ComputerWeekly

The Security Interviews: Evren Karaibrahimgil, Welsh FA


“The biggest threats are phishing and impersonation, and the human is the biggest target. Attackers don’t really try to hack you anymore, they just try to get the information off you,” says Evren Karaibrahimgil, IT manager at The Football Association of Wales (FAW).

Established in 1876, the FAW is the third-oldest national football association in the world and the body responsible for governing football in Wales, spanning 822 affiliated clubs and 120,000 registered players, from the men’s and women’s national teams down to grassroots football organisations. 

In his role, Karaibrahimgil is responsible for securing the FAW, its hundreds of employees, and the range of services it provides to footballers and fans throughout Wales against cyber threats, including phishing and impersonation campaigns.

That includes cyber attacks by fraudsters pretending to be the association’s CEO Noel Mooney in “urgent” requests sent to staff via text messages or emails. Those behind the attacks hope that by posing as the CEO, or another business executive, staff will be socially engineered to follow instructions they are issued without question, in what’s commonly an effort to steal data or money.

With Mooney a high-profile figure in football and regularly in the media, especially when international fixtures are being played, scammers have realised they can use his name to target staff at the FAW. For Karaibrahimgil, that makes training staff to identify these threats a top priority.

“We get plenty of texts and emails from fake accounts where they request information while pretending to be Noel Mooney,” he explains.

The biggest threats are phishing and impersonation, and the human is the biggest target. Attackers don’t really try to hack you anymore, they just try to get the information off you
Evren Karaibrahimgil, Football Association of Wales

This is especially the case when the Wales national teams are playing in matches in the Nations League, or during tournaments like the FIFA World Cup or the UEFA European Championship.

“When the campaigns kick off, the traffic for that kind of stuff tends to increase. When we get more media attention, that’s when we have to be more vigilant than usual. We have to keep on top of it by being proactive, rather than reactive.”

The Wales national teams have regularly qualified for international tournaments in recent years, most recently with the women’s national team taking part in the women’s Euro 2025, marking the first time they qualified for a major tournament.

Meanwhile, the men’s national team qualified for the men’s World Cup in 2022, marking its first appearance in the tournament since 1958. The team also qualified for Euro 2016, beating the odds to make it all the way to the semi-finals, and made the knock-out stages of Euro 2020, as well.

Preparing cyber defences for Euro 2028 on home soil

While the men’s team didn’t make it to Euro 2024 or the 2026 World Cup, with Euro 2028 set to be co-hosted by England, Scotland, Wales and the Republic of Ireland, and the Principality Stadium in Cardiff hosting matches, the FAW and the wider Welsh fanbase will be hoping Wales qualifies for the next tournament.

Karaibrahimgil shares those sentiments, of course, but in addition to that, he’s already thinking about and preparing for the cyber threats that hosting a high-profile international sporting event can potentially bring.

“We expect an increase in traffic in phishing and cyber attacks,” he explains. “The biggest challenge is keeping on top of it all because there’s a lot to do around protecting people and your infrastructure, but the attacks are always evolving, and the way hackers operate is always changing. It’s not like you learn one thing and that’s it, so you have to keep an open mind as well as trying to keep things as secure as possible.”

With Euro 2028, and potentially an appearance at the 2027 FIFA Women’s World Cup in Brazil in mind, the FAW recently signed a partnership with Welsh cyber security provider Socura, which is headquartered in Cardiff, to help it secure critical systems, digital services and sensitive data against cyber threats.

“We put the tender out and assessed other companies, but it was Socura which ticked all the boxes,” Karaibrahimgil explains.

“When we get more media attention, that’s when we have to be more vigilant than usual. We have to keep on top of it by being proactive, rather than reactive”

Evren Karaibrahimgil, Football Association of Wales

Through the partnership, Socura will supply the FAW with services including a 24/7 security operations centre (SOC) monitoring, managed detection and response (MDR), penetration testing, phishing simulation campaigns and security awareness training.

