DigiTalks: Future-Proofing Organizations against any threat with Sean D. Mack
Dive into the intricate world of cybersecurity in the first episode of the new series IT Insights: Inspire, Improve, Innovate recorded in our Center of Excellence in North Dallas. In this eye-opening discussion, Adam Gaca, VP of Cloud in Future Processing engages in a candid conversation with Sean D. Mack, Author, Speaker, and former CIO and CISO of Wiley. They unravel the true state of cybersecurity at American companies and uncover strategies to inspire innovation while minimizing operational risks.
Adam Gaca: IT Insights: Inspire, improve, and innovate. Join the expert discussions by the Centre of Excellence in North Texas on the hottest tech insights and boost your ROI. Hello everyone, welcome to the very first episode recorded in our Centre of Excellence based in Dallas, Texas. I am Adam Gaca, and I’m privileged to host tonight’s IT Insights episode with three values in mind: inspire, innovate, and improve. Our guest today is a CIO 100 award recipient, the author of The DevSecOps Playbook, an experienced C-level transformational leader with vast knowledge in IT roles such as development, cyber security, DevOps, and architecture – Sean Mack. Pleasure to have you, Sean.
Sean Mack: Great to be here.
Adam Gaca: So, Sean, 2024 has arrived, and we have definitely had a tough period with many challenges and risks we couldn’t predict that impacted the global market and the IT industry. We have seen situations like COVID, remote work, supply chain interruptions, war, and deep fakes. Looking back, what would be your top three insights or takeaways?
Sean Mack: It is a great question. First of all, thanks for having me here today in Dallas. We have been through an unprecedented amount of change over the past three to four years. To be an innovative leader, we must be willing to innovate and change ourselves. One of the biggest shifts for me personally has been the shift in thinking regarding remote work. We learned very quickly that we could work remotely; for instance, my previous organisation moved over 10,000 employees to work from home in just a weekend, and contrary to fears, it did not fall apart.
Now, the question is no longer “can you work from home?” but rather “what do you lose by not being together?” While productivity numbers often remained the same or higher at home, I use the analogy of a basketball team: players can practice jump shots alone and hit 100%, but they won’t function well as a team without being together. We need to continue re-evaluating the value of coming together.
My second insight is that crisis accelerates transformation. Challenges like war or disruptive technology act as existential crises that speed up change. Finally, regarding cyber security, threats are currently outpacing our response. While budgets are generally being maintained, the “bad guys” are investing far more quickly, and the threat landscape is growing by leaps and bounds.
Adam Gaca: That is an inspiring answer. We know we need to outsmart and outspeed our enemies, but how would you rate the cyber security pressure on companies in the States?
Sean Mack: I’d say it’s bad. It is complex because it is about matching readiness with risk tolerance and business requirements. For example, a financial institution needs the highest security, while a startup might prioritise speed to market over eliminating 100% of risk. Generally, the threat landscape is expanding faster than company responses. Cyber crime is now an $8 to $11 trillion industry, making it effectively the third-largest economy in the world behind the US and China. These are no longer just “hackers in basements” but well-funded corporate-like organisations and nation-states. Yet, most cyber security budgets remain stagnant.
Adam Gaca: I couldn’t agree more. We see increased budgeting for things like machine learning and AI, but not necessarily for the security of those data sets. How would you recommend we improve the cyber security posture in these organisations?
Sean Mack: I have a passion for DevSecOps because it allows for the implementation of security without huge costs or slowing down time to market. It’s about making security part of the culture rather than an afterthought. If you take the old approach, your budget will only grow linearly with your risk profile, but DevSecOps provides economies of scale.
Adam Gaca: The harsh reality is that security is often perceived as a nuisance or a necessary cost. How do you change that attitude without suffering a major incident?
Sean Mack: Sadly, incidents often drive change, but cultural change is the most difficult aspect—which is why I focus on people in my book. Support must come from both the top and the bottom: from the board and CEO down to the passionate engineers on the ground. You must build it into how you work by setting shared goals that include profitability alongside resiliency and security.
Furthermore, you need ongoing measurement—weekly, monthly, and quarterly metrics—to ensure a continuous conversation about improvement. We’ve used “cyber security champions”—members of business teams who are also honorary security team members—to embed that culture. Finally, you must communicate constantly through various channels like fishing tests and quarterly training.
Adam Gaca: So the saying “culture eats strategy for breakfast” is very much on point here.
Sean Mack: Absolutely.
Adam Gaca: Looking towards innovation, what will be the biggest innovation or threat in the cyber security space in the coming year?
Sean Mack: I’m going to say AI. It is fundamentally reshaping business, but we are already seeing its impact in cyber security on both the threat and response sides. On the threat side, we see better phishing emails and deep fakes, including AI-generated video messages of CEOs asking for password resets. On the response side, AI and machine learning are crucial for analysing data, detecting anomalies in communication, and empowering junior analysts to respond more effectively.
We are moving toward a future of “AI battling AI”, especially as threat actors use it for auto-adapting malware. We must ensure ethics and intent alignment in our responses. Ultimately, we also need to address the economics of cyber crime; as long as it remains a profitable multi-trillion dollar industry, it will continue to expand.
Adam Gaca: You don’t make the cyber security job any easier! We need to prepare for all variants while remembering that humans remain the weakest link. Thank you very much for your time and expertise. To our viewers, I hope you feel inspired. Let’s go improve and innovate. Visit us at ITinsights.tech for more podcasts and events.