For the November edition of Cyber Security Insights we look at emerging threats many see as science fiction but, is in fact, a very real current threat. Then, the question I am asked most often. With Black Friday, Cyber Monday and Christmas shopping all on the horizon do understand the psyche of the fraudster. 3 fascinating articles, we are looking at:

We’ve all heard the buzz: Quantum computing is coming. It’s not just coming it’s already here, and its implications for cybersecurity are real, right now.
If you’re a scaling business, a professional services firm, or a tech-first company holding sensitive data, you don’t have the luxury of waiting for “mainstream quantum.” Because the threat isn’t theoretical it’s operational.
One of the most pressing threats from quantum computing today is the “Harvest Now, Decrypt Later” strategy.
If your sensitive client files, intellectual property, or confidential transactions are being siphoned off now, they could be exposed in the near future without a single alert fired today.
And if you think your industry is not interesting enough for this kind of attack? Think again. State-sponsored groups and well-resourced adversaries play the long game. They’re hoarding data like dragons waiting for their quantum firepower to hatch.
Quantum computing threatens to break widely used public key encryption systems that underpin:
RSA (Rivest, Shamir, and Adleman, the three computer scientists who developed the public-key cryptosystem in 1977), ECC (Elliptic Curve Cryptography), and DH (Diffie-Hellman, a cryptographic protocol for securely exchanging secret keys over a public channel) are all vulnerable. Once quantum machines are powerful enough (and they will be), they could crack these algorithms in hours or even minutes. We’re talking about the collapse of trust across the digital economy.
This isn’t just an issue for cryptographers or governments. It’s a business risk. And smart organisations are already preparing.
Start by knowing what data you hold that’s:
This is the data that’s most at risk from quantum attacks.
2. Demand Post-Quantum Roadmaps from Vendors
Any supplier handling your data — cloud providers, comms platforms, authentication systems — should have a post-quantum transition plan. If they don’t, that’s a red flag.
3. Begin Crypto-Agility Planning
Crypto-agility means designing your systems so you can swap out encryption algorithms without rebuilding the entire infrastructure. This will be essential for transitioning to post-quantum cryptography (PQC).
4. Follow NIST’s PQC Standards
The US National Institute of Standards and Technology (NIST) is finalising new post-quantum cryptographic algorithms.
Federal Information Processing Standard (FIPS) 203 based on the CRYSTALS-Kyber algorithm for general encryption when we access websites.
For digital signatures and identity verification NIST has released 3 PQC algorithms:
Don’t wait for a deadline. Start assessing your crypto dependencies today.
While quantum breaks crypto, AI helps find the cracks. When these two forces combine and they will we’ll face adversaries who are faster, stealthier, and harder to trace than anything we’ve dealt with before.
This is why quantum-readiness can’t be siloed inside IT or the SOC. It must be a board-level issue, backed by proper risk modelling, vendor accountability, and long-term planning.
You don’t need to buy a quantum computer. You don’t need to become a cryptographic engineer.
But you do need to:
Quantum is not a tomorrow problem. It’s a today responsibility.
There’s no drama here. Just facts, urgency and a chance to get ahead.
Because when trust breaks, growth stops.

