In Spain, we continue to talk about cybersecurity as if the problem were primarily limited to large companies. It’s a mental crutch because it allows us to imagine that the risk lies elsewhere—in the IBEX, in the most heavily regulated sectors, in companies that already have a CISO, a budget, and specialized vendors. But the full picture goes beyond that, since the real blind spot lies in the thousands of small and medium-sized businesses that already operate online, rely on third parties, use digital services to stay in business, and yet still treat cybersecurity as a one-time purchase or as a topic exclusively for the IT department. In a country with 1.51 million active companies employing one or more workers, continuing to view the problem solely through the lens of large corporations is, quite simply, a mistake.
The biggest cybersecurity risk isn’t where we think it is