My Cyber Security Journey – Roz Woodward, Finance Director
In this article, we interview Roz Woodward, Securious Finance Director, about her role and journey into and through cyber security.
You are the Co-founder and Finance Director at Securious… Could you give us a bit of an overview of what that involves?
Well of course there’s making sure our finances are all in good shape – and that they’ll continue to be in the future. Whether that’s through scenario planning or simply considering how we could refine our delivery of cyber security partnerships. And really, it’s a bit of a juggling act… Between funding the development of new technology and products, like our new MDR solution, and investing in staff training, which is so important to us at Securious… It’s never easy. I think really, no matter what size your business is or how long you’ve been trading, there’s always some juggling involved.
And this is made particularly challenging by the fact we’re an independent business and always have been. We’ve had no external investment and have instead grown organically since inception. We’ve managed to simultaneously build a business in a new sector, grow our team, and develop new technology, all with no outside investment and going through covid and lockdown.
It’s great and we consider this to be a big achievement, especially in this day and age. But it hasn’t and won’t come without its challenges. The kind of growth we’re looking at inherently requires a considerable amount of investment. So we have to continuously improve our business model and predict how the market will evolve and which technologies will be core to our offering in the future – and which will, therefore, require product development now…
There’s a lot to do and I wear many hats that probably creep outside of the traditional role of Finance Director. But that’s what happens in small businesses with big ambitions.
Could you tell us about some of the other hats you wear?
I work with Darren, our Operations Director, to make sure that we’re constantly improving things for our clients. We both care about not letting them down – perhaps to a fault sometimes – so we spend a lot of time making sure that we’re in the best position for delivering everything they need.
I’m also an ISO 27001 Lead Implementor, which means I help businesses achieve ISO 27001 (the international standard for information security). This came pretty naturally to me thanks to my experience in risk as an accountant and auditor. It was really useful having that background because it naturally translated across to information security. They’re based on similar principles.
But actually, I found people were struggling with ISO 27001. I wanted to make it simpler and easier to achieve without dumbing it down too much… It used to cost so much for a traditional implementation and people found it hard to get their heads around, had so many questions and would often end up spending a lot of time and money on the process.
This was why we launched the ISO 27001 Academy, which Darren and I have been delivering to clients since 2020. It’s all about providing them with the guidance and support they need to achieve ISO 27001, either as single company teams or in cohorts with other like-minded businesses who are also looking to achieve the standard. That collaboration and network really helps them get through it, and we deliver it entirely remotely, so it’s been very effective through and since Lockdown with more people working from home. It costs a fraction of traditional implementation and if anything, it’s more effective. It’s been an exciting development for me, the business and our clients.
You mentioned your background as an accountant and auditor. Can you tell us a bit more about that, and how you came to be working in cyber security?
Well, I’ve always worked in finance – I’ve been a member of the Association of Chartered Certified Accountants for over 30 years. Half of that time was in practice and the rest was within financial services. I was lucky enough to be involved in a start-up sub-prime motor finance organisation from its early days and through to its later acquisition by GMAC and relocation to Cardiff. From here I was offered a position as Director of Finance for Continental Europe for GMAC RFC, the mortgage arm of GMAC, and was involved in the start-up of their mortgage lending businesses in the Netherlands and Germany.
I was spending my working life helping other companies with their financial planning and strategy, and it got to a point where I wondered, why? Why am I helping them when there’s clearly a big opportunity to build a cyber security business with my husband and Securious Co-founder Pete?
We had relocated to the South West and Pete had to work away a lot for a while. The demand for cyber security didn’t exist here. And though at that time no one knew they needed information security (as it was then called), we knew they would soon.
So Securious became a Cyber Essentials Certification Body – the first in the South West, and then a PCI QSAC, which meant we could help organisations achieve Cyber Essentials and PCI compliance. Gradually, we educated local organisations on the importance of cyber security. Pete did a lot of networking and I did a lot of research and blog writing in those days, along with all the finances. I really enjoyed it. And didn’t really realise how much I was picking up on by osmosis or how much I was learning until one day I realised it all made sense.
I suppose having a background as an auditor meant I was able to really get under the skin of a business quickly and work out what was important, what their key drivers were and therefore, how they could best prepare.
And I got things from our clients’ perspectives too; every company has a limited amount of time and money. So we had to find the most effective way to protect our clients while understanding no one has bottomless pockets. This means you have to assess their situation and determine where they need to focus their attention to protect themselves in a way that’s viable. Sometimes it’s about looking for quick wins where they can work with what they’ve already got, and other times it’s about helping them plan out their priorities and make sure they’re doing what’s most important first.
You said that in the beginning, there wasn’t much interest in information/cyber security from organisations in the South West. What was your vision at that time?
No there really wasn’t. We took a big leap of faith when it came to getting qualified (like becoming a Cyber Essentials Certification Body and PCI QSAC). It was not cheap or easy to achieve! But we could just see that there were plenty of fantastic businesses based down here. Other parts of the country were already investing heavily in cyber security, so it was only a matter of time before the South West would be too.
In terms of our vision, I know Pete had some big ambitions (that we’ve since realised) in terms of making enterprise-level monitoring technology available to smaller businesses based here. For me, it was about building up the South West and the businesses within it. Making it possible to keep cyber talent in the region, rather than losing fantastic people to companies based in London or wherever. And helping organisations that are based here understand, afford and achieve good cyber security, and thrive on the back of it.
It wasn’t easy and the journey is far from over, but I’d say we’ve stayed true to our vision. We knew what was coming and that demand for cyber security would pick up, and we wanted to be there ready to help organisations improve.
What advice can you give other non-technical business leaders/finance directors on how to get to grips with cyber security in their organisation?
Well, cyber security actually falls under finance in many organisations, which makes sense. After all, the reason a business cares about cyber security is ultimately financial. Whether that’s because you’re investing in preventative measures and monitoring technology or dealing with the aftermath of an attack and the huge sums of money that involves or revenue lost through downtime. And that’s not to mention the reputational damage a breach can do…
Now I don’t like all the scare tactics and I don’t tend to use them. But the truth is that if you get hit by a successful cyber attack, you could lose the whole business. You might not be able to pay your employees or fulfil customer orders. This is all vital, obviously. So my first word of advice would be that you absolutely should care about cyber security and take it seriously. It’s important that you understand the key operations you need to protect and what is in place to protect them.
And the world of cyber crime doesn’t stand still. With the speed at which this industry is changing in terms of how criminal threat actors are developing, you just don’t know what could be the next thing. You might not know what’s going to happen but you do need to be prepared. And that would be my second piece of advice – do what you can to reduce the likelihood and impact of an attack or breach.
What do you enjoy about your role now?
It’s what we can do for people. Giving them credibility that they didn’t have before as a result of achieving accreditation and compliance standards. Helping them win contracts and achieve their goals – because it’s really tangible. They put something in place, do all the right things and then win a contract they might never have got if they didn’t have those things in place. I feel like we help our clients catapult their businesses – and by proxy, the South West. It’s making clients more secure, yes, but letting them open big new doors is the most exciting part.