I have lost count of how many times a business leader has asked me this.
We're only a small company. We’re not a bank. We’re not a big tech company. We don’t even store credit card data. Why would anyone attack us? It’s an honest question. But it’s the wrong one.
Let’s unpack the psyche behind it and more importantly, what it costs you.
Asking “Why would they attack me?” often comes from a few mental shortcuts:
Assumption of obscurity You are not a household name, so you think you are invisible. But in cybersecurity, obscurity is not security.
False equivalence of value You assume attackers are only after money, IP, or trade secrets. You overlook that your email, your systems, your employee data, your supply chain access all have value.
Rational actor bias You believe attackers think like you do. That they would make decisions logically, target big fish only. But many attacks are opportunistic, automated, and indiscriminate.
Overconfidence in ‘low risk’ You have not had an incident before, so you assume you will not in the future. This is classic survivorship bias and it is how small to midsize businesses get blindsided.
Because you are connected Your access to bigger players such as clients, vendors and platforms makes you a perfect backdoor. Think supply chain attack, business email compromise, or credential theft.
Because you are vulnerable Attackers scan for low-hanging fruit. Outdated software, misconfigured firewalls, no MFA – all red flags for threat actors. It's not who you are, it's how exposed you are.
Because you are automatable Most cyber attacks start with automation. Bots do not care if you are an SME or FTSE 100 they look for open doors. Phishing kits, credential stuffing, ransomware all scale beautifully.
Because data is data Data is your business's crown jewels, so data such as employee records, client contracts, email addresses, intellectual property, client personally identifiable data and bank details. It all sells. The dark web does not discount data based on your company size.
Because Disruption is Leverage Ransomware doesn’t need to steal data. It just has to lock you out of it. And the smaller your business, the less tolerance you likely have for downtime which makes you more likely to pay.
When you think you are not a target, you underinvest.
Then the breach happens. Now you are a target. To regulators. To the media. To your customers.
What would happen if we were attacked tomorrow? What could we lose money, trust, reputation, operations, customers if we didn’t see it coming? How long could we survive without our systems? How attractive are we as a route into someone bigger?
These are the strategic questions. The grown-up questions. They’re the questions that keep your business resilient.
Cybercrime isn’t personal. It’s business. Scaled. It runs 24/7, with targets picked by code, not conscience.
If you think you are too small to be noticed, remember: You are not invisible. You are just unprepared.
Security isn’t about fear. It’s about readiness. Let’s get ready.

Fraud is not just a technical issue. It’s a psychological one.
If you want to protect your business, your clients, and your people you have to understand how fraudsters think.
Because they’re not just breaking into systems. They’re breaking into people.
Fraudsters are not just lone basement-dwelling hackers or organised crime syndicates operating offshore (though both exist). They’re adaptive, opportunistic, and, crucially, psychologically skilled.
They understand:
They don’t just look for weak passwords. They look for weak moments.
It could be a busy finance executive skimming emails on a Friday afternoon. A new hire afraid to question a senior colleague. A marketing team under pressure to hit end-of-quarter numbers.
They prey on behavioural patterns, not just technical flaws.
1. They Think Like Social Engineers, Not Coders Many fraudsters use minimal tech. What they do use is charm, manipulation, and well-rehearsed scripts. They rehearse human behaviour like actors preparing for a role.
They mimic:
It’s theatre. High-stakes, high-reward theatre.
2. They Test and Learn Scammers iterate like startups. They test phishing templates. Measure click-through rates. Tweak subject lines. Swap out logos.
If you’ve ever said “Who would fall for that?”, know that version probably worked just fine.
3. They Exploit Our Cognitive Biases They understand human psychology better than most professionals. And they weaponise it. they use common attack vectors, such as:
None of these require malware. Just manipulation.
Fraudsters don’t start with code. They start with reconnaissance.
They will map your company like a blueprint. They often know more about your people than you do.
Common Entry Points:
This isn’t advanced persistent threat (APT) espionage. This is open-source intelligence (OSINT) used with precision.
Then comes the move often subtle. A spoofed email. A cloned login page. A WhatsApp message from “IT”. It doesn’t look like an attack. It looks like business as usual.
Fraudsters don’t care if your firewall is best-in-class. They’ll walk straight through the front door if the receptionist believes they are the cleaner.
Your weakest link isn’t tech. It’s trust. It’s time pressure. It’s poor awareness. It’s assumptions.
That’s why security training must go beyond "don’t click suspicious links". It needs to help people recognise manipulation and feel empowered to challenge authority.
Want to fight fraudsters? Start thinking like them. Then outsmart them.
Fraudsters don’t hack systems. They hack people.
They sell fear, urgency, and false authority. Your defence? Truth, awareness, and confidence.
Don’t just lock the doors. Train your people to spot the con.
Because if we don’t understand how fraudsters think, we’ll keep losing to the stories they tell.
