Cyber Security Insights May 2026

Cyber Security Insights May 2026

Written by Bryan Altimas

Cybersecurity risk is no longer driven by lack of technology. It is driven by misunderstanding responsibility.

This month’s newsletter focuses on three assumptions that continue to expose organisations.

The belief that certification equals security. The belief that cloud platforms are secure by default. The belief that data in the cloud is automatically protected.

All three are wrong.

Each creates a gap between what organisations think is happening and what is actually in place. That gap is where incidents occur, audits fail, and trust is lost.

The common thread is accountability.

Whether it is controls, configuration, or data protection, responsibility remains with the business.

If that is not clearly understood, risk is being accepted by default rather than managed deliberately.

Cybersecurity Is Not a Badge on Your Website

Many organisations approach cybersecurity accreditation with the wrong objective.

The question is often framed as whether there is a badge that can be displayed following certification to Cyber Essentials, CAF, or ISO 27001. While such badges do exist, focusing on them reflects a misunderstanding of what cybersecurity is intended to achieve.

Cybersecurity should not be viewed as only a marketing asset. It is an operational discipline.

Frameworks and certifications provide structured guidance on how to manage risk. They define controls, processes, and governance expectations. However, their annual review they represent point in time assurance, not an enduring state of security. 

Organisations are not static. Systems evolve, business models change, and new technologies are introduced. At the same time, threat actors continuously adapt their methods. A control environment that was appropriate at the point of certification degrades quickly if it is not actively maintained.

The risk appears when cybersecurity is treated as a finite project.

  • Certification is achieved and the badge displayed on the website
  • Evidence is produced for audit
  • Attention shifts back to commercial priorities

This creates a gap between documented controls and operational reality, which is exactly where audits fail and incidents occur.

Effective cybersecurity requires continuous engagement.

  • Controls must be monitored and tested
  • Risks must be reassessed as the organisation evolves
  • Responsibilities must be clearly defined and owned
  • Leadership must remain accountable for outcomes

Standards such as ISO 27001 and schemes such as Cyber Essentials are valuable when used correctly. They provide a baseline and a common language for risk management. They should shape how an organisation operates, not simply how it demonstrates compliance.

Final Thought

A badge may support commercial credibility. It does not reduce risk. Cybersecurity only delivers value when it is embedded into daily operations, continuously maintained, and owned at a strategic level. Treat accreditation as the end, and you create exposure. Treat it as the starting point, and you build resilience.

Image
An AI-generated image of a network administrator managing secure servers.

Cloud Platforms Are Not Secure Out of the Box

The adoption of cloud platforms has accelerated rapidly across all sectors. Services such as Microsoft 365, Azure, SharePoint, Google Workspace, and AWS are now embedded into core business operations.

With that adoption comes a common and often unchallenged assumption.

If the platform is secure, then the organisation using it must also be secure.

That assumption is wrong.

Cloud providers deliver secure infrastructure, high availability, and a wide range of security capabilities. However, they operate under a shared responsibility model. The provider secures the underlying platform. The customer is responsible for how services are configured, accessed, and managed.

This is where risk is introduced.

Most cloud security incidents are not caused by platform failure. They are caused by misconfiguration and weak governance.

Common issues include:

  • Excessive user permissions and weak identity controls
  • Security features that are available but not enabled
  • Misconfigured storage leading to unintended data exposure
  • Limited monitoring and delayed detection of suspicious activity

The complexity of modern cloud environments amplifies the problem. Services are deployed quickly to support growth, often without clear ownership or baseline configurations.

Third party tools can strengthen visibility and control, particularly in areas such as threat detection, identity and access management, configuration monitoring, and centralised logging.

However, tools do not solve governance failures.

Clear accountability is required.

  • Defined ownership of cloud security
  • Agreed standards for configuration and access
  • Regular validation of controls
  • Ongoing monitoring and response capability

Cloud providers are explicit. Responsibility is shared, not transferred.

Final Thought

Cloud platforms give you the tools to build a secure environment. They do not build it for you. Assume security is included, and you create unmanaged risk. Security in the cloud comes from deliberate configuration, strong governance, and continuous oversight.

Image
An AI-generated image of secure cloud computing.

Your Cloud Data Is Not Automatically Backed Up

As organisations increasingly rely on cloud platforms, a related assumption has become widespread.

If data is stored in Microsoft 365, Google Workspace, or AWS, it is automatically backed up and recoverable.

That assumption is wrong.

Cloud platforms are designed for resilience and availability. They replicate data across infrastructure and protect against hardware failure. This is not the same as having a backup strategy.

The same shared responsibility model applies.

The provider ensures the service runs.

You are responsible for your data.

This becomes critical when something goes wrong.

Data loss rarely comes from infrastructure failure.

  • Accidental deletion by users
  • Overwriting or corruption of files
  • Malicious insider activity
  • Ransomware and other forms of attack
  • Regulatory requirements for historical data access

In many of these scenarios, native recovery options are limited.

Be precise.

  • Retention policies are not backups
  • Recycling bins are not backups
  • Replication is not a backup

A proper backup strategy gives you control through independent, recoverable copies of your data, defined recovery points and timelines, and the ability to restore operations with confidence after both accidental and malicious loss.

Third party backup solutions exist to address this gap. However, their effectiveness depends on alignment with business requirements.

You must define:

  • What data is critical
  • How much loss is acceptable
  • How quickly recovery is required
  • What your regulatory obligations demand

Without that clarity, backup solutions may exist but fail when needed.

Final Thought

Data is a core business asset. Its protection cannot be assumed. Cloud platforms provide availability, not guaranteed recovery. If you do not take ownership of your backup strategy, you will discover the gap during an incident, when recovery options are limited and the impact is immediate.

Image
An AI-generated image of data and privacy.


Join the Newsletter
Insights from Riverside Court Consulting Ltd into cyber security, data protection and regulatory compliance
Subscribe Now
Categories
Recent Posts

Cyber Security is serious. But it shouldn't be confusing and stressful

crossmenuarrow-right