THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


How I Lead: Grounded Judgment, Strong Teams
Scott Shaffer
Starting my career as an intern and moving through the ranks over a near 20-year career has shaped how I approach information security more than anything else. Being hands on early, working tickets, supporting users and seeing how systems behave in real time gave me a perspective that security cannot operate alone. Early exposure to fraud cases, account compromises and operational disruptions reinforced that speed, clarity and sound decision making matter just as much as technical controls.
As I advanced into roles with greater responsibility, managing incident response and coordinating across departments taught me that communication is often the difference between a contained incident and a widespread issue. You quickly realize that security is a collective effort requiring alignment across IT, operations, fraud and other organizational leadership.
It has also shaped how I view team dynamics. Supporting professional growth, building confidence and empowering others to take ownership strengthens an organization’s security posture far more than any single tool or control.
These experiences have led me to a practical and risk focused approach: concentrate on real threats, prioritize effectively, communicate clearly and cultivate teams that can operate independently and confidently.
Cyber Risk Today: Beyond Systems, Into People
The threat landscape is evolving faster than ever. One of the biggest challenges is the convergence of fraud and cybersecurity.
Attackers are no longer just exploiting systems. They are targeting people through social engineering, phishing and credential theft, which makes traditional perimeter defenses less effective.
A significant part of this reality is that the human element itself has become one of the largest risks. Even the strongest controls can be bypassed if an employee is misled, rushed, distracted, or simply trying to be helpful. Human behavior introduces variables that technology alone cannot fully eliminate. Training and awareness help, but they must be continuous and adaptive because attackers are constantly refining their tactics to exploit human trust, curiosity and emotion.
“Security should support the business, not compete withit. When controls are designed with the user in mind, they guide safe behavior rather than create frustration or slowdowns. The objective is to make sure people can perform their responsibilities confidently and securely.”
Third party and vendor risk is another major concern. Financial institutions depend on a wide range of service providers and each one introduces potential vulnerabilities. Even if your internal environment is strong, weaknesses in a vendor can still expose your organization. So it is just as important to review and manage these vendors.
What Balance Means: Protection without Operational Drag
Balancing security with usability starts with understanding risk. Not every system, transaction, or user requires the same level of control. A risk-based approach allows you to apply stronger measures where they matter most, such as high value transactions or privileged access, while keeping lower risk activities as seamless as possible.
A core principle is enabling employees to do their jobs without unnecessary barriers, but doing so securely. Security should support the business, not compete with it. When controls are designed with the user in mind, they guide safe behavior rather than create frustration or slowdowns. The objective is to make sure people can perform their responsibilities confidently and securely.
User education also plays an important role. When employees understand why certain controls exist, they are more likely to follow them and less likely to look for workarounds. At the same time, feedback from users should be taken seriously. If a control is consistently causing issues, it may need to be adjusted.
Ultimately, the goal is not to eliminate risk entirely. That is unrealistic. The goal is to manage and mitigate it in a way that supports the business rather than slowing it down, ensuring users can accomplish their work effectively while maintaining strong security.
Where Security Is Headed: Identity, Speed and Intelligence
Obviously, the big buzz word is AI! Artificial intelligence is one of the most significant trends impacting both attackers and defenders. Threat actors are using AI to create more convincing phishing campaigns and automate attacks, while financial institutions are leveraging it to improve detection, response and fraud prevention.
Identity security has become the new perimeter. With the rise of cloud computing, mobile access and remote work, traditional network boundaries are less relevant. This has driven increased adoption of Zero Trust principles, where access is continuously verified rather than assumed.
Real time monitoring and response capabilities are also becoming essential. It is important to invest heavily in tools and processes that allow them to detect and respond to threats quickly.
What I’d Advise: Stay Open, Aware and Evolve
Keep your options open early in your career. Cybersecurity is a broad field that touches every part of an organization, so gaining exposure to different areas, including network security, incident response, risk management and fraud, will make you more well-rounded.
Hands on experience is critical. Internships, entry level roles and practical labs provide real world understanding and help build confidence in applying what you learn. Certifications are a great way to strengthen your knowledge, demonstrate commitment and open doors to new opportunities, especially when paired with practical experience.
Understanding the business is just as important as understanding the technology. The most effective leaders can translate technical risk into business impact and help drive informed decisions.
Building relationships is another key factor. Cybersecurity requires collaboration across multiple teams, so strong communication and the ability to work with others will set you apart.
Finally, stay adaptable. The field is constantly changing and continuous learning is essential. The professionals who succeed long term are those who are willing to evolve with the landscape and take on new challenges.