Cyber Security Insights November 2025

Cyber Security Insights November 2025

Written by Bryan Altimas

For the November edition of Cyber Security Insights we look at emerging threats many see as science fiction but, is in fact, a very real current threat. Then, the question I am asked most often. With Black Friday, Cyber Monday and Christmas shopping all on the horizon do understand the psyche of the fraudster. 3 fascinating articles, we are looking at:

  • Quantum computing and why it is today's threat not tomorrow's science fiction.
  • Why would they attack me? The question I am most asked by business leaders.
  • Inside the mind of a fraudster and how they work.

Quantum Computing: Today’s Cybersecurity Threat, Not Tomorrow’s Sci-Fi

Image

We’ve all heard the buzz: Quantum computing is coming. It’s not just coming it’s already here, and its implications for cybersecurity are real, right now.

If you’re a scaling business, a professional services firm, or a tech-first company holding sensitive data, you don’t have the luxury of waiting for “mainstream quantum.” Because the threat isn’t theoretical it’s operational.

The Current Risk: Store Now, Decrypt Later

One of the most pressing threats from quantum computing today is the “Harvest Now, Decrypt Later” strategy.

  • Attackers are already exfiltrating encrypted data
  • That data might be useless today
  • But once quantum decryption tools mature, it becomes readable

If your sensitive client files, intellectual property, or confidential transactions are being siphoned off now, they could be exposed in the near future without a single alert fired today.

And if you think your industry is not interesting enough for this kind of attack? Think again. State-sponsored groups and well-resourced adversaries play the long game. They’re hoarding data like dragons waiting for their quantum firepower to hatch.

What Quantum Breaks

Quantum computing threatens to break widely used public key encryption systems that underpin:

  • HTTPS
  • VPNs
  • Secure email (PGP)
  • Code signing
  • Digital identity systems
  • Blockchain wallets and smart contracts

RSA (Rivest, Shamir, and Adleman, the three computer scientists who developed the public-key cryptosystem in 1977), ECC (Elliptic Curve Cryptography), and DH (Diffie-Hellman, a cryptographic protocol for securely exchanging secret keys over a public channel) are all vulnerable. Once quantum machines are powerful enough (and they will be), they could crack these algorithms in hours or even minutes. We’re talking about the collapse of trust across the digital economy.

So What Can Be Done Now?

This isn’t just an issue for cryptographers or governments. It’s a business risk. And smart organisations are already preparing.

  1. Classify and Audit Sensitive Data

Start by knowing what data you hold that’s:

  • Encrypted
  • Sensitive
  • Long-lived (i.e., it needs to stay confidential for 5+ years)

This is the data that’s most at risk from quantum attacks.

2. Demand Post-Quantum Roadmaps from Vendors

Any supplier handling your data — cloud providers, comms platforms, authentication systems — should have a post-quantum transition plan. If they don’t, that’s a red flag.

3. Begin Crypto-Agility Planning

Crypto-agility means designing your systems so you can swap out encryption algorithms without rebuilding the entire infrastructure. This will be essential for transitioning to post-quantum cryptography (PQC).

4. Follow NIST’s PQC Standards

The US National Institute of Standards and Technology (NIST) is finalising new post-quantum cryptographic algorithms.

Federal Information Processing Standard (FIPS) 203 based on the CRYSTALS-Kyber algorithm for general encryption when we access websites.

For digital signatures and identity verification NIST has released 3 PQC algorithms:

  • FIPS 204 recommended as the primary algorithm using the CRYSTALS-Dilithium algorithm
  • FIPS 206 recommended for applications requiring a smaller signature than Dilithium can provide using the FALCON logarithm. It uses less than 30kb of RAM.
  • FIPS 205 a larger and slower algorithm than the other 2 but valuable as a backup because it is based on a different maths approach to the other 3 algorithms. It uses the SPHINCS+ logarithm.

Don’t wait for a deadline. Start assessing your crypto dependencies today.

Bonus Insight: AI + Quantum = Threat Multiplier

While quantum breaks crypto, AI helps find the cracks. When these two forces combine and they will we’ll face adversaries who are faster, stealthier, and harder to trace than anything we’ve dealt with before.

This is why quantum-readiness can’t be siloed inside IT or the SOC. It must be a board-level issue, backed by proper risk modelling, vendor accountability, and long-term planning.

