


Arieh Shalem is the director of information security operations at First Quality Enterprises. During his tenure in the Israeli Army, he demonstrated exceptional prowess, transitioning into a role with a pronounced emphasis on security matters. Subsequently, his professional journey unfolded within Information Technology (IT) and Information Security (IS), with a steadfast dedication to end-to-end Cybersecurity. Throughout his diverse roles, ranging from Project Manager to Configuration Manager, he laid the groundwork for implementing robust security measures throughout the organization. By prioritizing security planning and risk mitigation, his role ensures the uninterrupted functionality of critical systems.
In an exclusive interview with Enterprise Security Magazine, Shalem shares valuable insights on the challenges, trends and best practices in the strategic enterprise security space.
What are your key roles and responsibilities at First Quality Enterprises?
Entrusted with a leadership role, my primary focus centers on the Security Operation Center (SOC), which houses an adept team of security analysts. In addition, I manage two Managed Service Providers (MSPs) that extend continuous support to customers, providing them with assistance and guidance, regardless of the time of day. This operational framework spans the globe, with teams operating in the United States and Israel, ensuring comprehensive, uninterrupted coverage.
The second crucial aspect of my responsibility revolves around the Security Engineering Group. This group is vital in scrutinizing and evaluating prospective security solutions before acquisition. Furthermore, we conduct comprehensive security assessments for all IT and business initiatives. Upon selecting the appropriate tools, the team oversees the entire procurement process, subsequent implementation, and ongoing maintenance of these tools.
With a keen focus on precision and efficiency, my responsibilities extend to managing this department, ensuring seamless coordination among the teams, and maintaining an optimal security posture for the organization. Through a systematic approach, we safeguard our resources and enhance our resilience against potential threats. As the steward of these two silos, I leverage my expertise to harmonize the synergy between various teams and maintain a robust security ecosystem that facilitates the organization's sustainable growth and success.
What are some of the challenges that you have encountered as the director of information security operations at First Quality Enterprises?
In managing a full-time manufacturing environment, the primary concerns are cyber threats, particularly the risks posed by malware incidents disrupting production and advanced data leakage prevention (ADLP) events leading to data breaches and reputational harm. These concerns are addressed by implementing multiple security controls and risk assessments.
“By fostering a culture of readiness and preparedness, the organization gains a distinct advantage in its ability to confront and neutralize malicious individuals.”
Efforts are directed towards constructing and monitoring effective security tools to detect and mitigate breaches in real-time. This is accomplished by adopting a layered approach that covers all entry and exit points of the organization, including emails, web channels, FTP, USB, and other access points. Regular penetration testing and evaluation ensure the robustness and responsiveness of these implemented controls.
The ultimate objective is to achieve a breach detection gap of zero, wherein potential breaches are promptly detected and dealt with. Our team works diligently to align with cybersecurity regulations and standards like the National Institute of Standards and Technology(NIST) and MITRE, consistently assessing our performance against these frameworks. Moreover, we maintain a dynamic heat map, tracking identified threats and corresponding actions to ensure proactive and effective cybersecurity.
What strategies do you follow to cope with the latest security threats?
To ensure effective coordination and timely execution of projects, we maintain routine communication with business leaders throughout the organization. These discussions align our objectives with theirs and address the needs of both the IT and business departments. The frequency of these interactions is essential as it allows us to proactively respond to potential security threats and prevent any breaches that could disrupt our operations.
Recognizing the criticality of prompt implementation, we are diligent in avoiding any delays that might lead to vulnerabilities in our systems. By fostering open communication channels utilizing tools like Microsoft Teams, we strive to maintain clear and efficient sync between teams. This approach minimizes the risk of errors and ensures a seamless flow of information and updates throughout the organization.
What are some of the technologies that you have leveraged to ensure successful projects?
Within our security strategy is the comprehensive idea of "zero trust," which aims to ensure secure and well-managed network access from any device, at any time, and from any location. We prioritize implementing the right controls tailored to different connection services. Whether internal or external, employee or vendor, each category receives a distinct access treatment, while continuous monitoring remains a standard practice.
The challenge lies in building a robust infrastructure to uphold this "zero trust" approach, where no entity within the organization is automatically trusted, including devices and users. By adopting this stringent stance, we fortify our defences and effectively increase the likelihood of detecting and eliminating potential threats.
Our approach involves crafting layers of control that encompass the entire process, starting from user connections, extending to the endpoints used, and further to the network and applications employed. The seamless orchestration of these different layers ensures the realization of AAA (Any Device, Anywhere, Anytime) connectivity that is both seamless and secure.
What will your advice be to your colleagues and fellow peers in the industry?
Inculcating a "zero trust" mindset across the organization is essential and entails conducting thorough awareness training. The aim is to create an atmosphere where team members stay watchful, not knowing if they are facing a genuine threat or a meticulously orchestrated simulation. This heightened state of vigilance ensures that all personnel are continually on the edge, ready to respond to any potential malicious activity.
The organization gains a distinct advantage in confronting and neutralizing malicious individuals by fostering a culture of readiness and preparedness. This proactive approach strengthens the organization's overall security posture and ensures a swift and effective response to any genuine security threat.