Ulta Beauty

A Practical Approach to Cyber Risk Leadership

Rebecca approaches IT risk management with a balance of persistence and agility. She focuses on understanding root causes, not just surface issues, and follows risks through their full lifecycle. At the same time, she adapts quickly to changing threats, technologies, and business needs. This steady yet flexible mindset helps her manage and communicate IT risk clearly and effectively.

Immediate attention goes to risks that align with active, high-velocity threats—for example, vulnerabilities being actively exploited in the wild, indicators of compromise tied to known threat actors, or exposures that map directly to current attack campaigns or threats known to target Ulta. If threat intelligence shows a rapid uptick in exploitation or if the weakness provides a clear, low-effort entry point for attackers, it becomes a priority for swift action. For long-term mitigation, I focus on risks that may not be actively targeted today but have the potential to grow as the threat environment shifts. These usually involve structural or architectural weaknesses, legacy technologies, or gaps in processes that require more strategic planning. While they may not pose an immediate threat, they represent areas where emerging attacker techniques or technology changes could elevate their risk level over time.

“I focus on what cyber risk means for the business, using data to guide clear decisions instead of reacting to fear.”

I focus on what the risk means for operations, customers, finances, or reputation rather than the technical details. I also use visuals, short examples, and clear options for next steps so stakeholders can quickly understand the situation and make informed decisions. Relationship building and collaboration are critical to incorporating risk awareness into agile/innovated/ transformative environments.

Data-Informed Risk Decisions and Leadership

In cybersecurity, the threat landscape changes quickly, so making counter-defense measures that are not data-informed is often wasted effort. I use data from threat intelligence feeds, log analytics, incident trends, vulnerability scans, and user behavior monitoring to understand what attackers are actually doing—and where our real exposures are.

This data helps me:

• Prioritize risks by highlighting which vulnerabilities are actively exploited or showing abnormal activity.

• Detect emerging threats through patterns in network traffic, authentication anomalies, or endpoint alerts.

• Validate control effectiveness by measuring how well existing defenses are preventing or detecting attacks.

• Support faster decisions with real-time indicators instead of gut feeling.

• In short, data gives me a live picture of our risk posture, enabling more accurate assessments and smarter, faster defensive decisions.

My advice is to balance confidence with humility. Staying humble doesn’t mean downplaying your expertise; it means being open to learning, asking questions, and recognizing that the landscape changes constantly. Humility keeps you adaptable, grounded, and able to build trust across technical and non-technical teams. At the same time, be prepared for moments when you may be the only woman in the room. Instead of letting that limit your voice, use it as motivation to show up with clarity, preparation, and authenticity. Your perspective is valuable, and your presence helps shape the culture for those who will come after you.

Focus on building strong relationships, because effective risk leaders influence through collaboration, not authority. Learn how to communicate risks in a way that is transparent, constructive, and focused on enabling business outcomes— not creating fear. And finally, invest in continuous learning. The threat landscape evolves daily, and strong leaders stay curious and keep sharpening their skills. Lead with humility, speak with confidence, and remember that your voice matters—even when you’re the only one at the table.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.