SecPod

Learn Search

Search across all Learn content

← Back to Expressions & POVs
Attacks are real, it would be naïve to think otherwise

Attacks are real, it would be naïve to think otherwise

All human beings have a part of the good and the bad. At times, bad takes over the good and other times, good takes over the bad. The fight between the good and the bad is not new.

May 28, 2013By Chandra2 min read

All human beings have a part of the good and the bad. At times, bad takes over the good and other times, good takes over the bad. The fight between the good and the bad is not new.

Attacks do happen and can happen to anyone, anytime, sometimes with notice and mostly without notice. In major part of the civilized physical world, people live in peace mostly. We have been able to contain the bad to a greater extent and the world is seemingly peaceful at large. But, there again, thefts happen, raids happen, conflicts happen, accidents happen, killings happen, underworld exists.

In the digital world, where you cannot visualize the image of an attacker, where the traces of the attacker are hard to characterize, where everything is virtual, it becomes harder to bring order. It is easier for attackers of all forms (humans and bots) to exhibit their skills more freely. Just as you thought your introvert friend is so extrovert online.

In order for this writing to remain relevant, I would ask you to Google, ‘recent malware attacks’ and I am sure you hit a million results. There are number of software applications and operating systems having vulnerabilities, there are spams and phishing attacks, there are sophisticated attacks (advanced persistent threats), attacks on the mobile devices, large banks are attacked, major news agencies are attacked, Government establishments are attacked, and technology companies are attacked. Who is safe?

Attacks are real; it would be naïve to think otherwise.

Each one of us has experienced an attack of some kind or many kinds at some point or at multiple points. If you haven’t been one of the victim, you probably didn’t realize your data was stolen or probably didn’t realize your system was used in one such attack or you have been plain lucky.

So, what do attackers target?

It is mostly your data and information, your credit card, online bank account details, financial transactions, your identity profile, your health records, your company data, your business strategy, your productive hours. And there are sophisticated, well-funded, organized attackers who target countries, defense establishments, water and energy supply, nuclear establishments, manufacturing units, satellites. And there are others who mostly take out your peace.

As much as we embrace this digital world, we need to be prepared to deal with its adversaries too.

Featured Posts

Open The Most Effective Vulnerability Assessment Framework What Makes One Effective
The Most Effective Vulnerability Assessment Framework What Makes One Effective

Point of View

The Most Effective Vulnerability Assessment Framework What Makes One Effective

No single named standard makes a vulnerability assessment framework effective. This piece covers NIST, ISO, and CIS Controls, then breaks down what actually separates a working framework from a checklist, coverage, risk based prioritization, cadence, ownership, and a feedback loop.

Sep 11, 2026

Open Threat and Vulnerability Assessment How Risk Actually Gets Calculated
Threat and Vulnerability Assessment How Risk Actually Gets Calculated

Point of View

Threat and Vulnerability Assessment How Risk Actually Gets Calculated

A vulnerability alone doesn't tell the whole risk story. This piece breaks down how a threat and vulnerability assessment pairs technical weaknesses with real attacker context, walks through the six step process, and covers frameworks like NIST 800-30 and ISO 27005.

Sep 11, 2026

Open Vulnerability Assessment Services: What to Look For
Vulnerability Assessment Services: What to Look For

Point of View

Vulnerability Assessment Services: What to Look For

Choosing a vulnerability assessment provider means asking about actual coverage, scan frequency, and whether findings come with real prioritization or just a CVSS dump. This piece breaks down what strong vulnerability assessment services include, red flags to avoid, and questions to ask before signing.

Sep 11, 2026

Open Agentic AI Vulnerability Assessment What Changes and What Does Not
Agentic AI Vulnerability Assessment What Changes and What Does Not

Point of View

Agentic AI Vulnerability Assessment What Changes and What Does Not

Agentic AI is expanding what a vulnerability assessment needs to cover, autonomous agents bring their own credentials, tool access, and memory, adding a genuinely new asset class alongside servers and endpoints. It's also compressing attacker timelines and introducing risk categories like goal hijacking and tool misuse that don't map to a traditional CVE. But the core discipline hasn't changed: the same lifecycle of scoping, scanning, prioritizing, and remediating still applies, human judgment still drives prioritization, and accountability still sits with the people who deployed the agent, not the agent itself.

Sep 9, 2026