{"id":18109,"date":"2023-04-05T14:52:37","date_gmt":"2023-04-05T14:52:37","guid":{"rendered":"https:\/\/www.crossjoin.pt\/?p=18109"},"modified":"2026-07-07T11:20:36","modified_gmt":"2026-07-07T11:20:36","slug":"cybersecurity-is-a-never-ending-marathon","status":"publish","type":"post","link":"https:\/\/crossjoin.com\/en\/cybersecurity-is-a-never-ending-marathon\/","title":{"rendered":"SIG team in Exame Inform\u00e1tica"},"content":{"rendered":"\n<h1 class=\"wp-block-heading\">&#8220;Cybersecurity is a Never-Ending Marathon&#8221;<\/h1>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">A good knowledge of defense and attack techniques is fundamental to guarantee security in companies, regardless of their size and sector of activity. To win this race, it is necessary to create a culture of knowledge across society.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The topic of cybersecurity gained relevance with the pandemic and with a greater digitalization of companies and processes. As an IT consultant, how does Crossjoin evaluate the current panorama of cybersecurity in companies<sup><\/sup> in Portugal?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Portugal has been no exception when it comes to increased investment in cybersecurity. With the shift to remote environments, companies were forced to adapt to a new reality, reinventing how they work and how they relate. This new normal has potentia<sup><\/sup>lized risks, often overlooked, and introduced major challenges to operations, such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The massification of remote work.<\/li>\n\n\n\n<li>Rapid adoption of collaborative tools.<\/li>\n\n\n\n<li>Heavy reliance on Software and Infrastructure as a Service (SaaS\/IaaS).<\/li>\n\n\n\n<li>Accelerated migration to Cloud Computing.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">With increased exposure and the escalation of cyber threats, there has been a trend of increased visibility regarding the dangers in the use of technology. There is a much greater attention to the risks of data leakages and loss of information, especially in light of compliance frameworks such as the GDPR (RGPD), and the severe impact breaches can have on a business.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This justifies, in part, the increased demand for information security professionals, as well as the adoption of international reference standards for information security management, such as <strong>ISO\/IEC 27001<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Crossjoin understands that it is imperative to protect against cyber and information security risks. For this reason, we invest heavily in internal improvements and the adoption of an information security culture, demonstrated by continuous audits under our ISO\/IEC 27001 certification. We constantly reinforce this need with our customers and partners; while an increase in investments in this area is perceptible, it is still insufficient against the level of sophisticated attacks to which they are subject.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Is there a growing awareness of the dangers and an increased investment in cybersecurity solutions in organizations?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We consider that there has been progress in society&#8217;s self-awareness, partly as a result of direct experience as victims of cyberattacks, but also thanks to the increase in media coverage of high-profile security breaches.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, in general, society is still not properly aware of the precautions to take regarding data exposure and transmission, nor of the impact that certain cybersecurity attacks can have on their daily lives. For this reason, we still see a lot of successful breaches due to a simple lack of attention or carelessness. Unfortunately, many companies do not pay enough attention to the topic of cybersecurity and data privacy, or they simply do not have the financial capacity to properly educate themselves and prepare for threats like the exposure of critical customer data.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Is the myth that cyberattacks only happen in big companies outdated?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Attacks on large companies end up gaining greater notoriety in the media for their direct, highly visible impact on financial values and the massive number of users affected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On the other hand, small companies are absolutely not immune. They suffer from automated attacks at scale and frequently become the target of choice for opportunistic attackers who exploit unpatched technical vulnerabilities, social engineering loopholes, and the general lack of an established information security culture.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Portugal has been noted as a frequent target for cyberattacks. Why does this happen?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Historically, metrics have shown Portugal ranking high among European countries experiencing intense cyber-activity, with the attacks carrying the greatest impact aiming to exfiltrate proprietary information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is due to a sum of several factors, main among them being a general lack of user awareness regarding safe data exposure and transmission. In addition, outdated, discontinued, or improperly maintained software across infrastructures significantly increases the available attack surface. However, it is important to note that this escalation is a synchronized worldwide phenomenon, not one isolated to our country.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">There is a lot of talk about the lack of literacy of users who continue to be the &#8216;weakest link&#8217; in cyberattacks. What can and should be done to change this picture?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The truth is that a large portion of cyberattacks stem from social engineering, such as phishing campaigns. These attacks have a high success rate because the digital society is not sufficiently prepared to recognize them. Although the investment required to mitigate these types of human-centric attacks is low compared to implementing complex technical defense infrastructure, it is an action that requires building a continuous culture of care.