Trust, Threats, and the Limits of Preparedness
Written by Rebecca Uffindell Wed 13 May 2026

Day 2 of the Cloud, AI & Cyber Security keynote track at Tech Show Frankfurt moved away from systems and architectures and into the conditions in which those systems are used, where exposure increasingly sits in behaviour, process and the assumptions organisations make about how they operate.
The discussion did not stay with a single type of risk. Instead, it returned repeatedly to the same underlying change: threats are no longer confined to infrastructure, but appear in the spaces around it, where trust is extended, decisions are made quickly, and systems interact with people under pressure.
When Access Looks Legitimate
The session on infiltration, led by Nicol Daňková, made that shift visible in a way that is difficult to reduce to a purely technical problem. The entry point is not a vulnerability in code, but a vulnerability in process, where hiring, onboarding, and remote work create access that appears legitimate.
“We are very often missing schemes like this.”
The observation sits alongside a broader pattern, where security teams continue to focus on malware, exploits and system-level threats, while recruitment practices remain outside that frame of attention.
“You are not having in your environment connected… a developer… You are already having a tool of North Korea.”
The distinction is subtle. Access looks normal, but the activity behind it is not. The system is entered through processes designed for trust, not control.
“Who in your organisation knows exactly what is on the devices of the developers who are working for you remotely?”
The question changes the focus away from infrastructure and toward assumption, where visibility is partial, and verification is uneven.
The scale of the model extends beyond individual cases.
“She was handling 90 of those laptops at the same point in time.”
Operations become distributed, with multiple identities, locations and organisations connected through what appears to be routine employment.
“You are having one paycheck… but you are having two seats in two different countries.”
The system does not break in a visible way. It continues to function, while the underlying conditions change.
Preparedness Under Pressure
That same gap between structure and reality appears again in the discussion of cyber resilience, in a panel chaired by Riccardo Riccobene of State Street Bank International, with Dr Chantal Spleiss of the Cloud Security Alliance, Anton Horn of Envoy Security, and Nicol Daňková returning to the discussion.
Dr Spleiss’s comparison to training holds at first, but the discussion moves quickly into how those simulations are constructed.
“It really depends on how exactly you are executing your simulations.”
Daňková’s point shifts attention to execution, where the realism of exercises determines their value.
The critique is not directed at the existence of exercises, but at their depth, where compliance requirements can produce activity without necessarily producing readiness.
“It is not only about knowing which plan to execute… it is about going and doing something.”
Knowledge exists, but behaviour under pressure remains uncertain.
“You don’t have time to check somebody else’s facts.”
Trust becomes operational rather than conceptual, where teams act on shared understanding rather than verification.
“If you figure out during the exercise… who makes the decisions, you messed up big time.”
Horn’s point places authority at the centre of response, where clarity must exist before an incident occurs.
“The check marks will not help you in a crisis.”
The distinction between documentation and action becomes visible at the moment when systems are under stress. The language shifts toward experience, where learning is tied to response rather than procedure.
Where Control Falls Behind
The discussion of governance, led by Anton Horn, Founder and Managing Director of Envoy Security, returned to a different version of the same problem, this time in how organisations attempt to maintain control over increasingly dynamic systems.
“GRC is so painful for most people… it’s so manual, it’s so Excel driven.”
The issue lies in how governance is implemented, particularly as engineering environments continue to accelerate.
“The current approach doesn’t really work anymore.”
The gap becomes visible in the difference between how systems are deployed and how they are controlled.
“GRC team is loading up the Excel checklist and the engineers have deployed five new services.”
Control lags behind change, creating a situation where compliance frameworks remain static while infrastructure continues to evolve.
“Why do you need a screenshot from me?”
Evidence becomes detached from reality, particularly where systems are already defined in code.
“You actually get a current state picture of how you’re doing in security.”
The shift moves toward continuous visibility, where state is observed directly rather than reconstructed after the fact.
“There’s a certain culture shift.”
The adjustment is not only technical, but organisational, where different parts of the business must align around new ways of working.
Written by Rebecca Uffindell Wed 13 May 2026
