THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Mark Leary, VP & CISO, Regeneron PharmaceuticalsAs a cybersecurity expert and technology business leader, Mark Leary has held successive positions in various Fortune 200 firms. Over the years, he delivered robust cybersecurity solutions to the federal government as well as the state clients. As a result, he gained vast experience in defense, aerospace, business process outsourcing, biotechnology, and life sciences.
In an interview with CIOReview, Mark explains the challenges CISOs face in the ever-changing cybersecurity landscape and how they can cope with them.
Can you talk about your journey over the years and how you landed at Regeneron Pharmaceuticals? What are your key roles and responsibilities there?
I worked for over two decades in the government sector, where I was initially part of the Armed Service and then held several civilian positions. I have spent most of my career with the United States Intelligence Community.
About midyear through my military career, I decided to join the reserves and landedin a job at Northrop Grumman, a leading aerospace and defense company. There, I worked mostly within the intelligence community, focusing on issues surrounding cybersecurity's offensive and defensive sides.
My role was mainly customer-facing, and I was specializing in delivering cybersecurity solutions to government clients. A few years later, I decided to do an internal rotation and took a position in the Internal Security Department, reporting directly to the then CISO. I enjoyed that role and soon rose to the leadership position.
After Northrop Grumman, I served as the global CISO of Xerox Corporation for about five years. I was responsible for revamping the company's document management technologies and business process outsourcing sector.
After Xerox, I joined Regeneron Pharmaceuticals, a biotechnology firm, as their first global CISO. The company has invented many life-transforming medicines that help patients fight ailments like eye disease, cancer, cardiovascular diseases, and infectious diseases.
What are the latest updates on the cybersecuritymarket? What, according to you, are some of the major pain points that organizations face?
While some CISOs are cybersecurity professionals with deep industry knowledge to translate their business requirements into cybersecurity strategies, many others think like business leaders but hold technical expertise in the field. They must think about information security's business side and translate the business requirements accordingly. The most effective CISOs are the ones that have their feet in either one of the two positions.
CISOs today face two key challenges. First, their threat and geopolitical landscape change as their organizations enter new markets while confronting a plethora of new business and regulatory compliance pressures. A CISO must keep abreast of all these aspects that plague their security posture and understand the relevance of their position in protecting the company.
On the technology side, many organizations in the market are adopting borderless business models where anyone in a company's staff can access its systems and data using any device from anywhere. Therefore, CISOs need to embrace the zero-trust approach in their organization to protect their business from the ever-changing threat landscape. Additionally, many enterprises are migrating their business to the cloud. Though it is an economical step with several efficiencies, CISOs have to consider the various security implications of cloud migration.
The second set of challenges stems from the environment outside the company. For example, as the Russia-Ukraine war rages on, some spillover can occur, like a new threat to the U.S. healthcare and life sciences or any other industry.
As evident from the borderless business models, cloud migration, and the geopolitical landscape, the IT industry is changing at a rapid pace. Consequently, security professionals need to align ourselves and our policies according to the changing tides.
What are some of the trends that have emerged lately in the market that help tackle these pain points?
Many technology providers still offer on-premise security solutions that are tied to on-prem data centers, workstations, and servers. Unfortunately, they are obsolete and unfit for modern-day business needs. Be it a change in business model, new threats, or new pressures; we think everything is being driven to the cloud. As a company, we must align ourselves to the new winds of change.
Can you give our readers an overview of some of the latest project initiatives you are working on?
One of the areas where we're placing a lot of effort is around automation and the use of artificial intelligence and machine learning. For example, we leverage ServiceNow to manage governance, risk, and compliance (GRC), security operations, and business continuity disaster recovery. After integrating the platform with some other tools and adding automated intelligence, we were able to move faster through standard, repeatable workflow and processes.
“The IT industry is evolving at a rapid pace. Consequently, we as security professionals need to align ourselves and our policies according to the changing tides”
We combined the new ServiceNow program with our SEIM big data platform Splunk to see the business operation, identify an alert, and automatically ticket ServiceNow. Additionally, using robotic process automation, we've allowed our staff to have bots sit on the ServiceNow queues to address tickets and resolve security incidents.
What would your piece of advice be for the upcoming professionals in this field?
Anyone aspiring to the next level needs to improve their skills constantly. They must be aware of different technologies, business methods, and models in their field. Then, it will suffice to look at what's around them, how it applies to them, and how their ideas and innovations can bring value to an organization.
My advice to my peers and cybersecurity aspirants is not to compete for your next job; compete for the one afterward. That will truly distinguish a high-performing professional. One can always improve them for the next job, but those who look ahead to where they want to be, can upscale their knowledge and experience exponentially.