Site navigation

Scot-Secure West | Proactive Security Made Simple and Human

Tom Quinn

,

simplifying cybersecurity
Celine Pypaert, security transformation manager at Johnson Matthey, explores how to humanise cybersecurity and break down security processes to make them more relatable and effective for businesses.

Speaking to a packed audience at this year’s opening session of Scot-Secure West 2024, Celine Pypaert gave insight into why security professionals should spend time learning how to communicate more effectively with those outside the cybersecurity realm, and the importance of making security as simple to understand as possible.

In her work as a security transformation lead at Johnson Matthey, a global sustainable technologies company, Pypaert delivers new security projects to drive cyber-strategy aligned business goals, with a holistic, proactive, sustainable, and strategic approach that helps empower business, improve people’s experience, and drive collaboration. 

Anyone that works in the industry, said Pypaert, knows that cybersecurity is multi-layered and complex, making it hard to convey its importance in an comprehensive way for ‘non-technical people’, which often includes those at the executive level.

But, according to Pypaert, security experts should strive to help executives and leaders make a connection between proactive, resilient security measures and why it matters for the health of a business.

Given the amount of money involved for what seems to outsiders like little return, asking for investments into security can become frustrating when it feels like those above don’t grasp how vital it is to keep defences intact.

“As a security function, or security team, we tend to be at the mercy of the wider company culture: the markets, IT budgets, hierarchical organisation structures, and paradoxically, we’re asked to be more secure while saving more money,” said Pypaert.

“Everybody cares about security when it affects them. Nobody likes to get scammed, no one wants their identity stolen. Security matters to us more than we realise, but something that I’ve found in my journey in security is that that message is not always translated.”

That’s why, argued Pypaert, simply monitoring systems and keeping up with the latest threats isn’t enough. It’s crucial for security professionals to put themselves in other’s shoes, find better ways to communicate, and learn what’s important to others in an organisation to make security align with other business aims.

Cyber risk equals business risk

“Boards speak differently about risk than we do in cyber,” said Pypaert, “and yet, cyber-risks are an integral part and are linked to the overall business risk.”

Rather than trying to force leadership to see things differently, those working in cybersecurity should instead find ways to make better security measures fundamental to the organisation.

Reading business reports can be a good place to start. Those can help explain the general health of the organisation, explore the company’s long-term business goals, and highlight other risks to the enterprise outside of cybersecurity.

That, Pypaert suggested, will help security professionals align cyber-strategy to wider organisational strategies, giving agency and vitality to a function which is often considered a drain on resources, albeit an essential one.  

Asking those outside security for their opinion can also go a long way. That might seem counterintuitive, as ‘non-security people’ generally don’t have the background or knowledge to effectively administer cyber-resources, but involving them in those decisions can have major benefits.

Pypaert pointed to Accenture’s State of Cybersecurity report from last year, which found that organisations that closely align their cybersecurity programmes to business objectives are 18% more likely to increase their ability to drive revenue growth, increase market share and improve customer satisfaction, trust and employee productivity.

“I recently heard a CEO and board member say that in 10 years of working on boards, they had never once been asked by someone from the security team, what is the most critical asset in your view that needs protecting?” said Pypaert.  

Tackling that lack of communication and simplifying security can get everyone on the same page, potentially loosening budgets for critical improvements and maintenance that otherwise might misunderstood, or even wilfully resisted.

Even with agreement about the need for investment, however, cybersecurity professionals still often have an uphill battle when it comes to conveying the importance of being proactive, and staying ahead of ever more inventive threats.   

Can security be more than a Sisyphean game of catch-up?

A big problem in many organisations, according to Pypaert, is that security systems that aren’t broken won’t be fixed, speaking to a reactive culture of diminishing security returns. 

This malaise often arises due to things like budget constraints, pressure from leadership, or a lack of resources. 

This means that when flaws are inevitably exposed, there’s a huge risk of more downtime and more money spent trying to fix a problem that could have been dealt with a lot sooner.

It doesn’t help that the consequences of being unprepared can sometimes be little understood. Patching up old systems can be seen as a waste of time and money, and it’s down to security professionals to help executives understand the stakes.

Some of the biggest cyber-attacks we know about happened because of flaws in outdated systems, as Pypaert pointed out. Ageing IT infrastructure and legacy systems contributed to recent ransomware attacks on the NHS and the British Library, impacting thousands and costing tens of millions.

That’s why being proactive, working to anticipate and plan before systems reach the end of life stage, as well as effectively communicating that to leadership, is so vital.

“As we all know, it’s not a matter of ‘if’ it’s a matter of ‘when’,” said Pypaert. “It’s about preparedness, and it’s about having an equal balance, not just focusing on the detective response, not just focusing on the tools and knowing about things after they happen, but also on what you can do strategically and tactically. What can you do to be more prepared?”

The best option is to be proactive. That can mean hunting out decrepit legacy systems, and looking for flaws in otherwise functioning structures, then taking that evidence to asset owners before upgrades become critical or an attack happens.

Making cybersecurity a relatable goal

“Everybody in organisations and especially leaders, should understand what their role in cybersecurity is,” argued Pypaert. “We each play parts in security, and getting that message across is really key.”

To make the case for robust cybersecurity, it’s important to emphasise how it impacts users and others within an organisation when it fails. That means simplifying and explaining in wider business terms why security matters.

“Technical terms don’t really mean anything to non-technical people,” said Pypaert, “but when you say, if we were hit by ransomware, it might take down the whole company, and our customers won’t even be able to email us, we won’t be able to ship products, we would lose money, they’ll get a better understanding.” 

Linking security with user experience, with revenue, even with keeping the lights on, can de-silo security measures and help executives better understand its implications, smoothing the way for necessary, and ever bigger, investment. 


Recommended reading


Unlocking innovation

Those proactive investments can have positive effects outside of simply keeping cyber-defences intact.

“By being more secure, by having data security, data governance, by knowing your IP, protecting your IP in a technical way, you can actually help unlock motivation, and be less reactive,” said Pypaert.

Positioning security as a business enabler doesn’t just improve defences, it can improve user experience too. As an example, Pypaert pointed out that keeping track of passwords and using password managers can be inconvenient, sometimes irritating, and that introducing more user friendly alternatives, like YubiKeys, can reduce human-error and lessen frustrations. 

Humanising security protocols in such ways can result in serious benefits for an organisation. That can mean anything from a smoother experience for third-party access, reducing friction among departments, or even improvements for in-house collaboration.

As an example, Pypaert said that unlocking the full potential of genAI requires security processes that meet business needs but also understands the way people want to work. That means ensuring better data security, and having data governance already in place so that AI becomes an asset rather than a threat.

Cybersecurity should no longer be viewed as a technical necessity but as a crucial business enabler, and by breaking down complex security processes to communicate their significance in clear, business terms, professionals can better engage with leadership.

It’s not just about budgets, but about fostering a culture where security is seen as integral to the company’s success, rather than just a cost centre.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data