Dexcom

Why do Businesses Need Robust Cybersecurity?

As a Vice President Cyber Security at Dexcom, Paul Stapleton is responsible for the security of the entire product life cycle to ensure that their products are being designed, developed and operated securely for all of our customers. Stapleton is a veteran Cyber Security leader with an innate ability to build effective, business aligned security solutions. An accomplished security architect and executive. His passion is designing and guiding security solutions as a business enabler, a competitive differentiator, and as a partner in growing the success of the organization.

What are the challenges currently prevailing in the industry while deploying cybersecurity programs?

One of the significant challenges is recruiting the right people. Many companies struggle to find enough qualified people to do the necessary tasks. I believe every organization should have a good recruiting program in place. From hiring the most senior people to fresher, companies need a variety of experience people to work together and create the finest team possible. For instance, newer employees have ideas and skills as well as knowledge of new technologies, whereas experienced people can mentor newcomers. It gives the opportunity to learn from each other. Additionally, it’s very important to make sure that your recruiters and contracting partners can understand your hiring need. Make sure your job descriptions are concise, accurate and to the point. Provide them with preparation questions to ask candidates before arranging interviews to ensure that they possess the knowledge and expertise you require.

Another thing is making sure that you have a complete toolset deployed to cover every part of your security program. I’ve seen many companies may have deployed one, two, or three tools, but they frequently lack other essential ones. As a result, it’s important to view your security program holistically and recognize where gaps exist. Deploy the right tools to address those gaps and weaknesses with less human intervention.

There are different sets of tools available today but choosing the right tool is another challenge. Stay up to date on the most recent tools and technology available in the market. To ensure that you have the best tools available to operate effectively, someone in your team should constantly be researching the newest technology and new products, attending the appropriate conferences, and be knowledgeable of current events.

What are the strategies you use to identify an incoming threat?

We always become ready in advance for any situation. In many cases, companies keep moving with the hope that nothing bad will happen, but adequately they don’t prepare for a security incident. It is important to establish and rehearse an incident response plan so that we are as ready as possible when something does occur.

"From hiring the most senior people to fresher, companies need a variety of experience people to work together and create the finest team possible"

Our crew is trained and ready to respond to any threat in advance, thanks to the strategy and incident response plan we have in place. We’ve gotten proficient at having solid backups, forensics, and threat-hunting technologies available to immediately figure out exactly what happens. If you are unprepared, it could have a negative financial and reputational impact on your company.

What measures did you take to keep your team connected during the pandemic?

I was totally unaware but prepared before the pandemic happened, as in most part of my career, I’ve worked remotely. I have had good hands-on managing and collaborating with my global teams remotely for many years. Some of my team members found it challenging to adjust to this new normal because they enjoy socializing, hanging out with friends, and eating lunch with coworkers. To be on a good note, we used to arrange a happy hour once a week so that we could get together, speak about anything other than work, and maintain our virtual cohesion as a team. However, after a few months of working remotely together, we all got used to it. Therefore, putting some measures into place, such as video conferencing, helped us greatly to be stronger and stay in touch outside of business sessions.

We had to establish some ground rules to keep it running since, as we all know, anything new is going to be difficult. I observed a lack of respect for people’s time or for working hours. People are sending emails, texts, and meeting requests constantly because it is WFH. We need to establish some guidelines for when meetings can start and end at a reasonable hour that won’t affect someone’s personal time. Additionally, it was important to make sure people weren’t getting burned out by working more than working hours to meet all the demands.

What would be your advice for the upcoming professionals to be successful in this field?

From a product security standpoint, I would advise my colleagues in the cybersecurity industry to integrate security into every stage of the product life cycle. You can’t just think about securing a product once it’s been built. It needs to deploy security architects to work with the product teams to make sure that their design is as safe as it needs to be from day one. Since it is our responsibility to ensure that the things we design, build, and utilize are secure for our customers, any substantial vulnerability should ideally be fixed before deployment.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.