rover, Marks and Spencer's, Harrods, Co op, just to name a few of the the enterprise customers and retail customers, their identity systems were breached by a simple phone call, by someone doing a phishing exercise.
[00:04:30] - [Speaker 1]
So the perimeter is being breached constantly, and we have to get out of that mentality that if we build a big enough wall, what's on the inside of the wall is gonna be safe because that wall is it's letting people in constantly. It is just, unfortunately, one of those things. There's too many clever people out there finding too many vulnerabilities too often. So when I joined Surtees, I kind of had a bit of an epiphany, which was that there's only really two reasons to break into a network. One, to be disruptive, and that's not very often.
[00:05:00] - [Speaker 1]
That that's the disgruntled employee. That's somebody who's got a grudge. Doesn't happen that often. And the other one is to make money, financially gain, from what you can steal from that company. And the thing that people steal, the thing that people realize has a value pretty much across the board is data.
[00:05:18] - [Speaker 1]
So if you would make the assumption that your perimeter and your identity is gonna fail, and sorry to say it for all of the hard diehard network people out there, look at the number of CVEs that are recorded on a daily basis by the top industry security infrastructure vendors, backs my point up, they are gonna get in. And if they get in, they will do the classic kill chain. They'll escalate privileges. They'll lock everybody out. They'll steal the data, exfiltrate it to the Internet, and likely corrupt what you're left with.
[00:05:50] - [Speaker 1]
So does it not make more sense to wrap the security around the data than the infrastructure? So that wherever that data goes, either intentionally by you, the data owner, or unintentionally where it's stolen, the security travels with the data. And if you can make that data secure in such a way that only you, the data owner, can access it, you've got sovereignty built into that data as well. And it means that, yes, they're gonna break in. Yes, they're going to compromise some of your devices.
[00:06:19] - [Speaker 1]
And, yes, they're going to steal some of the data. But what they get has no value to them. They can't do nothing with it. So the whole concept of breaking into the network is pointless. One of the analogies we've we've used quite a lot is what the the banking industry did when they're you remember all the security vans were transferring cash boxes between branches?
[00:06:40] - [Speaker 1]
They were the easiest thing to to steal for the robbers because they didn't have to worry about alarm systems and banks and vaults. They just had to steal a transit van. That was the easiest thing. So the banking industry decided the way around that was in these cash boxes to put a paint bomb, and that paint bomb will go off if an unauthorized person tries to open the box and steal the money, rendering that money useless and valueless. Almost overnight, the banking industry stopped having their transport cars stolen because the robbers realized there's no point.
[00:07:13] - [Speaker 1]
I can't use what I've stolen, so it's valueless. What Certis does is exactly the same thing, but for data. We render it valueless. Anyone that steals it that shouldn't have access to it. It's a really simple concept, but it's one that we've been shipping for, believe it or not, that twenty years.
[00:07:31] - [Speaker 0]
And there are so many newer threats now as well. One of the things I keep reading about is the looming prospect of quantum computing powered AI decryption that bring into life this notion of that many thieves out there or cyber attackers are harvesting now with the thought of decrypting later. Is this something you're you're hearing and seeing as well?
[00:07:50] - [Speaker 1]
Yeah. It's becoming a bigger problem, and and I I guess people don't think about it at the level they should do Yeah. Because until it happens to them, it's just another story in an email that pops into their inbox every morning that this company's been breached or that company. But there's there's some great real, not anecdotal evidence that this can really impact a business. It's a business risk.
[00:08:14] - [Speaker 1]
This isn't a security thing per se. This is a business risk that businesses need to take seriously. There's a classic example. There was a, I think it was a Finnish, psychotherapy company called Vostama, and it's it's a well documented example where the CEO thought that data security was an IT problem. You know?
[00:08:32] - [Speaker 1]
Just go down to IT. Let them deal with it. They they deal with security. They had a breach. They had very sensitive client information that got stolen.
