Academy Sports + Outdoors

Academy Sports + Outdoors

Alvarado is a digital risk specialist with 19 years of expertise in the IT industry. He is responsible for assisting enterprises in identifying digital risks and recommending solutions or controls to close the gaps. He is also a certified IT security specialist who is familiar with endpoint security, vulnerability management, identity management, data loss prevention, threat remediation, and best practices for securing IT infrastructure. Prior to cybersecurity, he spent 11 years working in high-speed manufacturing.

As the director of it security, could you explain a little bit more on what you’ve seen in the security landscape in your line of work?

Criminals have found cyberspace to be an increasingly appealing hunting ground over time. There are two reasons for this; first, people today are more connected to internet-based stuff. Our devices are connected to the internet, transactions are taking place, and we are trying to connect in a variety of ways. While an increasingly connected world makes our lives easier, we also need to think about the security that comes along with it. Most companies are already leveraging technology, and for those who don’t, a pandemic has forced them to do so. Growing tech companies have opted to make remote work easy for their employees, which enabled cybercriminals to touch anything that connects to the internet remotely. We know that Data is now the ‘new black gold’ for the hackers. They want your data to either sell or exploit it and to use ransomware to extort money from you. That is why cybercrime activities are lucrative in the industry. Second, breaches occur because big businesses do not do enough to put the right controls in place, resulting in a shortage of cyber security and cyber professionals to do the job. If the technology exists to help criminals in committing cybercrime, it also exists to keep them out. You make it much easy for them if you don’t secure your organization. Many businesses are utilizing technology such as AI and ML that allows them to be more efficient and automated today, but some firms still do not, either because they are unaware of it or because they do not want to spend the money for it.

“Think security folks should learn about databases, operating systems, hardware, configuration, and coding to understand how to secure them before becoming a cyber professional”

Could you elaborate on some of the best practices that businesses may use to improve their security?

Establishing a governance and compliance structure is one of the greatest initiatives. I first began working in the IT business, and I found that many organizations lacked a clear standard operating procedure and framework in place to set that governance. The framework consists of standards, guidelines, and best practices to manage cybersecurity risk. That’s why the government had to start regulating and enacting rules in place because big business was not doing enough. Security has been split into two categories: operations and governance and compliance, which helps to keep everything under check. The operational side is responsible for securing things that people use on a daily basis, while the GRC side is responsible for ensuring that you are following the rules and complying with data privacy and data protection legislation in order to keep the bad guys out.

When it comes to identifying enterprise security solution providers, how do you get their attention? Is there a procedure for evaluating their value offer and partnering with them?

Before choosing the right vendor, we need to understand where our organization at and where we want to be. We must ensure that our roadmap is realistic and we are aware of the regulatory compliance and also where our Data is flowing. Some businesses operate on-premise, while others have moved to the cloud, and some enable employees to use their own devices (Bring your own device). This is how company data is transferred to non-company-owned devices, posing new issues. We need to look for the correct tool, or else simply chatting to vendors may take you down a rabbit hole.

Any piece of advice there for upcoming professionals in the field?

I would advise aspiring professionals to be well-versed in a few areas, particularly the business side. I’ve seen many professionals

become so engrossed in technology that they are unable to apply it to the business side. To understand where the difficulty lies, I believe that every CSO should have a comprehensive understanding of both business and technology—how it operates, where data flows, and what infrastructure looks like.

Another key consideration is to be aware of what is on the horizon in terms of data privacy and protection. They must ensure that their organization complies with state-specific data privacy and data protection law. After they’ve grasped those concepts, what are the company’s risk appetite and business strategy? They must ensure that their IT security program is aligned with their business objectives. Because if any company wants to use your security plan, you must be able to justify it in terms of business operations, financial aspects, and regulatory compliance. All of these points will be very useful to be successful in the industry.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.