Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Data Protection - Making stolen data worthless: why security must start with the data
Data Protection Articles Attacks Encryption Security

Making stolen data worthless: why security must start with the data

Simon PamplinBy Simon PamplinMarch 30, 20265 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Making stolen data worthless
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Organisations have spent years investing heavily in cybersecurity solutions. Firewalls have been strengthened, identity systems refined, and monitoring tools deployed across increasingly complex environments. Yet despite this, data breaches continue to expose vast amounts of sensitive information, often with severe financial, operational, and reputational consequences.

The uncomfortable truth is that the industry has long been solving the wrong problem. Most security strategies are still built around protecting infrastructure such as networks, endpoints, and user access. But attackers are no longer trying to break through these controls in the traditional sense. Instead, they exploit stolen credentials, social engineering, and compromised third parties to gain legitimate access. Once inside, they go straight to the data.

And too often, that data is still readable.

This is why organisations continue to suffer the same outcome, even after investing in more tools. The perimeter may hold, authentication may work as designed, and yet the data is still lost. The problem is not that defences are failing. It is that the data itself is not being properly protected.

At the same time, a new and more complex challenge is emerging. Enterprises know that the cryptography they rely on today will not withstand the impact of quantum computing. They also understand that data stolen today can be stored and decrypted later as quantum capabilities mature – a “harvest now, decrypt later” model that quietly increases long‑term risk. However, most have no practical way to transition at the required speed and scale. Cryptography is deeply embedded within applications, spread across business units, and often owned by no one. The result is paralysis. Organisations face years of discovery, redesign, and migration projects that are likely to be outdated before they are even completed.

Boards are already asking whether they are quantum‑ready. CISOs are often forced to respond with roadmaps rather than outcomes, not because they lack awareness, but because they lack a simple and effective way to act.

This is where a fundamental shift in approach is needed.

Rather than continuing to focus on defending infrastructure, organisations need to focus on protecting the data itself. This means applying strong encryption directly to data in motion between systems, enforcing strict customer control over encryption keys, and ensuring that sensitive information remains protected at all times, regardless of where it resides, where it travels, or how it is accessed.

This approach changes the nature of a breach entirely.

Consider a typical ransomware attack. The attacker gains access, moves laterally within the environment, and eventually exfiltrates data before encrypting systems and demanding payment. The leverage comes from the value of that stolen data. If it can be read, sold or leaked, the organisation is under pressure to respond.

Now imagine the same scenario, but with the data itself persistently protected. Even if attackers gain access and extract information, what they obtain is unusable. It cannot be read, analysed or monetised. The incentive behind the attack disappears.

This is the essence of a data‑centric security model. It accepts that breaches will happen and focuses on limiting their impact. Instead of trying to prevent every possible intrusion, which is increasingly unrealistic, it ensures that when an attacker does get in, they gain nothing of value.

The implications are significant. Financial losses are reduced, operational disruption is contained, and regulatory exposure is minimised. Perhaps most importantly, organisations regain control over their data, even in compromised environments.

This approach also provides a practical path forward for addressing the quantum challenge. Rather than attempting to replace cryptography inside every application and system, protection can be applied around the data itself. This allows organisations to introduce quantum‑safe, crypto‑agile security as an overlay – with no application changes and no infrastructure rip‑and‑replace.

What organisations need is quantum‑safe protection for any application, across any infrastructure, anywhere, delivered in a way that is both practical and scalable. That means solutions that can be deployed quickly, operate independently of underlying systems, and adapt as threats evolve. It also means simplifying what has historically been a complex and fragmented problem, enabling security teams to enforce consistent protection without introducing operational friction.

Crucially, this approach supports both compliance and resilience. Regulators are increasingly focused on how organisations protect sensitive data, not just how they defend their networks. Demonstrating that data remains protected, even in the event of a breach, changes the conversation entirely.

There is also a broader strategic benefit. As organisations continue to adopt hybrid and multi‑cloud environments, traditional security boundaries become less relevant. Data moves constantly between locations, partners, and platforms. Protecting it at the source ensures that security travels with it, rather than relying on the integrity of each individual environment. Real control comes from ensuring that only the data owner can decrypt sensitive information, even when the underlying networks or platforms are compromised.

The reality is that cyber threats are not going away. Attackers are becoming more sophisticated, more patient, and more focused on outcomes. At the same time, the arrival of quantum computing will fundamentally change the assumptions underpinning today’s cryptography. Organisations cannot afford to wait for that moment to act.

The priority now is to design security for the world as it actually is, not as it was. That means accepting that breaches will occur, recognising that existing cryptography has a limited lifespan, and focusing on what truly matters.

When data is protected at its core, the impact of a breach is dramatically reduced. When that protection is quantum‑safe and adaptable, it becomes future‑proof.

The goal is simple but powerful: make stolen data worthless, because when attackers can no longer profit from what they take, the entire economics of cybercrime begins to change.

Simon Pamplin
Simon Pamplin

Simon Pamplin joined Certes in 2022, bringing with him his wealth of technical expertise and sales experience, previously within storage and data centre networking. Simon’s passion for business and technical solutions is shown by his strong track record of developing and managing high-performing teams of pre-sales professionals. His skills span across various areas, including on-premises and off-premises cloud, as well as large-scale consolidation and virtualisation of infrastructure. Simon has extensive experience working across different countries and cultures within EMEA and Russia, across multiple industries. Simon emphasises a practical approach to data security, urging organisations to prioritise safeguarding data above all else. With DPRM, he ensures customers can assess their security strategies effectively and make informed decisions to strengthen their security posture and enforce policies while mitigating risk.

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    Visual data is the blind spot in enterprise security: that’s about to change

    May 4, 20267 Mins Read

    Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

    March 10, 20264 Mins Read

    Microsoft: Python-Powered Infostealers Are Now Targeting macOS at Scale

    February 5, 20265 Mins Read
    ISB-Bora-Side-Bar

    No se ha podido establecer conexión. Error 429

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}