lee.potok@thal…
Wed, 09/30/2026 – 08:29
Cybersecurity Awareness Month 2026 highlights practical ways individuals and organizations can make life harder for cybercriminals. Thales experts emphasize protecting data wherever it resides, gaining visibility and control over cryptographic assets, using strong everyday security habits such as unique passwords, multifactor authentication and phishing awareness, and prioritizing digital sovereignty to maintain operational control in an evolving threat landscape.
Data Security
Identity & Access Management
Encryption Key Management
Thales | Security for What Matters Most
More About This Author >
Cybersecurity Awareness Month is a campaign that raises awareness about online safety and empowers individuals and businesses to protect themselves from cybercrime. This year, the campaign is built around one simple challenge: make life difficult for cybercriminals.
Staying safe online was never about one perfect decision. It comes down to small habits, repeated consistently, in the ordinary moments that make up a working day. The technology keeps changing. The fundamentals have not.
We asked people across Thales, from sales and marketing to engineering and leadership, spanning the whole world, what that looks like. Their answers follow.
Control the Data, Not the Perimeter
Enterprise data now resides across multiple disparate environments, many of them outside of an organization’s direct control. To make life harder for cybercriminals, our experts argue for focusing on the data itself, not the infrastructure it lives in.
Tushar Haralkar, Director of Sales Engineering, India & SAARC, is particularly assured on this point, noting that “every control we built over the last twenty years assumed one thing: that we own the ground the data sits on. We do not anymore. Which means protection must be attached to the data itself, not to the place it happens to be sitting.”
To implement that protection, Tushar advocates for a three-step approach:
- Discover and classify. You cannot encrypt, tokenize, or mask data you cannot see.
- Protect at the data object level. Apply encryption, tokenization, and masking to the object, so the protection travels with it.
- Own the keys. If the keys sit with the cloud provider or the SaaS vendor, a compromise of their key store is a compromise of your data.
Celestine Heng, Enterprise Account Manager (APJ), echoes this point, arguing that “the most effective practice is acknowledging that infrastructure defense is insufficient on its own. Organizations should secure their operations by encrypting critical data assets directly, neutralizing threats by rendering stolen information useless to attackers.”
Ai Qi Pek, Business Development Representative, ASEAN (APJ), drills down on the issue as it relates to mobile devices. She believes that people underestimate that, for attackers, phones are a gateway to both digital services and security. But it’s not enough to just secure apps.
“In APJ, where mobile banking, payments and digital services are part of everyday life, attackers can exploit identities or applications to ultimately reach valuable data,” she said. “Don’t just ask how you’re protecting the app, instead, ask what data sits behind it, who can access it, and whether that data remains protected wherever it moves or resides.”
Own Your Cryptographic Landscape
For many of our experts, understanding and controlling their cryptographic environment is one of the most important steps towards making life difficult for attackers.
Benjamin Longuechaud, Sales Engineering Lead, United States, looks at the problem from a quantum perspective, noting that “quantum computing has moved from ‘not a priority’ to an active line item in client planning, especially in healthcare and finance.”
He recommends starting a cryptographic inventory that maps “where RSA and ECC are used across your environment and how long that data needs to stay protected. Visibility into your cryptographic assets is usually the hardest step, and the one that matters most.”
Rob Stott, Regional Sales Manager, United States, meanwhile, would like to see more organizations being proactive, addressing foundational data protection concerns before infrastructure loses support, migration forces a redesign, an audit exposes gaps in database monitoring, or new regulatory requirements make encryption more urgent.
“When organizations finally address foundational data protection, the conversation becomes broader. They stop treating encryption, keys, certificates and sensitive data as separate projects and start thinking about how to protect data consistently
[…]
Content was trimmed to protect the source. Please visit the original article for the full text.
Read the original article:
