How Pete, CEO, got into cyber security and where he sees it going in the future

Pete Woodward Securious Cofounder and CEO, the South West's leading cyber security company

Pete Woodward talks us through his journey from working in the RAF to being the co-founder and CEO of Securious, the South West’s leading cyber security consultancy… 

Have you always worked in cyber security? 

Oh no. When I started work, I don’t think there was even a cyber security sector.  

I joined the RAF at 17 years old, straight out of school. It was a very technical role, but had nothing to do with computers. I was a Propulsion Mechanic working on fighter jets and engine propulsion systems.   

Looking back now, I can see that it was really good grounding for working in cyber security, though I had no idea that that’s where I’d end up. My role was ultimately about finding and solving issues; I would look at a problem with one of the aircraft – say a puddle of oil on the floor underneath it – and have to figure out what caused it. Then I’d have to find where the source of the issue was and figure out how the problem occurred in the first place, before finding a solution and fixing the issue. The same process goes for cyber security really. Though nowadays we’re more focused on proactive prevention rather than retrospective remediation.  

I spent 12 years working in the RAF, but the significant move for me was getting into IT. It was only after that I moved over to cyber security. 

What made you get into IT initially? 

After I left the RAF, I worked on an oil rig in the North Sea. It was a really hostile environment – offshore engineering out in the cold, wet and wind. One day I looked around me, seeing people in their late 40s and early 50s still doing it. I just knew I didn’t want to get stuck in a job like that forever.  

I started thinking about getting into a more analytical, IT-focused role. It actually came around the same time that I met Roz (Roz Woodward, Securious co-founder and Finance Director). Being single at the time, my lifestyle had never really been an issue. But I became aware of how risky it was, and I felt a need for a change of environment so we could settle down. I think that contributed to my change in career path. I felt like I had been sat on a bomb that hadn’t gone off yet. It was a relief to get away from it. 

So tell us about that early journey  

I used to be pretty hopeless with computers. At my first job in IT, I remember the internal IT person came up to my desk, put a laptop down in front of me and told me to get started. I was completely clueless. I just about knew how to connect to the Wi-Fi – so it was a pretty steep learning curve from day one. 

From there, I did a couple of boot camps so I could improve my basic skills: Microsoft certification, Cisco and all of that. That was around 2001. 

Cyber security didn’t exist in the same way back then as it does now. It wasn’t publicised as much, which meant cyber crime was far less common. But on the flip side, I think there were a lot more ports open and opportunities for attacks because people just weren’t so aware of them.  

How did you go from a relatively inexperienced IT person to being the CEO of a leading cyber security company? 

I started out working as a generalist for a big provider of all systems – IT, firewalls, routers, telephones. A lot of my role involved installing Microsoft applications and the like, but to me that just felt operational and a little bit dull, if I’m honest.  

I found myself naturally gravitating towards the information security side of things, as it was called then. I felt like that was where it was all happening – configuring firewalls, implementing multi-factor authentication, integrating Blackberry systems and looking at the security around all that.

It was far more of an interest for me. My first early experience of information security was around understanding the importance of sensitive data, encryption and how you get from one system to another securely. 

So, I got a lot more involved with networks, how data packets traverse the networks, how to block applications at firewalls and open ports. I just found it fascinating. And I was lucky to be working with a highly skilled technical team. There were five or six CCIEs (CISCO expert level), who really inspired me to get qualified myself.  

I ended up working in Information Security there for five or six years, and I learnt a lot of skills. But focusing on delivering someone else’s strategy wasn’t that fulfilling for me after a while. Most senior consultants are buried in the day to day and your voice doesn’t really get heard. I had a lot to give but I felt watered down in a large corporation.  

That was when I moved to the South West and started contracting. I got to work with some really big organisations (like Sainsbury’s, HP and BP), moving forward their strategy and goals. I learnt a lot of new skills. An organisation with 50,000 staff is a whole different game. And the thing I find quite funny is actually, the problems in these huge businesses aren’t really that different to those you get in much smaller organisations. The same things are wrong in terms of cyber hygiene, and the same problems affect everyone. Except it costs a lot more for a big business to sort them out.  

I had a lot of experience in cyber security by that point. I’d seen so much and had learnt many lessons about how to do things – and how not to do things. And I decided I wanted to take what I’d learnt from the big organisations and make it accessible to smaller businesses, who were suffering from many of the same issues, but didn’t have the money or expertise to even begin solving them.  

Securious had begun as a consultancy in 2007 with just me, but it really took off when we moved to the Exeter Science Park in 2017. 

I knew the market needed (or would soon need, we were a little ahead of the times I admit) more pragmatic dedication to delivering high level cyber security services. I wanted to share my knowledge to bring value and help organisations in the South West that previously didn’t really have access to the same level of expertise or technology as larger organisations.  

And honestly, that was when my dream of launching a SIEM/SOC for mid-level organisations was born. I saw them in the early days working with large corporations and I recognised the difference full visibility and logging and monitoring capabilities made to security. I knew that’s where the market would go. At that point, only businesses with hugely deep pockets could afford such investments in that kind of technology. I knew I wanted to be at the forefront of making these solutions available to smaller, local businesses.  

What do you enjoy most about your job now? 

What I love about cyber security is being at the forefront of risk. There’s a constant cat and mouse game to catch the bad guys before they wreak havoc on people’s businesses and lives.   

Cyber criminals are becoming increasingly creative, and it’s even becoming easy for the less technically-minded of them to successfully disrupt businesses’ operations for their own financial gain. Technology is making it easier for them to target many businesses at once with an attack. They use a constantly-evolving range of methods to improve their chances of success.  

This means we have to really try to get into the mindset of the hackers to deal with certain situations, and constantly bear in mind how their methods are changing. 

The good news is that technology is constantly evolving on our side too. It’s our job working in cyber security to understand and adapt to these developments in the cyber criminals’ methods, and cater our services to resolve the new issues that they create. We have to continually watch what they’re doing and react to new threats, while also thinking a few steps ahead and putting protective measures in place for clients ahead of an attack, so they are less likely to become a target of an opportunist, and are better prepared if/when they do.  

That’s what excites me the most I think. In a nutshell, finding and developing better ways to help our clients stay safe. 

Are there any misconceptions about working in cyber security? 

To an outsider I think cyber security sounds very complicated and hard to understand, but it’s not really. To me, it’s all very logical. As I learned more about it and did more training, I realised it makes a lot of sense. I started to understand that, of course you need to lock and secure this private information away to make sure nobody can access it, of course you need to do x, y z to prevent a, b, c from happening. It was doing a lot of what’s now just classed as best practice. 

Likewise, people think the hard part is learning and understanding how the technology works. But in my opinion, the real test is when you can’t solve something and you have to start thinking laterally to understand how you can overcome the problem or work around it. You have to consider which angle will allow you to get in and work out what’s going on. 

It’s endlessly fascinating. 

How is the cyber security sector changing and how can we respond to it? 

It’s bizarre to think about it, but cyber crime is available as a service now. There are platforms where you can literally put your target in, how much ransom you want, when you want your campaign to run, click go and that’s it. It’s really quite frightening. And it makes for such easy pickings for the criminals.  

To counter this kind of threat, I think there’s going to be a lot more automation and continual assurance, continual governance and continual assessments. I really hope compliance is going to move away from the single point in time checks to make sure everything’s secure and instead look at environments in real-time. 

You know how it is with car MOTs. Today, your vehicle is safe and compliant, but that doesn’t mean something won’t break tomorrow. If it does, that suddenly means your car isn’t safe anymore. However, it’s still compliant, it’s still got that MOT stamp of approval until your next test in a year’s time. But you could well  be driving it for the next 12 months thinking everything is fine… But actually, there’s a big problem that’s posing a significant risk. And it won’t be uncovered until your next MOT – if you make it that far…  

Cyber security is the same. Previously, we’ve just had the equivalent of MOTs. Tests at single points in time to see how secure everything was for that moment. And businesses get certificates or accreditations – stamps of approval – that say they are secure and doing the right things. But it’s not really good enough on its own. Not for their own peace of mind or for their customers, who need to know whether they can rely on their suppliers being secure.  

It’s good to know you were compliant yesterday, or last week or whenever, but what you really need to know is that you are compliant today, every day. That’s what I’m focused on making possible for all businesses, above all else.  

I also think there’s some really interesting new concepts around data security. For example, organisations looking to de-risk databases instead of securing them. This would mean if data was lost or someone broke in to see it, it’s not a big deal because it’s not putting anyone else at risk. It’s making some information fully accessible rather than wasting resources securing it.  

What advice would you give an organisation looking to improve its Cyber Security? 

That’s a big question. It varies enormously according to both their situation, for example in terms of the kind of data they handle, and their level of sophistication. For everyone, good cyber security is a journey rather than a destination. You never ‘get there’, but you need to keep getting better. 

If I had to simplify, my advice would be: 

  1. Get buy-in at board level  
  2. Understand where you are from independent experts 
  3. Build a plan to prioritise remediation according to the greatest risks 
  4. Achieve relevant third party accreditations (eg Cyber Essentials Plus, ISO 27001) 
  5. Educate your team – they can be your biggest weakness or greatest asset 
  6. Implement ongoing 24/7 monitoring and threat detection to highlight issues quickly 
  7. Promote/demand better cyber security within your supply chain 

Need support in making your organisation more secure?  

Get in touch using the contact form below, and a member of our team will be in touch.