


Jonathan Sinclair is a distinguished cybersecurity and IT leader with extensive experience in elevating cybersecurity from a mere compliance function to a core driver of business value. He is currently the Head of Cyber Security for Pharma at Roche, responsible for designing and implementing cybersecurity strategies that not only safeguard data and infrastructure but align closely with broader corporate objectives. Sinclair brings visionary insights into global markets, using cybersecurity as a tool to expand market reach, mitigate risks and drive fiscal responsibility within large programs.
In an Interview Manage HR APAC, Sinclair emphasizes on the increasing importance of cybersecurity in technological landscape, particularly in the pharmaceutical sector. He also highlights for a holistic approach to cybersecurity leadership, where professionals must be both technically proficient and able to communicate and collaborate across departments to align security efforts with business objectives.
Reflecting on past experiences
I began as a software developer, transitioned to risk assessments, where I gained a theoretical understanding of security. Later, I moved into network engineering and threat detection, working for a managed security service provider that gave me the experience of what it’s like to be customercentric.
From there, I moved into consulting, focusing on penetration testing and secure code reviews, which deepened my technical assessment skills and led me security assessment services at Novartis, overseeing global security initiatives such as penetration testing. A shift to digital forensics brought me into finance, consulting for private banks and handling highstakes incident response, especially for nation-state threats.
As CISO for Celgene’s EMEA and Asia Pacific regions, I partnered with legal teams to integrate GDPR into security, blending technical leadership with privacy compliance.
Later, a startup role allowed me to understand what board levels of expectations are in a startup, understanding the risk thresholds and the risks that startup is willing to take a far greater than enterprise and also managing global teams.
Currently, as Head of Security for Roche’s pharmaceutical division, I manage security across varied environments, from manufacturing to AI-driven digitalization, within an agile, matrix-driven organization.
Key insights and challenges
The geopolitical landscape is growing increasingly unstable, more so than we’ve seen in recent years. The goal was clear: achieve financial gains and access talent wherever it was available, so companies would simply shift operations to make that happen. At the C-suite level, the focus was largely on managing risk to enable these moves safely and securely. But there’s a growing awareness among top executives of the profound implications of geopolitical instability, a trend that began with the disruptions of COVID-19 and has since been heightened by ongoing conflicts in Ukraine and the Middle East, as well as increased tensions surrounding China and North Korea. Companies are increasingly considering winding down or relocating systems, a shift in corporate strategy that can be seen.
Cybersecurity in pharma also faces unique challenges as it must enable innovation while managing risks from interconnected manufacturing, R&D and cloud systems. AI-driven adaptability in factories increases the risk of manipulation, potentially endangering patient safety. To counter this, we enforce strict GXP controls and explore sustainable AI practices for decision traceability, though this area is still developing.
"For those entering the field, it’s crucial to recognize that leadership already understands business risks and prioritizes higher-level goals"
A wave of change
The AI side is likely the easiest to understand initially, especially since the pharmaceutical industry—particularly Big Pharma— has traditionally been focused on large-scale production, especially with small molecules like tablets and capsules. using hardware-centric, long-lasting systems. Now, software-driven disruption is reaching manufacturing, similar to changes seen in enterprises with no-code infrastructures and agile technologies.
In the pharmaceutical sector, we’re observing that patient demands and business models are shifting toward personalized medicine, where treatments are tailored to genetic profiles, which requires adaptable and dynamic production lines that can be reconfigured more easily—a capability that was previously unheard of. AI is key to this transformation, providing analytics that optimize manufacturing performance in real-time through metrics like yield and process efficiency. I work in a division dedicated to digitalization, operational excellence and artificial intelligence and we are deploying these methods across our manufacturing ecosystem especially newer, tech-enabled ones, where they integrate more readily. Even in legacy systems, AI is driving significant process improvements.
This transformation is also reshaping R&D, where AI-driven in vitro and in silico simulations enable us to target molecules and discover potential blockbuster drugs more efficiently, challenging traditional discovery methods. AI, alongside Zero, is thus profoundly advancing pharmaceutical manufacturing and product development.
Focusing on resilience and control
In the past, there was a demand toward maximizing efficiency and performance, often at the expense of redundancy, leading to minimized inventory and fewer dual systems or sites. However, disruptions like COVID and supply chain issues have shifted this approach. Now, there’s a renewed focus on building failover infrastructure and replicating systems.
We’re reconsidering cloud reliance, moving some operations in-house for better control over data and resiliency. Bandwidth limitations require local systems, especially for highvolume R&D data, as transferring large amounts in real-time isn’t feasible.
This shift is incorporated into our business continuity and disaster recovery plans. The industry’s recent disruptions have emphasized the need for resiliency and redundancy, prompting us to adopt zero-trust models, active-active standby systems and enhanced disaster recovery for greater local control and resilience.
Building Strong Teams for Achieving Business Goals In our matrix structure, decision-making shifts between top-down and bottom-up, with strong leadership at the CFO, CEO and CIO levels advocating for security best practices. However, as decisions shift to the edges, security awareness can be lacking. It’s my job to raise awareness beyond basic exercises like phishing drills, focusing on real risks and their impact.
In pharma’s safety-driven culture, we’re integrating cyber concerns, though it’s still a work in progress. Despite frequent breach news, many are unaware of emerging threats. I focus on outreach, particularly in smaller divisions, where breaches often occur and encourage people to ask, “If this were my house, how would I feel?” to build a stronger security culture.
Advice for industry peers
For those entering the field, it’s crucial to recognize that leadership already understands business risks and prioritizes higher-level goals. Cybersecurity professionals must step out of the technical silo and engage with HR, legal and finance to align security efforts with business needs, or their efforts will be ineffective.