


Jonathan Sinclair is a distinguished cybersecurity and IT leader with extensive experience in elevating cybersecurity from a mere compliance function to a core driver of business value. He is currently the Head of Cyber Security for Pharma at Roche, responsible for designing and implementing cybersecurity strategies that safeguard data and infrastructure and align closely with broader corporate objectives. Having worked in diverse leading positions, including CISO, board member and advisor, Sinclair’s experience spans finance, technology, TelCo, BioTech and Pharma. Beyond Enterprise threat reduction and operational excellence, he supports charitable organizations with their cyber security maturity journeys, increasing AI and machine learning awareness and advising start-ups negotiating early-stage development.
In this article, Sinclair emphasizes the increasing importance of cybersecurity in the technological landscape, particularly in the pharmaceutical sector. He also highlights a holistic approach to cybersecurity leadership, where professionals must be both technically proficient and able to communicate and collaborate across departments to align security efforts with business objectives.
A Journey Through Security and Risk Management
My career began as a software developer, where I built a strong technical foundation. I then transitioned into risk assessments, gaining a theoretical understanding of security concepts. This experience paved the way for my move into network engineering and threat detection, where I worked with a managed security service provider, honing my skills in customer-centric service delivery.
From there, I shifted to consulting, focusing on penetration testing and secure code reviews. These roles deepened my technical assessment expertise and led me to oversee security assessment services at Novartis, where I managed global security initiatives, including penetration testing. My career then evolved into digital forensics, consulting for private banks, and handling high-stakes incident response, particularly in cases involving nation-state threats.
As the CISO for Celgene’s EMEA and Asia Pacific regions, I partnered with legal teams to integrate GDPR into security frameworks, blending technical leadership with privacy compliance. Later, a role in a startup environment allowed me to understand board-level expectations and risk thresholds unique to startups, which are often significantly higher than those in large enterprises. This role also gave me valuable experience managing global teams.
“For those entering the cybersecurity field, it’s essential to understand that leadership is already well-versed in business risks and prioritizes overarching organizational goals.”
As the Head of Security for Roche’s pharmaceutical division, I oversee security across diverse environments, including manufacturing facilities and AI-driven digitalization initiatives. Operating within an agile, matrix-driven organization, I lead efforts to protect critical assets while supporting innovation in a rapidly evolving industry.
Adapting to Instability
The geopolitical landscape has become increasingly unstable, more so than in recent years. Historically, companies sought financial gains and access to talent by shifting operations wherever it made strategic sense, with the C-suite focused primarily on managing risk to facilitate these moves safely and securely.
However, there is a growing awareness among top executives of the profound implications of geopolitical instability. This trend, initially triggered by the disruptions of COVID-19, has been exacerbated by ongoing conflicts in Ukraine and the Middle East, as well as escalating tensions involving China and North Korea. As a result, companies are increasingly reevaluating their strategies, including the possibility of winding down or relocating systems to mitigate risks.
In the pharmaceutical sector, cybersecurity presents unique challenges. The industry must enable innovation while managing risks associated with interconnected manufacturing, R&D and cloud systems. AI-driven adaptability in factories, while transformative, introduces the risk of manipulation, which could jeopardize patient safety. To address these risks, we enforce stringent GXP controls and explore sustainable AI practices to ensure decision traceability. However, this area remains in its early stages of development, requiring ongoing attention and refinement to balance innovation with security.
Accelerating Drug Discovery with AI and Agile Technologies
The role of AI in the pharmaceutical industry is becoming increasingly pivotal, particularly as the sector undergoes significant transformation. Pharma has always relied on hardware-centric, long-lasting systems to support the large-scale production of small molecules, such as tablets and capsules. However, software-driven disruption is now reaching pharmaceutical manufacturing, mirroring the evolution seen in enterprises with no-code infrastructures and agile technologies.
The industry is shifting toward personalized medicine, where treatments are tailored to patients’ genetic profiles. This shift demands adaptable and dynamic production lines that can be easily reconfigured—capabilities that were previously unimaginable. AI is at the core of this transformation, providing real-time analytics to optimize manufacturing performance through metrics like yield and process efficiency. In my division, which focuses on digitalization, operational excellence and AI, we deploy these advanced methodologies across our manufacturing ecosystem. While newer, tech-enabled systems integrate these innovations more seamlessly, even legacy systems are seeing significant process improvements driven by AI.
This revolution extends beyond manufacturing into R&D. AI-driven in vitro and in silico simulations are accelerating the discovery of potential blockbuster drugs by enabling more efficient targeting of molecules. These advancements challenge traditional methods of drug discovery, offering unprecedented speed and precision. AI, combined with emerging methodologies like ‘Zero Trust,’ is profoundly reshaping pharmaceutical manufacturing and product development, heralding a new era of innovation in the industry.
Redefining Cloud Strategies for Operational Continuity
In the past, the focus in the industry was on maximizing efficiency and performance, often at the expense of redundancy. This approach led to minimized inventory levels and fewer ‘dual-sourced’ systems or backup sites. Disruptions caused by events like COVID-19 and supply chain challenges have prompted a significant shift in strategy. Today, there is a renewed emphasis on building failover infrastructure and replicating systems to enhance resilience.
This shift includes reevaluating reliance on cloud infrastructure. While the cloud offers many advantages, we are moving some operations in-house to gain better control over data and ensure greater resiliency. For example, bandwidth limitations make it impractical to transfer large volumes of R&D data in real time, necessitating localized systems to handle high-volume operations more effectively.
These adjustments are now integral to our business continuity and disaster recovery plans. Recent disruptions have underscored the importance of resilience and redundancy, driving us to implement strategies such as zero-trust models, active-active standby systems and advanced disaster recovery solutions. These measures are designed to provide greater local control, ensure operational continuity, and strengthen our overall infrastructure against future challenges.
The Key To Effective Cybersecurity
In our matrix structure, decision-making alternates between top-down directives and bottom-up initiatives. While strong leadership from the CFO, CEO and CIO levels champions security best practices, security awareness tends to diminish as decision-making shifts to the edges. My role is to elevate awareness beyond basic exercises, such as phishing drills, by emphasizing real-world risks and their potential impact.
In pharma’s safety-driven culture, integrating cybersecurity concerns remains a work in progress. Despite the prevalence of breach reports, many individuals remain unaware of emerging threats. My focus is on proactive outreach, particularly in smaller divisions where breaches are more likely to occur. I encourage teams to consider security on a personal level by asking, “If this were my house, how would I feel?” This perspective helps foster a stronger, more relatable security culture.
For those entering the cybersecurity field, it’s essential to understand that leadership is already well-versed in business risks and prioritizes overarching organizational goals. Cybersecurity professionals must move beyond technical silos and actively collaborate with HR, legal and finance teams. Aligning security efforts with broader business objectives is critical for achieving meaningful and effective outcomes.