For Karaibrahimgil, ensuring that staff based at the FAW headquarters – just outside Cardiff at The Vale Resort in Hensol, Pontyclun – are aware of potential cyber threats like phishing attacks and trained to identify and report them is vital to the security of the organisation.

“With Socura, we’ve started using BoxPhish. Our previous cyber security awareness and training provider was good, but the phishing emails always went out on the first of the month, which was too predictable. Now we can randomise it and pick realistic examples.”

Karaibrahimgil also praises the short, sharp nature of the training courses as preferable to hours-long courses which are only issued once a year, and potentially quickly forgotten by users.

“You can do those every few weeks, helping to make staff more aware. It gives us more control over the learning as well,” he says.

The nature of international football means that the men’s and women’s teams both regularly travel abroad to play matches. The qualifying matches for Euro 2028 have yet to be drawn and scheduled, but there’s a chance Wales could have to play teams based thousands of miles away, perhaps even having to go as far as Kazakhstan, as the squad had to in the qualifying group for the 2025 World Cup.

In this scenario, while cyber security remains vital, it’s also important to ensure it doesn’t disrupt the operations of the staff out supporting the team, no matter where in the world they are. Yes, it might look strange for a member of staff at a business to suddenly log in from Kazakhstan, for example, and it’s something that could indicate a compromise. But at the FAW, this kind of unique situation is taken into account.

“When we’re looking at and checking logs when users log in from IPs outside of the UK, how do you know if someone has been breached or if they are just away on a training camp?” asks Karaibrahimgil. “You check if those people are actually abroad and that it is a legitimate login. It’s simple actions like that.

“Multifactor authentication (MFA) is implemented for all users, and it’s fundamental to us that it’s enforced,” he adds.

Penetration testing a pillar of securing the FAW

Ensuring the security of an organisation isn’t just about protecting the users, it’s about ensuring the systems are protected too. And for Karaibrahimgil, one of the key challenges is making sure that systems and software are secure, especially at a time when new cyber security vulnerabilities are rapidly emerging – and rapidly being exploited.

“A big threat is security vulnerabilities and misconfigurations, which we keep on top of with security penetration testing. And all of our third-party external systems, we have to make sure they are secure,” he says.

The nature of the FAW as a sporting organisation means it deploys a range of bespoke software solutions for everything from registering players, coaches and referees within Wales, to the customer relationship management (CRM) tools used by grassroots football groups nationwide to organise leagues, cups, tournaments and other events.

These systems need to be robust to ensure that any sensitive information about players, be they children playing for teams at the local park on a weekend or professional footballers based in Wales, is secure against cyber threats or data breaches.

It’s vital to keep on top of everything proactively. To make sure you are liaising with your providers and reacting quickly to vulnerabilities. The more information you have, the more protected you are
Evren Karaibrahimgil, Football Association of Wales

“It’s the key system we use to manage football across Wales. All football games, events, cups and more are handled through that system, so we have to make sure that system is as secure as possible, and the pen-testing element is fundamental for that,” says Karaibrahimgil.

“That goes for other systems as well, like our website, which fans use for updates, the shop, the match centre. If anything were to happen to the website, that would impact us drastically. That penetration testing which Socura provides is crucial – we couldn’t do without it.”

When the FAW is pen-testing its systems, the organisation is also careful to ensure that the exercise is relevant to its needs and that if there are any vulnerabilities, issues or other feedback that emerge as part of the process, they can be acted on right away.

“We go through what is going to be tested, when it is going to be tested, how much weight we want to put on those systems, and they dissect it and identify any vulnerabilities, which we will fix right away,” Karaibrahimgil explains. “We look at it through the lens of what would have the biggest business impact if there was a breach. And we make sure we are as secure as possible based on that information.”

For Karaibrahimgil, it all comes back to making sure that when it comes to cyber security, the FAW is on the front foot.

“It’s vital to keep on top of everything proactively. To make sure you are liaising with your providers and reacting quickly to vulnerabilities. The more information you have, the more protected you are,” he concludes.



Source link