Growth attracts attention, and not always the good kind. As an enterprise scales, so does its attack surface, and with it, pressure from relentless threat actors looking for any chink in the armour.
But what would prove enough to defend a mid-sized firm might quickly buckle under the weight of sprawling infrastructure, a maze of compliance demands, and dozens of teams working in niche areas.
If your organisation still doesn’t consider cybersecurity an essential function, one tied to every other business goal, it’s in the minority. A recent nationwide survey by the UK Government found that 72% of all British businesses consider cyber a top priority, jumping to 96% for larger organisations.
Those who want to build (and secure) the most successful firms in any industry now have to make sure that, alongside scaling their operations, expanding their teams, and chasing new markets, their security strategy grows in lockstep with every other ambition.
But how to do that, and do it better than your competitors?
To answer that question, Rachel Coull, founder of fractional and interim CISO consulting firm RC SecureTech, walked a packed audience at DIGIT’s ScotSecure West through exactly what businesses need to do to scale their cyber functions, and how to reposition cybersecurity not as a cost centre, but as a catalyst for innovation and long-term growth.
Why Cybersecurity Must Scale
“When we talk about scaling cybersecurity, it’s a mix in terms of increasing your team size, increasing your tooling, or your tech stack, or it could mean scaling your organisation,” said Coull.
“What it really means is changing in light of what we’re now facing in terms of risk and the threat landscape.”
Working in cyber, especially for a large organisation, means doing battle on multiple fronts, all day every day, from contending with the ever-expanding attack surface introduced by new applications and devices to the innovation of adversaries and the pressure of regulators.
That’s not exactly news. After all, attack surfaces have been expanding since day dot and hackers have always played a cat and mouse game with security pros, but the scale and speed of these problems have now become untenable for cyber functions to manage without more resources and investment.
The growing cyber skills gap illustrates the challenge. Study after study shows that across industries, cyber functions are falling behind in hiring for critical areas like AI skills and cloud security, with industry experts warning earlier this summer that the UK needs to overhaul its outdated and obsolete cyber training regimes to make up the gap.
Coull’s view, and one seemingly shared by many across the cyber sector, is that every business is now faced with more threats, both the old and frighteningly new, but with fewer resources to tackle them.
“All of these things come together to make the case that we’re going to have to change and adapt. It’s just a different world we live in now.”
So what should a modern cyber function look like in this new world?
Think Big and Move Fast
Firstly, it should take the lead from other high-growth, agile companies in leveraging a startup mindset.
For Coull, whose twenty-year-plus career has spanned established firms running large cyber and IT operations to fresh-faced scale-ups, this doesn’t mean the chaos of daily scrums or one person running around doing the job of a whole department.
It means imbuing cybersecurity with innovation, flexibility, resilience and dynamism, making cyber an accelerator, rather than a brake.
“It’s almost behavioural,” said Coull, “there are lots of different ways you can do it. There are lots of tools, and there are different ways of approaching it, but it’s really about having a team, or being part of a team that recognises change is good, and wants to move fast.”
Cybersecurity teams, Coull argued, should work with ‘purposeful disruption’, leaning into innovation and the chance to make an impact – a dramatic shift from the ‘Department of No’ reputation that IT and cyber functions are plagued by.
Already, that reputation is slowly beginning to fade. A recent study from EY found that cybersecurity contributes up to 20% more value, or a median of $36 million (£26.5m), for enterprise firms whose security teams are working to onboard new tech and products, not to mention adding value in other functions like CX and the hunt for new markets.
This doesn’t take technical know-how, but rather a shift in mindset from defence to progress, said Coull.
“Always think of vision, of where we are going, and what we are doing. Ask what the purpose of what we’re doing is, and try and articulate that so in moments of confusion you can pause and think, does that achieve our goal?”
It isn’t just about scaling cyber to meet a rising threat, it’s about scaling purpose – one that extends beyond cyber into the wider business, driven by a desire to support other teams and the resilience to adapt quickly as strategies shift, always favouring clarity over chaos.
“It’s not just about what you create at the end, it’s about the journey, and there are definitely overlaps with a positive startup mindset or startup behaviour that resonates with a high-performing team,” said Coull.
Build a Team That Delivers
Crafting these high-performing, resilient, and fast-moving cyber teams takes more than technical talent.
There are myriad paid courses, free templates and fun quizzes that claim to give security leaders an edge in finding and nurturing the right people with the right skills, but according to Coull, what a scaling cyber function really needs is simple.
“We all have to have different types of skill sets, or add people into our team that have skill sets to enhance what we have, whether that’s partners or new people,” said Coull.
Being a security leader means recognising the strengths and weaknesses in your team and working to plug the gaps. Yes, you need people in your SOC that can deal with cloud security and malware detection, but you also need people that know how to navigate compliance frameworks, communicate risk to non-technical stakeholders, and anticipate threats before they surface.
If that sounds like a difficult balance to strike, it is. Last year, research from ISC2 found that 60% of global organisations agreed that skills gaps had impacted their ability to secure the business, with 58% saying they had put their organisations at significant risk.
“We have to leverage tooling,” said Coull, “whether it’s IAM [Identity and Access Management], whether it’s data loss prevention, the cloud, or cybersecurity dedicated platforms. And they’re all to some extent leveraging AI.”
You knew it was coming.
Maximise Value from GenAI and LLMs
It’s almost impossible to talk about scaling cybersecurity as a business enabler without bringing AI into the conversation, something Coull knows all too well.
“Whether it’s product development or software reviews, we’re going to have to understand AI regs, ChatGPT, Claude, and different genAI tools.
“[Organisations] may or may not want to introduce their own bespoke models, and at very least your senior leaders are going to ask you, ‘can I use it?’, or ‘how should I use it?’, so it’s definitely a skill set we all need.”
Recommended reading
- AI Ushering in A “Digital Divide” in Cybersecurity, NCSC Warns
- Report: One in Five Small Firms Have No Cybersecurity Lead
- Are Cybersecurity Teams Safe from the AI Axe?
As Coull says, it’s not up for debate. AI is both the darling and greatest existential threat for cybersecurity teams, with the technology now leading almost all strategy and investment decisions within the cyber function.
AI-augmented threat detection and intelligence, vibe coding, and AI-assisted scripting have transformed the role of security professionals, essentially overnight, and despite the risks involved and the extra tasks it generates in policy and compliance, AI has emerged as the new standard in cyber.
However, Coull argues that firms could be using it more effectively. The future, she said, is in developing a hybrid approach. Firms should use generic, vendor AI to help them scale quickly, then custom models for differentiation, coupled with upskilled teams to make the most of these two facets combined.
“The tools are being used against us in terms of cybersecurity attacks, but they actually do have a purpose if they’re used correctly to help us do what we need to do, and help us with scaling.”
“If we can’t adopt new technology or use genAI platforms and upscale a little bit, then the only ones really getting an advantage are the adversaries, and there’s plenty of them.”
Scale or Fail
It’s not only the threat of more sophisticated attacks that means cybersecurity functions must scale.
Coull pointed out that firms are bringing in new technologies at an unprecedented rate to stay competitive, while a growing and fragmented regulatory landscape has left security teams scrambling to grow as fast as the complexity around them allows.
But organisations that treat cybersecurity as a dynamic, integrated function, one that evolves with every new product, market, and regulation, will weather the storm, while those with rigid, outdated approaches will sink.
“I’m a cybersecurity person at heart, so I understand the risks that come with it, but I do see it as a balance,” said Coull. “There’s opportunity and risk, and you need to navigate through that.”





