My Cyber Security Journey – Nigel Peirce, CTO

In this article, we interview Nigel Peirce, Securious Chief Technology Officer, about his role and journey into and through cyber security.

Cyber Security Journey - Nigel

You are the CTO at Securious, could you give a bit of an overview of what that involves?

So my role is essentially about helping all of our clients secure their environments, and making sure that cyber security is workable for them. 

Anyone can come along and say ‘this is best practice – you must do that’. But our guidance has to be relevant and meaningful to each of our individual clients. You have to have a pragmatic approach to help them deal with security effectively and efficiently. 

If there are gaping holes in their systems, then you’ve got to insist that they fix them as an absolute priority. When it comes to something like PCI DSS, it’s fairly black and white. If they haven’t got something necessary in place to meet the compliance levels, they have to get it in place. But in other cases, some clients are quite early in the journey to cyber security. It’s more about hand-holding them and showing that it’s not quite as scary as they expect. 

Ultimately, we’re here to support clients and help them implement the relevant best practices with minimal disruption to make their environments secure.

As CTO I am also responsible for securing our own internal systems and making sure we’re on top of our game ourselves.

Have you always worked in cyber security?

No, I haven’t. I worked in various IT roles and cyber security was a natural progression from there. 

When I worked at Capita I looked after several thousand servers across multiple data centres. I started looking at vulnerability management, and tasking engineers to work with patching all the servers and things like that. I found it a rewarding task, seeing the immediate changes, and decided to go down that route. 

That was more than 10 years ago now.

How long you were in IT before that?

I’ve worked in IT since 1996, so like 26 years? Is it really that long? Scary. Various roles, but always IT-related.

And you said cyber security felt kind of more rewarding. Why is that?

Because you can really make a difference. 

At the start, I worked in a very large environment with lots of big customers, like London councils. They were constantly having stability problems and other similar issues. So after sorting their problems out, we’d have those customers coming back to us going ‘Hey, this is great! Our systems are secure and stable’. It was really rewarding. 

Once you got into cyber security, what was your journey from there? 

It started off by doing physical security patching of all these thousands of servers on behalf of Capita. After that, I became a data centre manager for South Western Ambulance Service. It was around the time the WannaCry virus hit the NHS – so around 2017 – and they needed a lot of things to change. 

I realised it was something that I want to do more from the governance side than the managerial. Looking at what the systems are doing, how to protect them, and those kinds of things. So I took it upon myself to get the CISSP certification, which gave me a really good grounding and overview of cyber security across a whole IT infrastructure. 

It’s not just about how to patch the system, but what you should be doing to protect the system. Right from installing the patches through to having the policies, securing things – that kind of journey. That gave me the added bonus of being offered the IT security manager of the South Western Ambulance Service, which then gave me the responsibility of securing the whole of the Trust from a cyber security perspective. 

That led me to look at cloud security, and get the relevant qualification in that as well.

In terms of the products we offer here at Securious, could you talk a little bit about Managed Detection and Response (MDR)? 

For us, offering our clients a Managed Detection and Response service is a game-changer for their cyber security. And because it is a managed service, it is much easier for them to get up and running with minimal disruption.

Monikal, our SIEM solution, makes up the backbone of the MDR service. It’s a great solution and is really cost-effective when you look at the other options out there.  Monikal is perfectly priced to give all of the relevant small and medium-sized organisations visibility of their environments from an end-to-end perspective. A lot of  IT companies are providing some types of monitoring systems, but they only look at Microsoft 365, for instance. But Monikal does the end-to-end across their infrastructure. So not just who’s logging on and when they’re logging on, but it’s everything from the firewalls, to their networks, which really does give an all-encompassing overview of how secure the systems are.

We see this kind of service as the next era for cyber security. We’re delighted to be making it accessible to a much wider range of clients.

What do you enjoy about your role now?

One thing is the variety and being able to both help clients and see the impact we are having.

I get involved in everything really, from helping clients going through Cyber Essentials, Cyber Essentials Plus and PCI DSS compliance to onboarding them with Monikal and our MDR solution. 

I enjoy getting to know the clients, getting to know their environments. Coming from quite a technical background, it’s much broader than just security – which can be very policy-driven. Seeing issues and giving insights into what organisations can do better, working with their IT providers, reminding them of best practice and what they should and shouldn’t be doing. It’s all about helping them get secure. 

So it’s really nice. I’m not pigeonholed into one particular area of cyber security. I get to work across the board.

Would you say there are any misconceptions about working in cyber security?

In the last few years, cyber security has become such a massive industry that saying that you work in cyber security doesn’t really define what you do. 

It’s such a big sector, with so many specialist areas. 

Now when you say you work in cyber security, a lot of people will picture hacking and coding. Whereas it’s really not a lot of that. It’s such a varied industry. Anyone can get into it. 

There’s such a multitude of roles within cyber security that anyone can find their niche.

What do you feel the future of cyber security might look like?

Good question. 

Well, it’s never going to go away. A problem everybody acknowledges is you’ve got nation-state attackers, who are hugely well-resourced to do nothing but look at holes in organisations. So everyone is always trying to stay one step ahead of them, with differing degrees of success. 

Visibility is key, hence the importance of SIEM solutions like Monikal, which means clients can actually see what’s happening in their environment and across their devices. Without this, effective cyber security can be like looking for a needle in a haystack.

And I think artificial intelligence and machine learning are going to progress more and more. We’re still relatively in the early days. A lot of anti-malware solutions are using machine learning, like the Antigena Email solution we offer from Darktrace to prevent phishing attacks.

There will also likely be more attention to risks outside of your environment such as domain spoofing where cyber criminals create clones of your website on similar-looking URLs. This is why we’ve started offering SAGA from Munit.io to help alert clients to any attempts to do things like this.

Any advice for people looking to improve their cyber security?

I think an awful lot of customers are scared to ask questions about cyber security, for fear they’ll be made to look stupid. But if you’ve not got experience with cyber security, how can you know? 

You’ve got to ask somebody. So ask us!