[00:08:40] - [Speaker 1]
The CEO was given a three month suspended jail sentence and fired because he was negligent in carrying out his job of protecting the crown jewels of that company, which was sensitive data. The stock price of that business plummeted as a result, and they were acquired by their nearest competitor. They no longer exist. Wow. In that scenario, a data breach resulted in a criminal prosecution, fines, reputational damage, and ultimately, the collapse of that business.
[00:09:08] - [Speaker 1]
So when you start thinking about it in more detail, it's a real and present danger today. Forget quantum because quantum's coming. Yeah. You know, when it's coming is up for debate. I think it's a lot sooner than a lot of people because I'm starting to see that, and industry giants like Google are starting to agree with this.
[00:09:26] - [Speaker 1]
But there's a real and present danger at the moment, and it is under the term of harvest now, decrypt later, because people are stealing data protected with today's encryption. And today's encryption will be rendered completely useless when the advent of generally available quantum computing, occurs. What we're doing at SerTes is we're taking the NIST approved quantum algorithms, and we're wrapping that around the data. So in the same way as I just said, if someone steals data that's protected by SerTes, not only do they get something that's valueless, they now get something that's wrapped in a quantum algorithm with an encryption key that's changed every sixty minutes. So they've got sixty minutes to crack this, so it has no value to them.
[00:10:04] - [Speaker 1]
They they can't do anything with it. Ironically, what they should do is go and break into the company next door that hasn't yet bought Certi's because they don't have that capability. It's a sad fact to life, but, you know, we are protecting our customers' data. We're open to talking to other customers.
[00:10:20] - [Speaker 0]
Wow. There'll be so many leaders listening around the world shuffling uncomfortably listening to that example there. And you also wrote a brilliant article, Will. What I loved about it is you painted a very human picture of cybercrime from ruined credit scores to identity theft, emotional stress, etcetera. Do you think businesses or many businesses still underestimate that that real world impact that breaches can have on ordinary everyday people?
[00:10:46] - [Speaker 1]
I I think you've only got to look if you look at business impact, you've only got to look at things like Jaguar Land Rover Yeah. Shutting down the manufacturing of of an automobile industry and all its supply chain for months, and costing hundreds of millions. Same thing with Marks and Spencer's. But it's the reputational impact, let alone so they get back up and running, and yes, they've had lack of trading weeks because their systems have been down, but it's the reputational impact. If you're a retailer like Marks and Spencer's, if your customers decide to vote with their feet and go and walk to your nearest competitor, that's very hard to get that trust back.
[00:11:25] - [Speaker 1]
And if they think you can't protect their credit card information, their delivery information, their their track history of what they bought from you, well, you've got a question. Why are they gonna stay with you and they can go to a another retailer and do the same thing? So I think until something personal happens to people, they tend to not think about it too much. Yeah. The other thing we say, Nick, is if you lost your phone in the street, I mean, it's a bit of a pain that you've lost that expensive piece of hardware, but you can replace it.
[00:11:55] - [Speaker 1]
It's the content that's on that phone that is the real pain to you. It's your banking information that's on there, because we all rely on these things. You've given up all your banking cards. You've given up all of your personal information on there, your access to your your cloud providers and and services that you use. So it all comes down to data.
[00:12:14] - [Speaker 1]
You can protect the data. The physical aspects of it, the infrastructure means less. It doesn't mean nothing. It means less than we've thought about it in the past. You really need both.
[00:12:24] - [Speaker 1]
I mean, we all know that security is a a many layered thing. It's the classic onion of of of services. You can't replace everything with a silver bullet, but you do need to focus on what is the problem today. And the problem today is not infrastructure. The problem today is data and the availability that people have access to it and what they can do with it.
[00:12:46] - [Speaker 0]
And one of the most striking lines in your piece is that the I think you said the next breach won't feel like a big deal until it is. So I've got to ask that. Have we become too numb to breach notifications and cybersecurity headlines that that seem to be coming up on an almost daily basis? Are always, to a certain extent, numb to them now?
