22/06/2026
The question is no longer whether your organization will be attacked. It's whether you'll be ready when it happens.
Last June 11, 2026, we sat with four people who deal with this every single day โ not in theory, but in practice. And what they shared was equal parts eye-opening and sobering.
๐๐ญ๐ญ๐ฒ. ๐๐จ๐๐๐ซ๐ญ ๐. ๐๐๐ ๐ฎ๐ข๐ of CICC didn't sugarcoat it. The attacks are already here โ phishing, smishing, supply chain breaches โ and they follow a pattern: Investigation, Hook, Play, Exit. By the time most organizations realize what happened, it's already done. He walked through the CIANA-PS framework and the Data Privacy Act, and left everyone with something simple enough to remember but serious enough to act on: if you don't need it, don't collect it. If you collect it, protect it. If you no longer need it, dispose of it properly.
๐๐ซ. ๐๐ข๐ฅ๐ฅ๐ข๐๐ฆ ๐๐ฆ๐ฆ๐๐ง๐ฎ๐๐ฅ ๐๐ฎ of Novare Technologies had us rethinking AI entirely. Not as a tool but as a shift in how we think. The cognitive revolution, he called it. And the risks aren't coming. They're here. Prompt injection. Model poisoning. Deepfakes. And something quieter but just as dangerous: cognitive dependency. The slow erosion of our ability to function without AI telling us what to do next. His point on High Trust Work hit differently too. The jobs that matter going forward aren't just technical. They require judgment. Ethics. Accountability. Things a model can't replicate.
๐๐ซ. ๐๐ฅ๐ข๐ณ๐๐ฅ๐๐ ๐. ๐๐ฎ๐ซ๐๐ง of CyberSoCPH put up a slide that should genuinely alarm anyone in education. Threats evolve daily. AI evolves weekly. But curricula? Every five to ten years. We are sending graduates into a threat environment that their education never prepared them for. His argument: every program, not just computer science, not just IT, needs cyber awareness baked in. Because the attack surface doesn't care what your major was.
๐๐ซ. ๐๐ข๐๐ฌ๐จ๐ง ๐๐ข๐ง๐ ๐ฌ๐จ๐ง ๐๐ฎ๐ of SQrity kept it grounded. The DICT National Cyber Security Plan is already in effect. The Data Privacy Act has teeth. NPC compliance isn't optional. And yet most organizations are still treating cybersecurity like an annual training they can tick off a list. His Three-Pillar Framework covering Academe, Industry, and Government only works if all three are actually moving. One pillar holding up everything else isn't resilience. It's risk.
The thread running through all of it? Cybersecurity stopped being an IT issue a long time ago. It's in the boardroom now. In the classroom. In every policy memo and budget decision. If you're in leadership and you're still delegating this entirely to your tech team, that's the gap.
So, a few things worth doing this week:
๐ Find out what personal data your organization is sitting on. All of it. Then ask if you actually need it.
๐ค Look up prompt injection and model poisoning. Not to become an expert, just to know what you're dealing with.
๐ If you're in academe, pull up your current curriculum and check the last time cybersecurity was seriously reviewed.
๐ข Check your organization against the DICT National Cyber Security Plan 2023-2028. The gaps are probably bigger than you think.
The conversation happened. Now the work starts.
Thank you to our speakers, our participants, and everyone who came ready to engage. More masterclasses ahead. ๐