Our Message to Scaling Businesses:

You don’t need to buy a quantum computer. You don’t need to become a cryptographic engineer.

But you do need to:

  • Ask better questions about your supply chain
  • Map your data risks
  • Build crypto agility into your roadmap
  • Educate your leadership team
  • Treat quantum as a compliance and continuity issue.

Quantum is not a tomorrow problem. It’s a today responsibility.

There’s no drama here. Just facts, urgency and a chance to get ahead.

Because when trust breaks, growth stops.

Why Would They Attack Me?

Understanding the Dangerous Mindset That Leaves Businesses Exposed

A conceptual, professional illustration about cybersecurity threats to businesses. The image depicts a dimly lit, abstract representation of a business network, with glowing red lines indicating potential vulnerabilities or attack vectors. In the foreground, a silhouette of a business leader is shown looking perplexed, with a thought bubble containing the question "Why would they attack me?". Subtle graphical elements suggest data flow and interconnectedness, emphasizing the concept that even smaller entities can be targets due to their connections. The overall aesthetic is modern, clean, and slightly ominous, using a colour palette of blues, grays, and highlights of red to convey a sense of urgency and underlying risk. The style is vector art with a focus on conceptual representation rather than literal depiction.
Ai generated image depicting attack vectors and vulnerabilities

I have lost count of how many times a business leader has asked me this.

We're only a small company. We’re not a bank. We’re not a big tech company. We don’t even store credit card data. Why would anyone attack us? It’s an honest question. But it’s the wrong one.

Let’s unpack the psyche behind it and more importantly, what it costs you.

The Psychology Behind the Question

Asking “Why would they attack me?” often comes from a few mental shortcuts:

Assumption of obscurity You are not a household name, so you think you are invisible. But in cybersecurity, obscurity is not security.

False equivalence of value You assume attackers are only after money, IP, or trade secrets. You overlook that your email, your systems, your employee data, your supply chain access  all have value.

Rational actor bias You believe attackers think like you do. That they would make decisions logically, target big fish only. But many attacks are opportunistic, automated, and indiscriminate.

Overconfidence in ‘low risk’ You have not had an incident before, so you assume you will not in the future. This is classic survivorship bias and it is how small to midsize businesses get blindsided.

The Real Answer: Why They Would Attack You

Because you are connected Your access to bigger players such as clients, vendors and platforms makes you a perfect backdoor. Think supply chain attack, business email compromise, or credential theft.

Because you are vulnerable Attackers scan for low-hanging fruit. Outdated software, misconfigured firewalls, no MFA – all red flags for threat actors. It's not who you are, it's how exposed you are.

Because you are automatable Most cyber attacks start with automation. Bots do not care if you are an SME or FTSE 100 they look for open doors. Phishing kits, credential stuffing, ransomware all scale beautifully.

Because data is data Data is your business's crown jewels, so data such as employee records, client contracts, email addresses, intellectual property, client personally identifiable data and bank details. It all sells. The dark web does not discount data based on your company size.

Because Disruption is Leverage Ransomware doesn’t need to steal data. It just has to lock you out of it. And the smaller your business, the less tolerance you likely have for downtime which makes you more likely to pay.

The Cost of Underestimating the Threat

When you think you are not a target, you underinvest.

  • You skip proper backups or you trust a vendor with doing your backups
  • You do not test your backups actually restore
  • You delay patching
  • You do not test your incident response (if you have an incident response plan)
  • You do not train your team
  • You do not vet your vendors

Then the breach happens. Now you are a target. To regulators. To the media. To your customers.

So What Should You Be Asking Instead?

What would happen if we were attacked tomorrow? What could we lose money, trust, reputation, operations, customers if we didn’t see it coming? How long could we survive without our systems? How attractive are we as a route into someone bigger?

These are the strategic questions. The grown-up questions. They’re the questions that keep your business resilient.

Final Thought

Cybercrime isn’t personal. It’s business. Scaled. It runs 24/7, with targets picked by code, not conscience.

If you think you are too small to be noticed, remember: You are not invisible. You are just unprepared.

Security isn’t about fear. It’s about readiness. Let’s get ready.

