Chapter 2
02The Evolving Threat Landscape
“The attacker does not need to succeed every time; it is enough that we forget once.”
As organisations rely more and more on digital systems and software, cyber threats grow in number, sophistication and impact. Understanding these threats is a precondition for effective strategies to protect sensitive information and keep systems intact. Awakening security starts by knowing the adversary: who they are, what tools they use and what they want.


Text in this figure
Actors · Who attacks? · Organised crime groups · Insiders · State-backed actors · Opportunistic hackers · Tools · How? · Ransomware · Phishing and social engineering · Supply chain compromise · AI-enhanced attacks · Goals · What do they want? · Money and extortion · Intellectual property · Personal data · Disruption and reputation · Motives change and tools evolve, but the target is the same: your information · Figure 3
The Rise of Cybercrime
Cybercrime has become a lucrative industry in which criminal organisations exploit advanced techniques to breach software and networks. Motives range from financial gain to political aims, but the consequences are equally harsh.
- Ransomware: Encrypts an organisation’s data until a ransom is paid, and today it is often paired with extortion by threatening to publish stolen data. It targets organisations of every size, and a small agency is no less attractive.
- Phishing: Messages impersonating trusted parties to steal credentials or install malware, now precisely tailored to each victim.
- Advanced persistent threats (APT): Long-term intrusions that lie dormant inside the network, quietly gathering information.
The Supply Chain: The New Back Door
Software today is rarely built from scratch; it is assembled from open-source libraries, APIs, cloud services and plugins. Every external component is a grant of trust. Compromising a single popular library, or a plugin in a design application, can give an attacker access to thousands of organisations at once. That is why a software bill of materials (SBOM) and supplier assessment have become essential parts of security.
Insiders
Not every threat comes from outside. A disgruntled employee, a former contractor who still holds the link to the shared folder, or a well-meaning colleague who sends the wrong file to the wrong client. The insider threat, intentional or not, accounts for a large share of data leakage incidents.
AI-Enhanced Attacks
AI is a double-edged sword. Attackers use it to write flawless phishing messages in any dialect, clone executives’ voices to request urgent transfers, and produce fake videos that damage brands. Defenders, in turn, use it to automate threat detection, analysis and response faster than ever before.
From the Field
The most dangerous moment in a creative agency is delivery night: everyone is exhausted, the client is waiting, and an urgent message asks for “the link to the final files, now”. Attackers sometimes know your deadlines better than you do.
The landscape changes, but the conclusion holds: no single tool is enough. What withstands this diversity is a management system that understands its assets, assesses its risks and adapts continuously, which is the subject of the rest of this book.
Lessons Learned
- 1Ransomware and phishing remain the most widespread threats.
- 2Every library, plugin and external supplier is part of the attack surface.
- 3The insider threat, intentional or accidental, deserves the same controls.
- 4AI speeds up attacker and defender alike; the difference lies in the system, not the tool.
Tip: use ← → to move between sections.

