THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.



With over two decades of expertise in cybersecurity, Jonathan Sinclair is Head of Cybersecurity at Roche. He began his career as a developer, specializing in enterprise application integration, which provided him with valuable insights into the complexities of connecting large enterprises and managing everything from logistics to product delivery. Sinclair transitioned into risk assessments for emerging technologies and moved to a managed security service provider, where he led network migrations and security operations. He later headed Novartis' information security assessment service as well. His passion for advancing security practices and his deep expertise in both software and hardware security empower him to drive cuttingedge solutions in an ever-evolving threat landscape.
In an interview with Enterprise Security Magazine Europe, Sinclair highlights the need for organizations to integrate cybersecurity into their operations and align it with business goals to mitigate risks and demonstrate value.
Cybersecurity is The Market Differentiator
Cybersecurity is a key component of business operations. Compliance adds a layer of complexity to operate in a highly regulated environment, as it requires organizations to adhere to regulatory requirements. There is a growing emphasis from regulatory bodies and countries on integrating cybersecurity into these regulations.
While compliance is crucial, the true value lies in integrating cybersecurity into development and operations. Today, organizations must showcase a strong cybersecurity posture not just to regulators but also to boards, shareholders, and executives—making cybersecurity a key market differentiator. This becomes even more critical in industries like pharmaceuticals, where trust is paramount.
Maintaining patient’s trust is non-negotiable when you are a global pharmaceutical organization dedicated to saving lives. A company's cybersecurity posture serves as a measure of its trust. If an organization’s security is compromised frequently, it raises questions about the integrity of the drugs they produce.
Cybersecurity ensures that the organization is not only safeguarding sensitive data but also reinforcing its credibility and reliability among customers. In this sense, cybersecurity enables organizations to demonstrate their commitment to quality, safety and trust, ultimately strengthening the bond between the business and its stakeholders.
Don’t Trust Anyone, Don’t Trust Network
We believe identity and access management (IAM) is critical to the overall security posture. Our approach involves mapping job functions, increasing the checks we perform on new employees and ensuring that the appropriate roles and responsibilities are assigned to those job functions.
“A Company's Cybersecurity Posture Serves As A Measure Of Its Trust. If An Organization’s Security Is Compromised Frequently, It Raises Questions About The Integrity Of The Drugs They Produce.”
We have adopted a ‘don’t trust anyone, don’t trust the network’ mindset, which forms the foundation of our IAM strategy. We have also implemented segmentation and other compensating controls to mitigate risks. We are actively implementing zero trust throughout the organization. While zero trust as a concept has been around for a while, it poses significant challenges for larger organizations due to complexities like legacy systems, multiple directory environments and the sheer scale of operations. In Roche, with 200,000+ employees and multiple directory systems, keeping everything synchronized is a huge task.
In addition, role-based access reviews, endpoint controls for device validation and managing Bring Your Own Device (BYOD) policies add further layers of complexity. However, our focus remains on user identity. We are building the mechanisms needed to ensure that identity stays at the core of our security strategy.
Aligning Cybersecurity with Business Strategy
Technical expertise is vital for building a strong team. People skilled in incident response, forensic investigations and malware analysis are crucial for navigating the evolving threat landscape.
Business leaders focus on expanding market share, improving efficiency and adapting to demand rather than the intricacies of firewalls or segmentation. This creates a gap between technical teams and business objectives, making it crucial to find individuals who can translate cybersecurity risks into strategic value. Cybersecurity champions at various sites help bridge this gap, but hiring for such roles remains challenging.
Risk professionals excel at analyzing strategic risks, particularly in new markets. However, they can sometimes be overly cautious, which may clash with a business’s need to take calculated risks for growth. While hiring for technical roles is easier by focusing on specific skills, the real challenge is finding professionals who combine technical expertise with a business-focused, proactive approach to security.
Security is often perceived as a blocker, making it essential to demonstrate the ROI of security initiatives. For instance, deploying tools like web application firewalls or intrusion detection systems must translate into organizations productivity gains or asset protection. Crafting these narratives requires a mindset, which is not widely developed in cybersecurity, where the focus often remains on the "what" instead of the "why." Business leaders may approve increasing security budgets year after year because they recognize the evolving threat landscape, but they still want to see measurable value.
As new threats like AI-driven attacks emerge, the industry needs a shift in mindset. Cybersecurity professionals must learn to articulate how their efforts safeguard critical assets, prevent disruptions and enhance productivity. Advancing into strategic roles demands not only technical expertise but also strong business communication and a broader perspective.
Key Advice For Aspiring Leaders
Stop treating tech and business as separate entities. While some CFOs and CEOs are tech-savvy, their focus is on business value. Discussions toward risk considerations, particularly cyber risk quantification. Present technology proposals with a clear ROI—for instance, show that while a solution may cost a certain amount, the potential losses from a cyberattack could be far greater. Let business leaders make informed decisions based on measurable risk and impact.
Business leaders think in terms of trade-offs, like where to invest based on costs and benefits. Speak their language by emphasizing ROI and risk, not technical jargon. As a security leader, step out of your comfort zone and engage with senior leaders directly.
Avoid staying within technical teams or focusing only on delivering security KPIs. At the leadership level, it Is about aligning security initiatives with business priorities. Business logic changes frequently due to board influence or market shifts and you must adapt. Immerse yourself in the business, interact with leaders and understand their concerns to align security with organizational goals effectively.