[00:13:05] - [Speaker 1]
I I think we are. I think we see so many of these things. It becomes commonplace. Guardian, another business has has been breached. I I like you, I must see probably twenty, thirty, 40 of these emails a day.
[00:13:16] - [Speaker 1]
They're dedicated websites, so all they do is report on these, and they have new content every single day. The scary thing is the industries that it's filtering into. I'm starting to see a lot more health care that's being broken into. People go, why would that be important? Well, if you look at health care, say, in North America, you've got seriously sensitive personal information that can impact people's livelihoods, their job activities, their ability to get loans and financing due to their health records.
[00:13:46] - [Speaker 1]
But also, you think about the connected systems that people have out there and across the world, really. You've got MRI scanners that are taking very sensitive information and sending it unencrypted over a network. Those those MRI scanners are now being challenged to be PQC and quantum safe. What option have you got? Go and buy another $5,000,000 MRI scanner or put a solution in front of it that protects that data anyway in flight?
[00:14:15] - [Speaker 1]
And that's really one of the benefits that Certis is bringing. Do this without doing a rip and replace. We don't need to go and replace all of your infrastructure and your identity. We're not working at that level. We're working on the data.
[00:14:27] - [Speaker 1]
All we're interested in is looking at that data flow, and then we can protect it. Get us as close to the source and destination of that data as possible, and then wherever that data goes, you and you alone can access it, and everybody else gets nothing of value. So it the different industry is quite concerning. I mean, we we all know that banks are a big target, and we know that, they've been a target for a long, long time. They have very, very good security systems.
[00:14:52] - [Speaker 1]
But, again, they are probably the leaders in thinking about data security, but even they are only just starting to implement it fully.
[00:15:00] - [Speaker 0]
So a special thank you to Denodo for supporting the Tech Talks Network and helping us keep these conversations going because moving beyond AI pilots all starts with connecting your models to trusted enterprise data. So if you're ready to move beyond AI pilots, Denodo can help you connect your AI models to trusted enterprise data in real time. So you can scale faster and reduce risk. So if you're interested in turning AI into business value, simply visit denodo.com. And you also mentioned that perimeter based security models are struggling in today's threat environment earlier in our conversation.
[00:15:44] - [Speaker 0]
Is that because also because of the the rise in insider threats becoming more common? I've seen so many reports of I think there was a BBC reporter who was recently, and they were offered a king's ransom for his login, for example. Are all these things becoming more common?
[00:15:59] - [Speaker 1]
I think they are. I the the internal bad actor, whatever you want to refer to them, is is is quite rare. I mean, this disgruntled employee it's usually through a phishing exercise that they'll get credentials to bypass the perimeter. But it's that that mentality as we talked about earlier, that the perimeter is defense area, and everything on the inside of the perimeter is safe. I mean, I've had security engineers telling me that they don't protect the land side because they've got such a strong perimeter and identity.
[00:16:30] - [Speaker 1]
You sit there going, you're just waiting to be breached. It's gonna happen to you. That's a mentality change that we really need to work on because that is just scary. Now, the difference between the network engineer mentality and a data centric viewpoint is the network engineer is always playing defense. They're always looking at what's threat analysis?
[00:16:57] - [Speaker 1]
What has happened to someone else? What is the information that's out there that I can then go and patch to protect against? Now the challenge with that mentality is that something has already had to have happened for you to be able to build a patch to protect against it. So there's already been a breach in that method. Now for a network engineer, I like to say that that's a bad day at the office.
[00:17:18] - [Speaker 1]
Someone's broken in. You've it, hopefully. You've asked the the vendor for a patch. You waited for them to provide a patch. You've deployed it on your, you know, Tuesday patch day, and hopefully it won't happen again.
[00:17:31] - [Speaker 1]
But you're always playing catch up. And I think what we've seen with things like Mythos coming out recently is that Mythos is now taking existing vulnerabilities and CVEs, concatenating them together to come up with a whole new method of attacking. It's using known individual methods, but not as one new attack vector. So the network engineer mentality is never going to be ahead of the game. They're always going be playing catch up, which arguably is okay in a security, network security environment, because that's what we've done for twenty odd years.
