Many companies don’t suffer security incidents because of sophisticated hacking techniques. They suffer because of assumptions.
“We’re too small.”
“We’re not interesting enough.”
“It won’t happen to us.”
This assumption creates vulnerability long before any technical weakness does.
In Hacked, now what?, Nathalie Claes describes a pattern she has observed for more than two decades in the field: companies consistently underestimate their exposure. As a CISO, DPO, and external auditor, she has repeatedly encountered organizations convinced they were secure, until closer inspection revealed serious gaps.
Cybercriminals are not operating emotionally. They operate statistically.
Automated tools constantly scan the internet. Phishing emails are sent out in large numbers. Weaknesses are found within minutes. It’s usually not a targeted attack on one specific company. It’s about volume and persistence.
And this is where the central misunderstanding begins:
Information security has never been about IT alone.
Beyond IT: The real scope of information security
When people hear “information security,” they immediately think of firewalls, antivirus software, or IT departments. But information security is not about technology, it is about protecting information itself.
Every organization depends on protecting three core principles: Confidentiality, Integrity, and Availability, commonly known as the CIA triad.
- Confidentiality ensures that information is accessible only to authorized individuals.
- Integrity guarantees that information is accurate and has not been altered.
- Availability ensures that systems and data remain accessible when needed.
These principles apply to far more than servers and software.
Human Resources manages employee records, contracts, payroll data, and sensitive personal information. Finance handles payments, banking details, tax documentation, and supplier agreements. Marketing stores customer databases, campaign analytics, and brand strategies. Sales protects pricing structures, contracts, and negotiation details.
None of these departments are “IT.”
Yet all of them are prime targets.
A ransomware attack that locks financial systems is not just an IT issue, it is a business continuity crisis. A phishing email that compromises HR data is not a technical glitch, it is a reputational and legal risk. A system outage affecting customer platforms impacts revenue, trust, and long-term growth.
Information security is therefore not a technical project. It is a business risk management discipline.
The Hacker’s perspective
To truly understand the urgency, you must shift perspective.
Imagine your organization through the eyes of a cybercriminal. They do not see your brand values or your years of effort. They see data. They see opportunity. They see potential financial gain.
Attackers operate at scale. They automate investigation. They identify exposed systems. They test credentials obtained through previous breaches. They leverage social engineering tactics to manipulate employees. They continuously search for weak links, and the weak link is rarely a server configuration alone.
The weakest link is often human behavior.
One employee clicking a malicious attachment can be enough. One reused password can open multiple systems. One unverified phone call pretending to be a supplier can redirect payments.
For the attacker, your organization is just one of many attempts. For you, a single successful attack can be devastating financially, legally, and reputationally.
Increasing European legislative pressure
While cyber threats are evolving rapidly, regulation is evolving alongside them. The European Union has significantly increased legislative pressure to strengthen digital resilience across member states.
The Cyber Resilience Act introduces mandatory security requirements for products with digital elements. Manufacturers and providers must ensure that cybersecurity is integrated from the design phase onward. Vulnerability management and secure development practices are no longer optional, they are expected.
The NIS2 Directive, which came into force in October 2024, significantly expands the scope of its predecessor. It imposes stricter risk management and reporting obligations on organizations operating in critical and important sectors, such as energy, healthcare, transport, digital infrastructure, and more. Importantly, NIS2 also emphasizes supply chain security. Even if your organization does not fall directly under the directive, your clients might — meaning you will likely need to demonstrate adequate security measures to maintain business relationships.
The AI Act addresses the rapidly growing use of artificial intelligence. It introduces risk-based classifications for AI systems and requires transparency, governance, and accountability measures. Companies must carefully evaluate how AI is integrated into their products and services, ensuring reliability and minimizing bias.
The General Data Protection Regulation continues to enforce strict rules regarding the processing of personal data. Since 2018, GDPR has reshaped how businesses handle customer and employee information, imposing significant penalties for non-compliance.
Sector-specific regulations, such as DORA for financial institutions, further reinforce operational resilience requirements.
This wave of legislation is not meant to burden businesses, it is meant to elevate resilience. However, compliance requires structured risk assessments, documented processes, technical safeguards, internal training, and governance oversight.
Organizations that treat compliance as a checkbox exercise miss the point. Those that embrace it as a strategic opportunity strengthen trust, reputation, and long-term sustainability.
The Rise of AI and the Domino effect
Artificial intelligence is reshaping the threat landscape.
Attackers now use AI to craft highly convincing phishing emails, automate vulnerability scanning, and generate deepfake audio or video impersonations. Social engineering has become more sophisticated and more scalable.
At the same time, businesses are rapidly integrating AI into customer service, analytics, marketing automation, and decision-making systems. Without proper governance, AI can introduce new risks: biased outputs, lack of transparency, overreliance on automated decisions, and new attack surfaces.
In a highly interconnected digital ecosystem, one vulnerability can trigger a domino effect. A compromised supplier can impact your operations. A breached software provider can expose thousands of downstream clients. A single weak authentication process can open access to multiple integrated platforms.
The modern enterprise does not operate in isolation. Risk travels through networks, technological and human.
The Human Factor
Despite all technological advancements, most security incidents still originate from human interaction.
This does not mean employees are careless. It means organizations often fail to equip them properly.
Security awareness training is frequently treated as an annual formality rather than a continuous cultural investment. Policies are written but not embedded in daily practice. Reporting suspicious activity is not always encouraged or rewarded.
Employees must understand not only what to do, but why it matters. They need clear procedures, realistic simulations, and leadership that models secure behavior.
When employees feel supported rather than blamed, they become active defenders of the organization.
Creating a culture of security
Information security is not a department. It is a mindset.
It requires leadership commitment at the highest level. It demands clear accountability structures. It depends on continuous risk evaluation and improvement. It involves aligning technology, processes, and people.
Creating a safety culture means:
- Conducting regular risk assessments.
- Embedding security considerations into strategic decisions.
- Investing in employee awareness.
- Establishing incident response plans.
- Monitoring and reviewing controls consistently.
- Treating security as an enabler of trust rather than a cost center.
The companies that thrive in today’s digital landscape are not those that avoid every risk. That is impossible. They are the ones that understand their risk profile, take proactive measures, and prepare for when, not if, incidents occur.
Because when an attack happens, it is not an IT problem.
It is a leadership issue.
It is a financial issue.
It is a reputational issue.
It is a business continuity issue.
Information security has nothing to do with IT alone.
It has everything to do with the future of your organization.
These reflections are explored in greater depth in Hacked, now what?, where Nathalie Claes provides practical guidance for organizations navigating today’s evolving threat landscape.
Get your copy now:
English book:
🔹Amazon
🔹bol.



