enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Academy Sports + Outdoors

Navigating Cybersecurity and Business Risk

Mark Alvarado, Executive Director of IT Security & Compliance at Academy Sports + Outdoors, has over 21 years of IT experience, including 12 years specializing in cybersecurity. His expertise includes digital risk management, policy development, IT compliance and regulatory strategy. He is skilled at identifying digital threats and implementing controls to protect critical infrastructure. His leadership helps align cybersecurity with business goals, securing the organization’s digital assets in a complex threat landscape.

Recognizing Mark Alvarado’s diverse background spanning manufacturing, IT leadership and cybersecurity, this exclusive interview provides critical insights into the evolving role of cybersecurity in business, the financial and technological challenges organizations face today, and the strategies needed to build resilient, law-aligned security programs in an increasingly connected world.

What often gets overlooked in my IT career path is my first 11 years in high-speed manufacturing, working with companies like Pepsi and Coca-Cola. At the time, I thought switching industries was a complete shift when I entered IT, but that experience gave me a strong foundation. I started in IT at 32, not by plan but by necessity. I had just got married, lost my job and was in the middle of buying a house, worried the mortgage wouldn’t go through without valid employment.

My brother-in-law ran an IT consulting firm and hired me as a project manager and business analyst. I was working as a quality control manager at Shasta Beverages and with few options, I accepted. That role ended up being pivotal. I worked with K–12 school districts like KatyISD, gaining exposure to IT consulting and public-sector environments.

Returning to School, Rebuilding the Path

When the 2008 financial crisis hit and contracts dried up, I took it as a signal: it was time to formalize my path. What followed was a decade-long journey of academic and professional growth— earning 22 IT certifications, a BS in IT, a Master’s in Cybersecurity, an MBA in IT Management, and most recently, a Master’s in Cyber Law. Each step built not only technical proficiency, but strategic insight and leadership capability.

“To secure funding, you have to be a student, not just a technologist, of the business”

I’ve worked across industries—oil and gas, legal, and retail— in roles ranging from business analyst to director. That range refined both my technical skills and leadership mindset. I’m academically and professionally trained as a hacker but also manage a full cyber program. The blend of technical depth and business acumen allows me to build security programs that are practical, measurable, and aligned with the organization’s goals.

Cybersecurity’s Real Challenge: Business Alignment

While technical expertise is critical, the real challenge in cybersecurity is aligning with the business. It’s not just about stopping hackers. It’s about understanding how a business operates, what matters most, and how to protect those assets in a way that doesn’t hinder growth. You can’t secure what you don’t understand.

Funding is often the biggest barrier. “Cyber criminals are profit driven. So are businesses. If the CISO can’t clearly articulate risk in terms, leadership understands, funding won’t follow. That’s why understanding finance, regulation and legal framework is essential.

In an increasingly connected world—where every device has a camera or microphone and every app can be a threat vector – I believe that security must be deeply integrated. I strongly believe in employing a layered defense-in-depth model, guided by zerotrust principles and interwoven technologies that communicate and respond as one. Think of it like fabric—the strength comes from the threads working together.

Modern CISO must be part architect, part strategist, and part translator—bridging technology, risk, and business. You wouldn’t build a house without a blueprint. The same applies to cybersecurity. As CISOs, we help create that blueprint and ensure it's built to last.

For those seeking to grow in this field, I would advise them to be more than a technologist—be a student of the business Executives generally want to do the right thing. It’s up to us to show them why and how. That’s how you build a cybersecurity program that earns trust, gets funded, and keeps bad actors from stealing critical business data.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.