powered_by-logo reporter-logo inbusiness-news-logo GOLD-DIGITAL-EDITIONS

Alexandru Ghioca: Every file that a business receives is a potential backdoor for cyber attacks

The critical role that files play in modern security architecture was analysed by Alexandru Ghioca, Regional Sales Manager SEE, at OPSWAT, in his presentation entitled 'Your Perimeter Is Open: Rethinking File Security as Your First Line of Defence' at the 6th Cyber Security Conference.

Ghioca analysed the security paradox, explaining how files that move daily through email, mobile storage devices, web portals, and sharing platforms create permanent points of exposure. Organisations are constantly investing in defence tools, but breaches are increasing, with the average cost of a data leak reaching $4.88 million and the average time to detect it reaching 258 days. Historical examples of massive disasters prove that the root of the problem is hidden in records that were considered trustworthy.

Businesses have entry gates designed to accept documents, but not to check them. The problem is exacerbated by the fact that over 450,000 new malware variants are created every day, as the use of artificial intelligence models on the dark web allows the automatic creation of unique digital threats in a matter of seconds, rendering traditional detection methods useless.

At the same time, he stressed the need to move from simple detection to preventive consolidation, presenting the limitations of an approach based solely on perimeter protection. The classic method of scanning and waiting for results is only effective for threats that have already been registered. In contrast, OPSWAT's advanced content deconstruction and reconstruction technology does not rely on digital footprints. It decomposes the file, removes any active content, and rebuilds a completely clean and secure document for use.

In addition, the expert underlined that the challenge of the time shifts from whether a file is safe to open, to whether its content is true. Given that 76% of organisations in the United States faced payment fraud attempts in 2025, the platform incorporates a dedicated AI content authenticity checker that evaluates the authenticity of invoices or documents as they are entered.

In his presentation, Ghioca also highlighted the stringent requirements of the new NIS2 and DORA regulatory framework, linking record-level prevention to operational resilience and practical solutions that organisations can adopt immediately. The European directives, which have been incorporated into the national law of Cyprus under the supervision of the Digital Security Authority, cover 18 productive sectors and provide for fines of up to 10 million euros or 2% of global turnover for cases of violations.

For their immediate protection, Ghioca suggested that businesses map every file entry channel, implement simultaneous scanning by multiple security engines, replace file blocking with their sanitisation to maintain workflow, and record every file management decision for future audits.

(Source: InBusinessNews)