Living under scrutiny creates a problem walls do not solve: the value walks out on its own. What is needed is protection no commercial product provides, and someone reachable when something happens.
I am appointed to boards as the security expert supporting the chief executive, because around that table an independent voice on this is usually missing. Responsibility for information security now falls personally on the leadership: it is no longer reputation or money alone.
Security is not a product you install, it is something people do or fail to do. I work with senior leadership so they stop delegating it and start deciding. Without technical slides and without scaremongering.
I am a co-founder and chief technology officer of CyberGrant, and the patents in the record are mine: on technical direction I am not impartial, and I say so. On the vendor I am: when I advise, my own technology is not among the options.
Do you know the one thing almost nobody can do?Keep a secret.
The best work I have done is the work nobody ever heard about. These cases are real, told without the details that would identify anyone.
Personal images, years old, had reappeared across dozens of sites copying from one another. No attack: they were simply there. Every time one came down, three more appeared elsewhere. It took patience, the right tools and careful coordination to secure removals, contain the spread and starve the material of oxygen until it stopped circulating.
A pirate site was publishing tracks stolen somewhere along the production chain, online before the official release, with enormous damage to people who had worked on them for months. The work was to find where the material was leaving, stop the spread and close the tap.
A wave that appeared to have a life of its own and showed no sign of stopping. Here the job is not to build barriers: it is to understand how the machinery works, put out the individual fires, and give the person back some control over something that detonated around them.