


As a dual-role CIO/CISO, Jody Barnes drives digital transformation by aligning cybersecurity, cloud computing, and IT strategy with business goals. He is passionate about bridging technology and strategy to unlock value, support continuous transformation, and build resilient, future-ready organizations in a rapidly evolving digital landscape.
In an exclusive interview with Cyber Security Review, Barnes shared his views on his journey from an analyst to a CISO.
Evolving Through Leadership
My journey began in the late 1980s in the manufacturing industry. I started as an analyst providing field support, which grew into operational support, including digital networking and data communication. I eventually transitioned though several industries including telecommunications, healthcare, utilities, and am now back in manufacturing. Along that journey, for the first half of my career, my involvement with data communications and digital networking established the foundation of my skill set.
I moved into leadership early and, about midway through, shifted to information security despite limited experience. The opportunity arose from my technical expertise and proven success in team management. Transitioning from infrastructure to information security was challenging, but I embraced the change, asked questions, and expanded my skill set. I developed resilience by leading responses to multiple ransomware incidents at a previous company and later stepping in as interim CIO at my current company after the departure of the previous CIO, ensuring the team remained focused and steady during the transition.
Manufacturing-Specific Security Priorities
Regardless of industry, you have to align with business objectives. You must understand the company challenges to assess and prioritize risk, because you can’t fix everything at once. When I joined Ingevity after our spin-off, we didn’t have a comprehensive information security program or protective controls. There were many things to be done, but I focused on incremental improvements that would move the needle in an appropriate timeframe. Sometimes the most significant risk may take a year to fully address, while other high-risk areas can be resolved in weeks.
“Learn the business by viewing the company from both a business and technical perspective and effectively translate technical risks into the business language”
Good change management and clear communication are essential. I communicate in business language for executives and in plain terms for employees, anticipate impacts to operations, and always have a backup plan. Creating allies across the business helps frame the message and gain alignment more quickly. For modernization around SecOps, I automate wherever feasible, including patch management, vulnerability scanning and threat detection and I look for embedded AI capabilities within those toolsets to scale effectiveness.
Working in a manufacturing company with fewer direct consumer touch points, we focus on safeguarding our internal processes and systems. This approach is crucial in manufacturing, where security priorities differ significantly from those of consumer-facing businesses. Consumer businesses focus on protecting the customer’s personal and financial data, but in manufacturing, the priorities are protecting intellectual property, operational resilience, and stakeholder trust. We are integral to multiple supply chains, including the automotive industry, so production continuity and brand integrity are crucial. We demonstrate our commitment through third-party attestations, external audits and certifications such as ISO 27001 to show that we take security seriously.
Bridging AI Innovation with Leadership Growth
On the plant floor, we incorporate robotic process automation and leverage AI against plant information (PI) data for predictive maintenance and quality control. On the corporate side, the most significant changes are in knowledge management and business process automation within business streams such as order-to-cash and procure-to-pay where AI can analyze data faster, detect fraud, and speed decision-making. The goal is to free employees from low value tasks and instead make room for more strategic activity. We have embraced generative AI, and about 75 percent of our executive team has adopted it, saving roughly two to four hours from their work week.
As technology reshapes operations, leaders must grow with it. Learn the business, understand the company from a business perspective as well as a technical one, and translate technical risks into business language. Communication skills are, in my opinion, even more important than technical skills. You need to communicate clearly so your audience understands risk and value. If you cannot communicate that, you will not be invited to the table to discuss strategy. On the technical side, avoid becoming a one-trick pony. Keep stretching across technologies, build confidence in new areas, and stay comfortable with being uncomfortable.