THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.



Brian Weidner is the Senior Director of Global Information Security and Chief Information Security Officer (CISO) at A. O. Smith Corporation. He leads the company’s global cybersecurity efforts, working closely with teams across regions to manage risk and support business operations. Brian heads a skilled team of security professionals and helps ensure the organization stays protected in a fast-changing threat landscape.
AT A GLANCE:
• Business-Aligned Security Strategy – Developing cybersecurity strategies grounded in business goals, market dynamics and organizational risk tolerance.
• Risk-Informed Manufacturing Protection – Collaborating with operational leaders to implement security measures that support production while safeguarding critical systems.
• Real-World Leadership Development – Encouraging aspiring professionals to grow through mentorship, calculated risks, continuous learning and long-term vision.
Driving Security Strategy: Aligned With Industry Demands and Risk Tolerance
My approach to developing and implementing cybersecurity strategies involves several key components, which are gathered by partnering with all areas of the business. It is crucial to understand the business, its strategy and the markets it operates in. I assess the organization's risk tolerance. I identify the risk concerns of the business. I ensure compliance with legal and regulatory requirements in the regions where the business operates or plans to operate. I analyze the threat landscape and its evolution within the business context.
With this information, I can develop a strategy that balances operational risks with cyber risks. I break down my strategies by quarters, allowing us to continually improve our security control maturity while remaining agile and responsive to business needs or changes in the threat landscape. It is important to remember that tomorrow always brings new challenges, and being agile and comfortable with constant change is key.
Managing Cybersecurity Challenges: By Joint Risk Mitigation and Continuous Dialogue
One of the key functions of a CISO and cybersecurity program is to enable and protect revenue generation.
As the manufacturing environment continues to evolve, so do the threats to manufacturing organizations. Some of the primary challenges in securing manufacturing environments include implementing lean, transparent security controls that protect and shield the production line while enabling operations to continue running smoothly and ensuring operator safety.
“It is important to understand how suppliers are protecting their environments and what measures they take to safeguard any access or information provided to them. Regular follow-ups, not just during contract renegotiations, but through ongoing communications, help foster trust.”
To address these risks, I follow a similar approach to other areas of the business. I partner closely with the business leadership responsible for the area and walk the gemba with them to understand the operations and risks. Together, we develop several options for protecting the environment and assess the risk mitigation and costs associated with each. We then collaborate to create a joint strategy and focus on delivering that strategy.
Addressing Supply Chain Threats: Embedding Security and Trust into Vendor Relationships
To bolster third-party risk management, I always recommend establishing a high-trust relationship with suppliers. Transparent and honest conversations are crucial for building trust. It is important to understand how suppliers are protecting their environments and what measures they take to safeguard any access or information provided to them. Regular follow-ups, not just during contract renegotiations, but through ongoing communications, help foster trust. Additionally, ensuring that contractual agreements include balanced controls based on perceived risks is essential. This approach benefits both organizations in the event of an incident or event.
Key Advice: Have Long-Term Vision and Real-World Learning
The advice I often provide to individuals building their career in cybersecurity includes being patient, taking calculated risks, building relationships, never stopping learning and finding a good coach or mentor. In today’s on-demand world, with the additional pressures of social media stories, it is important to understand that building a career takes time. The field of cybersecurity offers numerous paths and continues to grow every day. Focus on understanding what you enjoy doing and create a plan to reach your destination. As you build your plan, consider the risks you may need to take to achieve your desired outcome and prepare as best as you can. I caution against getting stuck in analysis paralysis; commit and make decisions. Some will be good, others not so much, but learn from every opportunity. Continually stay informed about what is happening in the business world and the associated risks. Most importantly, build relationships and find a good mentor or coach. All top athletes and business people have something in common: they have had or have mentors or coaches. This gives you the opportunity to learn from others' mistakes and successes while growing yourself.