Cybersecurity strategies are failing

Cyber firm pleads with enterprises to wake up to the data security crisis before financial and legal fallout becomes catastrophic.

  • Tuesday, 22nd April 2025 Posted 8 months ago in by Phil Alsop

Certe has released two hard-hitting whitepapers exposing the harsh reality: businesses are pouring billions into outdated security models that do nothing to stop data breaches. Their research dismantles the illusion that network security protects enterprises and reveals the cold, hard truth: data is the only asset that matters, and companies are failing to protect it.

From the research, it was quick to conclude that despite the cybersecurity industry’s relentless push for firewalls, endpoint protection, and network monitoring, businesses are still being hacked. The reason? They’re guarding the wrong thing. Enterprises obsess over securing the perimeter while cybercriminals walk straight past their defences and steal what they came for: data.

Paul German, CEO of Certes, doesn’t mince words: “Cybercriminals do not steal networks, they steal data. Intellectual property, financial records, customer information, and trade secrets; these are the goldmines. A breach can happen without a single firewall being compromised, yet the business impact is catastrophic.”

He continues, "Data is now more valuable than cash, real estate, and even physical infrastructure. A manufacturing plant can be rebuilt, but once sensitive data is exposed, it’s gone forever. The explosion of ransomware, insider threats, and relentless regulatory crackdowns means a data-first security strategy is no longer optional, it’s survival.”

The statistics are alarming. IBM reports the average cost of a data breach hit $4.45 million in 2023, yet this is just the tip of the iceberg. The reputational damage, lost customers, and crushing fines under GDPR, CCPA, and other regulations can cripple a company overnight.

Traditional cybersecurity is stuck in the past, relying on perimeter-based security when businesses operate in a borderless, cloud-first world. Remote work, SaaS applications, and third-party integrations have shattered the concept of a “secure network,” leaving companies dangerously exposed. Worse still, insider threats and simple misconfigurations are often the cause of breaches, not elite hackers.

"The biggest lie in cybersecurity is that protecting the network protects your business," says Simon Pamplin, CTO of Certes. "Attackers are already inside. Employees, contractors, and even trusted partners can be the weak link. A zero-trust approach assumes breaches are inevitable, so the only way forward is to make stolen data useless.”

Certes is calling for enterprises to abandon failed security strategies and adopt a Data Protection and Risk Mitigation (DPRM) approach. By leveraging encryption, access controls, and zero-trust principles, businesses can render stolen data worthless, even if attackers get inside the network.

Paul German concludes, “The message is clear: securing networks is a fantasy. If businesses don’t rethink their cybersecurity priorities now, they’re not just at risk, they’re already compromised.”

Identity security meets real-time threat response

Posted 2 weeks ago by Sophie Milburn
SailPoint announces new integrations with CrowdStrike to bolster identity-based threat response, advancing security operations and decision-making...

Small businesses face rising cybersecurity attacks

Posted 2 weeks ago by Sophie Milburn
Nearly half of US SMBs faced cyberattacks, yet many remain underprepared and reliant on untrained staff for security, Guardz study finds.
TCS strengthens its alliance with Aviva by expanding its policy administration services, embracing advanced digital solutions for customer-focused...
Hammer teams up with Nexsan to offer storage solutions across EMEA, enhancing modern data management capabilities.

Nordic security expertise expands in Europe

Posted 2 weeks ago by Sophie Milburn
MetaCompliance expands its foothold in Europe by acquiring Nordic leader Junglemap, enhancing its capacity to offer advanced security and compliance...

CrowdStrike launches Falcon AIDR for AI security

Posted 2 weeks ago by Sophie Milburn
CrowdStrike unveils Falcon AIDR, a unified platform to secure AI interactions, marking a new era in enterprise AI security.

Storage platform receives HPE validation for integration

Posted 2 weeks ago by Sophie Milburn
StorONE's platform meets HPE's standards, enabling organisations to efficiently leverage HPE ProLiant Gen11 servers.
Keepit partners with Ingram Micro to extend its data protection solution to French resellers and MSPs, enhancing reach and robustness.