Inside the Mind of a Fraudster: How Scammers Think

Why It Matters to Your Business

A conceptual image of a head with hand on top and scrambled thoughts of fear, urgency, distraction and authority during a fraud attack. The colour palette is greys with white and brown vessels coming from the brain.
AI generated picture of a head and thoughts during a fraud attack

Fraud is not just a technical issue. It’s a psychological one.

If you want to protect your business, your clients, and your people you have to understand how fraudsters think.

Because they’re not just breaking into systems. They’re breaking into people.

Who Are Fraudsters, Really?

Fraudsters are not just lone basement-dwelling hackers or organised crime syndicates operating offshore (though both exist). They’re adaptive, opportunistic, and, crucially, psychologically skilled.

They understand:

  • How trust works
  • How fear manipulates behaviour
  • How distraction, urgency, and authority can override critical thinking

They don’t just look for weak passwords. They look for weak moments.

It could be a busy finance executive skimming emails on a Friday afternoon. A new hire afraid to question a senior colleague. A marketing team under pressure to hit end-of-quarter numbers.

They prey on behavioural patterns, not just technical flaws.

The Fraudster’s Mindset: What Makes Them Tick?

1. They Think Like Social Engineers, Not Coders Many fraudsters use minimal tech. What they do use is charm, manipulation, and well-rehearsed scripts. They rehearse human behaviour like actors preparing for a role.

They mimic:

  • The tone of a CEO
  • The language of a supplier
  • The urgency of a bank security alert

It’s theatre. High-stakes, high-reward theatre.

2. They Test and Learn Scammers iterate like startups. They test phishing templates. Measure click-through rates. Tweak subject lines. Swap out logos.

If you’ve ever said “Who would fall for that?”, know that version probably worked just fine.

3. They Exploit Our Cognitive Biases They understand human psychology better than most professionals. And they weaponise it. they use common attack vectors, such as:

  • Authority bias “This is your CEO. Urgent action required.” Or "This is your bank we have detected fraudulent activity"
  • Scarcity bias – “Limited-time offer. Click now.”
  • Reciprocity – “Here’s a free PDF guide… just enter your details.”
  • Social proof – “500+ companies use our AI audit service.”

None of these require malware. Just manipulation.

How They Find Vulnerabilities

Fraudsters don’t start with code. They start with reconnaissance.

They will map your company like a blueprint. They often know more about your people than you do.

Common Entry Points:

  • LinkedIn: Who’s new? Who got promoted? Who has “payments” or “finance” in their title?
  • Company Websites: Outdated staff lists, unprotected forms, partner details
  • Social Media: Who just posted about going on holiday or attending a conference?
  • Job Ads: What tech stack are you using? Which systems are in place?

This isn’t advanced persistent threat (APT) espionage. This is open-source intelligence (OSINT) used with precision.

Then comes the move often subtle. A spoofed email. A cloned login page. A WhatsApp message from “IT”. It doesn’t look like an attack. It looks like business as usual.

What Does This Mean for Your Business?

Fraudsters don’t care if your firewall is best-in-class. They’ll walk straight through the front door if the receptionist believes they are the cleaner.

Your weakest link isn’t tech. It’s trust. It’s time pressure. It’s poor awareness. It’s assumptions.

That’s why security training must go beyond "don’t click suspicious links". It needs to help people recognise manipulation and feel empowered to challenge authority.

What You Can Do?

Want to fight fraudsters? Start thinking like them. Then outsmart them.

  • Simulate attacks – Use phishing simulations and red-teaming to surface blind spots.
  • Train behaviours, not just policies – Make security part of culture, not compliance.
  • Layer psychological awareness – Teach teams how scams feel, not just how they look.
  • Empower people to pause – Build a culture where it's okay to say “something feels off.”
  • Map your digital footprint – If it’s visible to scammers, it’s vulnerable.
  • Test your trust lines – Check how easily someone could impersonate leadership or partners.

Scammers Are Selling Stories

Fraudsters don’t hack systems. They hack people.

They sell fear, urgency, and false authority. Your defence? Truth, awareness, and confidence.

Don’t just lock the doors. Train your people to spot the con.

Because if we don’t understand how fraudsters think, we’ll keep losing to the stories they tell.


Join the Newsletter
Insights from Riverside Court Consulting Ltd into cyber security, data protection and regulatory compliance
Subscribe Now
Categories
Recent Posts

Cyber Security is serious. But it shouldn't be confusing and stressful

crossmenuarrow-right