enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Alera Group

Security as Strategy: Leading Cyber Risk in a Distributed Enterprise

Matthew Mudry

Security Strategy Champion

From Practitioner to a Strategic Leader

Leading security programs across insurance, healthcare, and energy trading has shaped my approach to be highly practical and business-aligned. At Alera Group, the integration of over 100 firms has reinforced the importance of scalable, repeatable security frameworks that can adapt to different levels of maturity. Earlier roles at HomeServe and CareCentrix emphasized regulatory rigor, while building a global program at Castleton taught me how to embed security into fast-moving, high-risk environments. A key inflection point in my career was learning from strong, trusted mentors. Their guidance helped shift my mindset from being purely a hands-on security practitioner and engineer to operating as a strategic leader. They pushed me to think beyond technical execution and focus on outcomes, risk alignment, and delivering business value. Together, these experiences shaped my focus on resilience, integration, and delivering measurable, business-driven security outcomes.

Balancing Agility with Security

Security should be an enabler, not a blocker. I focus on risk-based decision making, aligning controls to what matters most to the business. Standardizing core controls, leveraging automation, and embedding security early in processes allows teams to move quickly without increasing risk. It is about creating guardrails that are clear and consistent, so the business can innovate confidently within them.

“Security should be an enabler, not a blocker. It is about creating guardrails that are clear and consistent, so the business can innovate confidently within them.”

That strategic clarity, however, must be grounded in an honest assessment of the threat landscape. Ransomware, identity-based attacks, third-party risk, and the misuse of AI are among the most significant threats today. Leaders should prioritize identity and access management, endpoint detection and response, and strong vendor risk programs. Equally important is focusing on visibility and response capabilities. You cannot protect what you cannot see, and you cannot respond to what you do not understand.

Culture, Leadership, and the Evolving CISO

Making security awareness a part of culture starts with making security relevant to people’s day-to-day roles. I focus on clear, practical communication and tying security behaviors to real-world impact. Partnering closely with HR, Legal, and leadership helps reinforce expectations, while consistent training, phishing simulations, and policy alignment ensure accountability. Culture is built when security becomes part of how people work, not something separate from it.

The responsibility of driving that culture ultimately falls on a role that has itself undergone profound transformation. The role of the CISO has shifted from technical oversight to strategic business leadership. Today, it is about translating cyber risk into business risk, influencing executive decisions, and enabling growth while protecting the organization. CISOs are expected to be communicators, risk managers, and business partners, not just security experts. The focus is no longer just on protection, but on resilience and ensuring the organization can operate through disruption.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.