[00:18:03] - [Speaker 1]
If you flip it on its head and you look at the data side of things, and you look at what happens to a business when data is exposed, Forget what I talked about before, reputational impact, finance, etcetera. You've got regulations. You've got compliance that you have to fit in with GDPR, DORA, NIST too. All of those regulations rely on one piece of data being exposed for them to kick in. So you could have 4% of your global group revenue as a fine just for the first breach.
[00:18:34] - [Speaker 1]
That could be enough to bring that business down. Around the world, those percentages are wildly different. I think the the Australian Privacy Act is the biggest one at the moment at 30% of global group revenue per breach. That really could destroy a business. So it's not okay to play catch up in the data centric viewpoint.
[00:18:53] - [Speaker 1]
In the data centric, to use my American colleagues terms, you've got to go on the offensive. Not be offensive. Go on the offensive. So when you go on the offensive, you assume you're gonna be breached. So you make sure that you protect the subject of that breach or the target of that attack first, so when the inevitable happens and you are breached, again, they get nothing of value.
[00:19:16] - [Speaker 1]
All of their efforts have been completely wasted. The business is protected because you and you alone have access to that data. It it all comes back to data, and I'll keep saying it like a stuck record, but data is the target of attacks. Data is what businesses run on. Data is what they should be focused on protecting, as well as the other things.
[00:19:35] - [Speaker 1]
But up until the last probably five years, people have assumed infrastructure will solve the problem. It won't. Unfortunately, in the way that today works and the way that data has a value like never before, data needs to be protected as well.
[00:19:51] - [Speaker 0]
I'm glad you, talked about regulations there like GDPR, NIST two, DORA. There's so many now, and they're all in increasing pressure on organizations to act more responsibly and be more proactive when it comes to security. But I'm I'm curious from what you're seeing and hearing and all the conversations you're having, are fines and compliance requirements really changing behavior, or or are many companies still treating it as a almost a cybersecurity box ticking exercise?
[00:20:20] - [Speaker 1]
I think it used to. I mean, I think compliance and regulations used to be such small fine. It was almost a slap on the wrist. It was a case of, yeah, I can, yeah, I I can absorb that fine as the cost of doing business. It's cheaper to pay the fine than it is to implement a whole new set of systems.
[00:20:35] - [Speaker 1]
But I think with the advent of the value of data increasing, things like GDPR and DORA and NIST two and all the other ones have increased their percentages. You look at the largest single fine was against Meta of 1,300,000,000, and that wasn't even a breach. That was the movement of EU citizen data from the well, from Ireland, in this case, to North America in a form that could be intercepted by North American Secret Service, ironically, was what they were complaining about. Mhmm. That 1,300,000,000 was 4% of global group revenue of Metagroup.
[00:21:13] - [Speaker 1]
So that's an eye wateringly large sum of money that before had never been seen. That really gets people's attention and that's something we're seeing around the world. There are still some regulations that are probably small enough percentages that people give them not lip service, but again, it's a tick box exercise in some cases. But I think the advent of DORA, advent of increase on GDPR, like I said, the Australian Privacy Act, all of the personal identity information that you have around The Middle East, that is becoming a really hot topic. In fact, in certain regions of the world, that's become more of a hot topic than traditional security, because they recognize that personal identifying information has an ongoing value rather than just breaking into a network.
[00:22:01] - [Speaker 1]
So, yeah, we are starting to see that. And I think the industry is kind of coming round to the way that we've been thinking for a long time, because we're seeing that people are focusing more and more on post quantum cryptography because they recognize that what they thought they were using to protect their data in the past is just gonna be completely useless in a couple of years' time. So they have to think about it differently, and that that's really what we're starting to see. We get called into more and more customers purely to talk about how can we help them, and largely, it's around how can we help them with their legacy systems because they're either terrified that they can't update those systems or they don't know how to. Most of are on traditional mainframes.
