This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Cybersecurity as a Business Opportunity – a Success Story Through Pain and Failure

Download resources

About this session

Martin Lemay, CISO of Devolutions, recounts how he built the company's security programme from scratch after joining in 2018, and why his first ninety days went badly. Fresh from consulting, he dumped red-flagged pentest reports on developers, pushed a SIEM he had no analysts to run, flooded IT with patch requests, blamed SDLC practices and presented NIST CSF charts; the CEO answered with a comic strip and a quiet warning that graphs are not the business. The turning point was a remark that a security team contributing to the product could grow to fifteen people. Lemay reframes security as a business opportunity using a Jim Collins flywheel: build expertise, identify risks and opportunities, contribute to solutions, earn trust. Concrete examples include an identity programme that cut access provisioning from three days to an hour, in-house fixing of low and medium bugs, reusable crypto libraries, updating marketing's security vocabulary and answering customer compliance questionnaires. Four years on, the security budget grows about 29 percent a year, at 3.7 percent of revenue, across GovSec, DevSec, red team and OpSec functions.

Cybersecurity is often seen as a necessary evil or pain. Engaging into a cyber security program requires money, highly specialized workforce, technology and support from many stakeholders. The overall total cost just keeps growing and growing every year to reduce this critical risk. New security solutions and processes tend to slow down productivity and impact business velocity. However, when seen under the lens of "opportunity", it can also uncover new sources of income, improve marketing reach, enable stronger competitive advantage, enrich business culture and more. Great returns can be realized if approached with a different eye. This talk aims at tackling the bright side of cyber security investment by exploring the good and the bad we experienced as an SMB. We hope that at the light of this talk, refreshing new discussions might fire up in your own organization and will, perhaps, result in fresh, new, innovative and "profitable" cyber security initiatives.

Key takeaways

  • Do not open with a pile of red findings and frameworks; a new security lead who only adds work to developers and IT becomes the necessary evil nobody wants in the room.
  • Fixing bugs is a quality expectation, not added value; find ways the security team can contribute to features, productivity and customer trust.
  • Use in-house security expertise to solve business problems end to end, such as an identity process that grants approved access within an hour with full traceability.
  • Turn compliance into sales enablement by building processes to answer customer security questionnaires and certification requests.
  • Trust is built actively and transparently over years and lost in seconds; show wins, own failures and take calculated risks.

Speakers

Martin Lemay
Martin Lemay
Chief Security Officer · Devolutions
With nearly 15 years of experience in the IT and cybersecurity field, Martin Lemay has successfully bridged the gap between technical expertise and strategic leadership. Starting from a robust technical foundation, Martin has seamlessly transitioned… Read moreRead less

With nearly 15 years of experience in the IT and cybersecurity field, Martin Lemay has successfully bridged the gap between technical expertise and strategic leadership. Starting from a robust technical foundation, Martin has seamlessly transitioned into project management and executive roles, where he has designed, planned, implemented, and tracked comprehensive cybersecurity programs from the ground up. His initiatives are meticulously aligned with industry-leading standards such as ISO/IEC 27001, NIST CSF, CIS Controls, and CyberSecure Canada. Martin’s deep technical knowledge, combined with his executive experience, uniquely positions him to communicate and advocate for cybersecurity initiatives across diverse audiences. Whether addressing technical teams, executive boards, or stakeholders with varying levels of expertise, Martin excels at translating complex cybersecurity concepts into actionable strategies, ensuring that security is understood and prioritized at all levels of the organization.

Resources

Tags

More from GoSec 2022

Also from Martin Lemay

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.