Cybersecurity Expert Brian Wagner on the Future of Digital Threats and Why Human Error Remains the Biggest Risk

Brian Wagner is recognised as a leading authority in cybersecurity, with frontline expertise in protecting businesses against modern digital threats. 

A former Global Head of Compliance at Amazon Web Services and now Chief Technology Officer at Defence.com, Brian is regarded as one of the best cyber security speakers, shaping the future of cybersecurity and risk management for organisations worldwide. 

In this exclusive interview with Champions Cyber Security Speakers, Brian shares his insights into the evolving threat landscape, the crucial role of human behaviour in data breaches, and why proactive security strategies are essential for businesses to stay resilient in the face of rising cybercrime. 

 

Q: In your experience, what remains the primary cause behind most data breaches in organisations today? 

Brian Wagner: Sadly, it’s human beings. Humans are naturally trusting by nature — it’s just ingrained in us. Statistically, it’s a fact that phishing is a major cause, and that people are the weakness. Traditionally, before email was a big thing, exploits were more physical. For example, someone might walk into a front office and say, “Look, I’m late for a job interview, can you please print my CV?” — and hand over a USB stick. Once plugged in, that would breach the system. 

These days, with remote working, phishing is absolutely on the rise. But really, I don’t want to keep leaning on phishing for every single answer. To answer your question more broadly, people are, unfortunately, the weakest link in any organisation when it comes to data security. 

 

Q: As cyber threats evolve, what type of attack do you anticipate will define the next major wave of cybercrime? 

Brian Wagner: Wow. I think it’s going to be linked to advances in quantum computing and futuristic technologies. As our computing power gets stronger, there will come a time when our current encryption mechanisms will be rendered useless. 

I don’t know if it will be the very next wave, but looking at how encryption is handled today and how data is protected digitally, there is a not-so-distant future where encryption can be broken within a reasonable amount of time — either through quantum computing or simply through generally more powerful systems. 

 

Q: Ransomware attacks are increasingly crippling businesses. In your view, what immediate steps should companies take if faced with financial extortion from hackers? 

Brian Wagner: First of all: do not pay them. That is the absolute number one rule — do not pay — because that is exactly why ransomware attacks exist. It’s lucrative. If nobody paid, attackers wouldn’t do it. 

Number two would be figuring out what the impact is. Ideally, if you have already been backing up and archiving data, then it would be an inconvenience at worst. 

There are two reactions to this. One, if you have backup data, you theoretically will not lose any data. Even if the original is never unencrypted, you would ideally have a backup. The inconvenience there is that it takes time to restore that data — which would cause an outage, but again, only an inconvenience at worst. 

The other side of it is what data has been stolen or ransomed. If attackers exploit that data — whether personal information, customer details, or internal files — you have an obligation to notify the individuals concerned, not just under GDPR but also as a respectable business. 

You should absolutely reach out and say, “This is what has happened, here’s what we believe was taken.” Individuals then also need to be vigilant. But again — rule number one — don’t pay them. 

 

Q: For businesses aiming to bolster their cyber defences, what straightforward yet impactful measures would you recommend implementing first? 

Brian Wagner: I think the absolute top tip — and it’s easy to implement — is to use a password manager. 

A lot of breaches now are from commonly used passwords or passwords leaked on the internet. Using a password manager is probably the absolute easiest way to prevent a breach. 

Secondly, vigilance around emails is crucial. If you’re not familiar with phishing: it’s when attackers try to get people to surrender information — usernames, passwords, bank details, whatever it may be. For businesses, if someone falls victim to phishing, attackers typically use their credentials to log in and cause damage. 

There’s not always one simple fix, but a good general rule is: be sceptical of all emails. 

And a third very useful tip: everyone today uses third-party services — everything is subscription-based now. If you can enable multi-factor authentication, do it. 

If you lose your password or someone steals it, multi-factor authentication ensures that without that second factor, even a stolen password is useless. 

 

Q: Reflecting on your professional journey, what is the single most valuable piece of advice you would offer your younger self — or aspiring cybersecurity professionals today? 

Brian Wagner: Don’t be afraid to fail. Just try things — especially early in your career, no matter the field. 

There’s this tendency towards perfection, thinking “I have to be the best” or “I have to succeed immediately.” But failure is a crucial part of growth. 

Also — stick with your strengths. Early in their careers, people want to please everyone. They say yes to everything to try to advance. For example, if you’re hired to solve a software issue for Ford Motor Company and someone says, “Hey, you’re good with computers, can you fix the printer?” — it’s okay to say no. 

You have to stay on track and command authority within your domain. That’s very important. 

This exclusive interview with Brian Wagner was conducted by Mark Matthews.