THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Jody Hawkins is a seasoned information security professional with decades of experience in the information technology landscape. As a key figure in the enterprise security arena, he is highly proficient in understanding the intricacies of information security and how it translates to various business requirements.
In an interview with Enterprise Security Magazine, Hawkins shares his insights on the latest trends and challenges emerging in the enterprise security space and ways to address the vulnerable areas of security to stay ahead of the game.
Can You Briefly Outline the Journey That Led You to Your Current Position as The Senior Director of Information Privacy and Security Compliance?
Having been in the industry for over 30 years, I have transitioned from various hands-on technical roles to become the senior director of information privacy and security compliance in the organization for which I work. After taking up the leadership position, my focus has shifted from direct involvement in technical operations to orchestrating and streamlining the organizational aspect of my teams to help us navigate in the right direction for the future.
How has The Industry Evolved to Address The Various Challenges Prevailing in The Industry Today?
The security industry has always been highly regulated, and there has been a significant shift in the approach to cybersecurity. Previously, adherence to security measures was often treated as a checkbox exercise driven by regulatory requirements. However, understanding the inherent benefits of robust security practices, leaders in the industry are now trying to adopt a holistic security model focused on data protection and risk reduction. This transition has been accelerated due to the realization of the positive impacts of these approaches.
Can you share insights on any good strategies or initiatives that can be implemented to enable the industry to comply with these digital security regulations?
Multifactor authentication and data loss prevention are two major initiatives that will help us ensure regulatory compliance and bolster our overall security poster. The increasing computational power makes traditional passwords more susceptible to compromise. Proactive authentication mechanisms have to be implemented to counter the diminishing efficiency of passwords.
"Multifactor authentication and data loss prevention are two major initiatives that will help us ensure regulatory compliance and bolster our overall security poster"
While it is important to prevent external entities from gaining unauthorized access to our systems, it is equally important to stop inadvertent data leakages by our employees. This can be done by actively addressing user behavior through targeted training and awareness programs.
How do You Foster a Culture of Awareness and Compliance Within Your Organization Regarding Information Security?
To foster a culture of awareness and compliance, we have focused on creating a security-minded workforce, ensuring that every individual, irrespective of their role, thinks and acts with a sense of security in mind. This is achieved by leveraging the capabilities of our awareness ambassadors, who are leaders within each team who champion security practices. They play a pivotal role in creating a security culture in their areas, utilizing their influence to impart information effectively.
Other than these leaders, anyone who wants to volunteer for these campaigns receives in-depth training on the safety protocols that need to be maintained to stay protected from hackers and scammers.
We also conduct phishing campaigns to stimulate real-world threats from scammers. We deliberately create emails that mimic potential phishing attempts to encourage our employees to be vigilant. These practices help us identify vulnerable areas that need additional attention and also serve as an exercise for our talents to prepare for real situations.
How do you ensure security amid the recent shift in the workforce’s desire for more remote working environments?
The transition to a work-from-home environment has contributed to the challenge of securing key fob access to physical office spaces. This prompted us to intensify our awareness campaigns by adopting various measures, such as actively participating in events like security awareness weeks and months.
Recognizing the limitations of communication channels, we have opted for a variety of strategies, like incorporating screen lock reminders, emails, and intranet messages that pop up on the employee screens to remind them of the importance of security. To disseminate information in manageable portions, we also engage employees with interactive games like word searches and crossword puzzles, ensuring that the learning process remains enjoyable and effective.
What is Your Sage Advice to Your Peers and Upcoming Professionals in This Changing Space, Especially with Increased Remote Work and Cloud-Based Services?
Continuously educating and configuring various security solutions is crucial in the cloud space. Any tools are only good for their coverage and utilization. No matter how advanced it can be, effectively combating potential threats requires knowledgeable individuals to wield it.
Regardless of individual strengths, a comprehensive approach to establishing a well-rounded strategy is imperative for a robust security program. Security is everyone’s responsibility, and it is essential to maintain ongoing attention and adjustments in response to the evolving industry solutions to stay ahead of the game.