THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.



Jeremy Thompson is serving as the senior director of security at Highline Warren. He provides strategic leadership and operational oversight for the organization’s cyber security and physical security programs. He is responsible for safeguarding enterprise systems, data and infrastructure through the development and execution of comprehensive security strategies aligned with business objective.
Comprehensive Cybersecurity Leadership and Risk Management
My responsibilities encompass the following domains:
• Cybersecurity Governance & Risk Management: I am responsible for establishing and maintaining security policies, standards and controls in alignment with NIST CSF. I Lead risk assessments, vulnerability management and compliance initiatives to ensure regulatory and contractual obligations are met.
• Operational & Physical Security: I oversee initiatives to secure operational technology (OT) environments and physical access systems. I also look after the vendor partnerships and ensure resilience through contingency planning and testing.
• Incident Response & Resilience: I lead the development and execution of the Cybersecurity Incident Response Plan and crisis communication strategies. I coordinate cross-functional response efforts and the Operational Resiliency Committee.
• Strategic Planning & Leadership: I am responsible for long-term security strategy, budget planning and maturity improvements.
• Team Development & Engagement: I build and mentor a high-performing security team.
Integrating Risk Management into Organizational Decision-Making
Depending on the understanding and integration of risk management into decision making at the organization, different strategies need to be used. I have found that for organizations that may be risk aware (such as safety), but may not have integrated risk management practices, understanding the company’s top priorities is the essential first step. Once you understand that, you can better align risks or threats that may have a stronger effect on those top priorities. You may be able to utilize peer companies or breaches in your broader industry to help illustrate how an attack may affect your own company. Also, be sure to use ‘plain language’ scenarios and have an impactful ‘fact’ that would help illustrate the likelihood or impact of the risk. Another helpful tool would be to illustrate to the executives that cybersecurity maturity is a not pass/fail situation; maturity is a journey, and just because you have a baseline capability does not mean you have the same risk mitigation as a fully mature capability in place. Lastly, if there is no risk management framework in place in the organization, look to partner with other areas like compliance and safety to socialize and build awareness of risk management with executives.
"I have found that for organizations that may be risk aware (such as safety), but may not have integrated risk management practices, understanding the company’s top priorities is the essential first step."
Addressing Insider Threats
Many organizations are not where they should be with regard to insider risk, especially if they don’t consider themselves to be dealing with classified data, highly proprietary information like trade secrets and so on. However, insider risk is a real threat to every company. On the human side, look for things like disengagement, visible disgruntlement, changes in work habits and regular attempts to bypass established processes or controls. They may attempt to justify it by saying they are just trying to do something more efficiently, however, additional context needs to be reviewed, like sudden isolation from peers. From a cybersecurity perspective, indicators could be abnormal access attempts, irregular data transfers or some other efforts to circumvent security controls. Adding this entire context together and correlating with other HR signals are necessary to fully understand if a threat is present. Often, companies are very cautious about sharing data, say between HR and cybersecurity. Therefore, due to perceived employee privacy concerns, many times insider threat goes unnoticed until it manifests itself. Although it is a very sensitive area, the security leaders should always try to form collaborative and open communications with the HR team, in order to best mitigate insider risk.
Building Stronger and Resilient Teams
Cybersecurity fatigue can be difficult, especially with small teams which may have operational day-to-day monitoring, governance tasks, as well as projects, all demanding their time. Being a good leader means recognizing wins and success early and to ensure the team members are valued. Make sure that tedious tasks, such as weekend on-call duty, are rotated often and fairly. Also, engage with them to help bring forth ideas for simplification and automation wherever possible. That keeps them invested in the program, and that sense of ownership helps to maintain morale and emboldens them with a sense of quality in what they are doing.
A new or at least renewed emergence of the concept of anti-fragility is important. Antifragility goes beyond resilience by not only withstanding disruptions but improving because of them. Just as tabletop exercises are used to test and refine response plans, real-world incidents should be treated as opportunities to learn, adapt and strengthen processes. By encouraging small and controlled failures, decentralizing responsibility and building flexible architectures, organizations become less brittle and more adaptive. This mindset ensures security programs grow stronger under stress, turning disruption into a driver of continuous improvement.