enterprisesecuritymagapac

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

CGS International Securities

Timeless Information Security Leadership

Hwee Cher Tan

Cyber Leadership Voice

Hwee Cher Tan is the Group Head of Information Security & Data Governance at CGS International Securities. With extensive expertise in cybersecurity, data governance, and risk management, She drives secure digital transformation by aligning security strategies with business objectives, regulatory requirements, and emerging technology trends.

The digital landscape has moved from the age of local data processing and closed group communications to open world computing with artificial intelligence (AI) and quantum speed in 5 decades. The advancement has exponentially expanded storage and sharing capabilities and attack surfaces.

Information Security has been around even before digitalization, but has never been able to keep abreast with it. For each digital era, it takes about a decade for defenders to reasonably understand the threats and vulnerabilities, and figure out the necessary defence and mitigation to thwart them. Implementing defence and mitigation requires proper testing, authorization, and monitoring, which are costly in terms of manpower, tools, and time. Organizations often have primary business objectives that drive the cutting of these costs. In addition, having 50 or more tools with independent management, monitoring, and reporting capabilities that cannot be integrated or correlated further slows down the effectiveness of Information Security.

Enhanced storage and sharing brought about a data explosion, which adds to attack surfaces for data breaches. Besides defending against attacks, organizations also need to maintain data quality to build and manage customer relationships. The birth of Data Governance finally formalized the need to properly manage and govern data. Each digital era is adding another level of difficulty in managing data volume, sharing, and storage across geographical borders and jurisdictions.

“With good and holistic strategy and leadership in Information Security and Data Governance, the organization can innovate securely and properly.”

Information Security and Data Governance appears to be responding to each digital era – faster in understanding challenges, faster in implementing controls, more effective in convincing budget grants, recruiting more manpower, or using more artificial intelligence. Looking closer, there are fundamentals that cut across the eras. Cyber hygiene failed 50 years ago, still fails now, and will fail again in the future if attention is always on the transforming Information Security and Data Governance, along with digital transformation. The Information Security and Data Governance stack should be designed to have holistic coverage and be applicable regardless of speed, volume, or location.

Beyond Technology and Tools

Leading Information Security and Data Governance is not about being the first person to tell the organization about a new security or data threat, to move to a new security or data measure, and to cultivate a new security or data culture. It is about understanding the organization/business strategies, identifying organization/business assets, assessing threats and risks the organization/business face/will face, formulating security and data plans and roadmaps, and building security and data stacks. It is also about balancing speed vs controls, diversification vs standardization, and risks vs costs. It is certainly about the ability to talk technical and non-technical to different levels of employees and the ability to determine the level of detail required at different sessions, so that partnership, rapport, and collaboration can be established with different business units and departments.

With good and holistic strategy and leadership in Information Security and Data Governance, the organization can innovate securely and properly.

That said, no one organization has the same risks/threats/strategy as another, even in the same industry. Risks and threats evolve, too. Leaders need to identify the underlying natures and patterns of emerging threats and challenges and update their Information Security and Data Governance strategies. After cloud computing, we are bombarded with AI, generative AI, agentic AI, Post-Quantum Cryptography (PQC), and Quantum Key Distribution (QKD) in recent years. Regulators and standard institutions are also busy publishing new requirements and guidelines. These are the new challenges that leaders should analyze to identify the timeless fundamentals, e.g., asset management, dynamic coding practices, and input validation.

Building Future Security Leaders

For someone who is new to Information Security and Data Governance, starting from fundamentals such as data, system, and network administration is always encouraged. With the basics, security and governance can be built on and studied further. Determination to trace and investigate is another trait to better understand how things can be improved. Finally, passion would see the new professional as far as the Information Security and Data Governance field is fast-moving and changing, and takes a deep interest in keeping up with it.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.