[00:22:40] - [Speaker 1]
Again, banking industry runs all of their systems on what we would class as legacy systems. They're worried about multi cloud because all of our cloud vendors have different security models. How do you get a single consistent security policy across all of them? And they're worried about how do I get the same level of security but right out to the edge, to my end users, to my execs who are running around with laptops with corporate information on them. It's no longer good enough, and it hasn't been for a long time, to rely on things like a VPN.
[00:23:09] - [Speaker 1]
That just doesn't cut it anymore. We know that VPNs are good for what they used to do, but they're not sufficient to protect the data that flies over it, because they're an infrastructure solution. They protect the connection. They don't protect the data. Once it it leaves that connection at the other end, it's unprotected, but the end user or the data owner is still legally responsible for that data no matter where it goes.
[00:23:33] - [Speaker 1]
That's a concept that people are only just starting to get their heads around.
[00:23:36] - [Speaker 0]
And we are twenty minutes into a tech podcast without mentioning AI, so we better change that. And AI is, though, rapidly changing the cybersecurity, threat landscape. And whether it be automated phishing, deep fake scans. They've got agents involved now as well. And I'm curious.
[00:23:55] - [Speaker 0]
When it comes to keeping you awake at night, how concerned are you that cybercrime is becoming more personalized, scalable, and and even harder for everyday consumers to spot?
[00:24:05] - [Speaker 1]
I think if we were still doing the the traditional defensive type approach, I'd be terrified because Yeah. Mythos is a great example. You've got an AI tool that can go and scan every known vulnerability from your dot and come up with a whole new attack based on picking or cherry picking from each of those those vulnerabilities. That that there is no way that a security vendor can keep up to date patching all of those combinations. There's just gonna be too many of them.
[00:24:33] - [Speaker 1]
And people are doing you know, we've had ransomware as a service for a long time. We're we're now having breaches as a service. We've got organizations that have made these AI bots open as a service to go and attack whoever you want to attack. It's a pay per pay to play environment, which is, again, quite terrifying. But because you're always gonna be catching up on the defensive, you're never going to win.
[00:24:56] - [Speaker 1]
These things can do the same attacks, but a lot faster and a lot more of them. So you need to flip it around on its head and go on the offensive. Do something different. Think differently. Don't think in the way that people have traditionally done security.
[00:25:10] - [Speaker 1]
You have to think outside the box and change your approach. Otherwise, you're just going to be the next victim. For us, AI and large language models is just another form of data. What we have to do is try and make sure that data flows to where you want it to flow and not elsewhere. So you really want to be able to control your corporate information going to your local language model that you're running as an internal AI solution and not out to a general purpose public AI model.
[00:25:39] - [Speaker 1]
And that's, again, something you can do if you can control that data flow.
[00:25:43] - [Speaker 0]
And finally, as we look ahead into the future, what what do you think will separate those organizations that will earn customer trust in this AI era from those that could face lasting reputational damage after the next inevitable breach? It's not a case of if, but when in many cases. But what do you think will separate those organizations looking forward?
[00:26:04] - [Speaker 1]
Yeah. I'm starting to see two distinct groups of people. There's the group of people who've decided to go down a more traditional path of doing an assessment on their cryptography, looking at every application they have, looking at every piece of infrastructure, identifying where the vulnerability will be when quantum finally arrives, and then making a two or three year plan to go through and upgrade these systems. Whilst that's a laudable thing to do, they're missing the point. Quantum is one problem.
[00:26:34] - [Speaker 1]
Stealing of data is a today problem. So they need to do something now that protects the data that's being stolen to monetize when quantum is generally available. But if you think about the people going through these assessments, when they finish the assessment and they've actually done the upgrades, there'll be new algorithms out. So they're gonna have to start again. It's like painting the fourth bridge.
[00:26:54] - [Speaker 1]
It will never ever end. It will be a continuous process. And while they're doing an assessment, they're vulnerable. So is their customer data. So it has to be a blended approach.