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thus, the best defense against phishing and social engineering is <strong>continuous awareness<\/strong>. Crucially, this awareness should not be restricted to corporate environments and companies. Awareness about information security principles, safe browsing, social networking security, and possible threat vectors should start as early as possible. Exposure to the digital world starts earlier every generation, so education needs to begin with the youngest minds in public society, schools, and universities.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What support can Crossjoin provide to companies in this regard?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In the same way that technology is constantly evolving, forcing a rapid response when it comes to threats, the services provided in this area must evolve too. We continuously advance our information security and cybersecurity services to incorporate this component into every kind of project.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We help our clients implement a true <strong>Information Security by Default &amp; by Design<\/strong> approach. We do this through:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Integrating information security directly into core business processes.<\/li>\n\n\n\n<li>Conducting rigorous development security audits and consulting.<\/li>\n\n\n\n<li>Injecting security checks seamlessly into the application deployment flow.<\/li>\n\n\n\n<li>Evaluating and diagnostics of SaaS and Cloud environments (&#8220;Cloud Security&#8221;).<\/li>\n\n\n\n<li>Providing a dedicated information security management service (<strong>Information Management Security Check<\/strong>).<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Internally, Crossjoin has a security skills center. What is the role of this center?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Internally, we have our own cybersecurity competence center, operating as a Special Interest Group (<strong>SIG<\/strong>). This center allows us to constantly update and improve our capabilities on cybersecurity issues, both for internal consumption and for our customers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our core responsibilities are safeguarding our corporate information, maintaining a highly specialized team, raising security awareness among all our employees, and proactively preventing threats to minimize the risks and structural impacts of possible attacks.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What differentiates your offer in such a competitive sector?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Our offer differs from the rest of the industry in the methodology and culture that defines our approach to problems. We strictly define the goal, isolate exactly what we need to achieve that goal, and then map the path to it \u2014 <strong>never making assumptions<\/strong>. This objective approach allows us to arrive at the most viable solution and solve performance and security problems considered completely impossible by many others in our industry.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What are your internal challenges, and what are the challenges facing organizations in general when it comes to cybersecurity?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Our core challenges are the same as those facing organizations globally: keeping up to date with the new offensive technologies and vulnerabilities that are developed every single day, and keeping 100% of our workforce prepared to recognize and deflect sophisticated attack attempts.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What warnings would you leave to entrepreneurs on the subject of security?<\/h3>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">&#8220;The warning we leave is to always be on alert and in continuous evolution. Cybersecurity is a never-ending marathon, in which our adversary only has to outrun us by a millimeter, once, to win it. We have to be always ready and always on the alert when using cyberspace. That&#8217;s why it&#8217;s necessary to always be up-to-date with new technologies and new methods of defense and attack that are developed.&#8221;<sup><\/sup><sup><\/sup><\/p>\n<\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\">Media Features<sup><\/sup><sup><\/sup><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Featured Team:<\/strong> Crossjoin SIG (Special Interest Group) Team<\/li>\n\n\n\n<li><strong>Publication:<\/strong> Exame Inform\u00e1tica<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;Cybersecurity is a Never-Ending Marathon&#8221; A good knowledge of defense and attack techniques is fundamental to guarantee security in companies, regardless of their size and sector<span class=\"excerpt-hellip\"> [\u2026]<\/span><\/p>\n","protected":false},"author":2,"featured_media":18121,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"rs_blank_template":"","rs_page_bg_color":"","slide_template_v7":"","footnotes":""},"categories":[74,53,54],"tags":[],"class_list":["post-18109","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles","category-crossjoin","category-team"],"acf":[],"_links":{"self":[{"href":"https:\/\/crossjoin.com\/en\/wp-json\/wp\/v2\/posts\/18109","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/crossjoin.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crossjoin.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crossjoin.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/crossjoin.com\/en\/wp-json\/wp\/v2\/comments?post=18109"}],"version-history":[{"count":1,"href":"https:\/\/crossjoin.com\/en\/wp-json\/wp\/v2\/posts\/18109\/revisions"}],"predecessor-version":[{"id":27441,"href":"https:\/\/crossjoin.com\/en\/wp-json\/wp\/v2\/posts\/18109\/revisions\/27441"}],"wp:attachment":[{"href":"https:\/\/crossjoin.com\/en\/wp-json\/wp\/v2\/media?parent=18109"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crossjoin.com\/en\/wp-json\/wp\/v2\/categories?post=18109"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crossjoin.com\/en\/wp-json\/wp\/v2\/tags?post=18109"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}