[00:27:04] - [Speaker 1]
They need to put something in in place today. And again, you know, blatant plug. Certi's can do that for them today, whilst they go through their assessment, because it's a perfectly valid thing to do to go and upgrade to the latest quantum safe versions of your algorithms and infrastructure. 100% you need to do that. But you cannot allow your data to sit there and be vulnerable for a couple of years while you go and have a look at where all your cryptography is.
[00:27:31] - [Speaker 1]
The different groups is as easy as that. There's the ones who are trying to put this off because they don't really know how to fix the problem, so they're gonna go through an assessment process. And there's the ones who are out there going, there are solutions that can help me today. I need to do something today, and I can worry about the upgrade in my own time. So that's the split that we're seeing between the two groups.
[00:27:52] - [Speaker 1]
And the ones that do the fixing the problem today are gonna be the ones that succeed because they can generally say to their customer base, we have your data under control. We have it protected. Your data is safe. That's a big big plus in my mind. If I was working with an organization, I I choose that one over one that said, yeah.
[00:28:13] - [Speaker 1]
In a couple of years' time, we might have something in place.
[00:28:16] - [Speaker 0]
And I think that is a thought provoking moment to end on. So much to take away there. And for people listening that would like to continue this conversation, maybe we've set off a few light bulb moments today in this this chat. Where would where would you like me to point everyone listening to connect with you, your team, find out more information about everything that you're doing? Where would you like me to, what links would you like me to post, sir?
[00:28:38] - [Speaker 1]
Yeah. So if they go to our website at certes.ai, there's a whole resource section on there of white papers, case studies that we because we've with pretty much every vertical there is, from critical national infrastructure through to banking and governance and public sector. You name it, we've got case studies that will cover that. If they want to connect with me directly on LinkedIn, happy to have an offline conversation with anybody about this. But there's plenty of information on our website to take you through it.
[00:29:09] - [Speaker 1]
And if they wanna take it further, we'd love to have a chat with them.
[00:29:12] - [Speaker 0]
Awesome. Well, I will include links to everything you mentioned. I'll also include a link to that article, cybercrime is coming for you and no one's stopping it. We talked about a lot of it today. We all think it's not gonna happen to us whether we're in the office or as a consumer, then we find ourselves going on that almost change curve of why is this still happening.
[00:29:31] - [Speaker 0]
But I think understanding why businesses should care, why as consumers we should care, and understand what needs to change and how to change, These are all critical for every single person listening today. So I urge people to if they're interested in carrying on this conversation, please check those links out. Feedback to me. What are you doing? What's working?
[00:29:50] - [Speaker 0]
What isn't? But more than anything, Simon, just thank you for starting this conversation today. Really appreciate your time. Thank you.
[00:29:57] - [Speaker 1]
It's been a pleasure. Thanks.
[00:29:59] - [Speaker 0]
So a big thank you to my guest for joining me today and sharing such a direct and practical view of where cybersecurity needs to go next. What really stood out to me today was this simple idea that attackers are usually chasing the same thing, data. And if that data remains valuable once it leaves your environment, then the breach has already achieved its purpose. That's why Simon's argument around data centric security feels so timely right now. Firewalls, identity controls, and network defenses, all these things still matter.
[00:30:35] - [Speaker 0]
But organizations also need to think about what happens after attackers get in. And for me, this conversation serve as a timely reminder that cybercrime is deeply personal. Behind every breach notification are people dealing with fraud, identity identity theft, financial stress, and a loss of trust in companies that they always just took for granted would protect them. So if you'd like to learn more about anything we talked about today, I'll include the links in the show notes over at techtalksnetwork.com. And as always, I'm always open to hearing your thoughts.
[00:31:14] - [Speaker 0]
Are you and your organization doing enough to protect the data itself, or are you still hoping the perimeter will hold? Let me know. Time for me to go now. I'll speak to you all again bright and early tomorrow, but thanks for listening today. Bye for now.

