Tech

‘I love solving puzzles and this industry is full of them’ finds cyber CISO

Published

on

Company86’s Cheryl Martin discusses the cyber landscape and why the skills shortage is more than a recruitment problem.

Having first started out in banking, Company86’s CISO Cheryl Martin moved through a series of customer-facing roles before becoming curious about the technical side of STEM. This interest generated a range of opportunities, such as building telecoms technology infrastructure supporting sub-sea cables and developing the UK’s internet backbone. 

She told SiliconRepublic.com, “That, in turn, led to a role undertaking major expansion into data centres. From there I pivoted into information security and have never looked back, embracing the various technology trends along the way.

“I love solving puzzles and this industry is full of them. Technology, threats, capabilities and risks all have one thing in common, they constantly change and manifest themselves into something different, much like a chameleon. The challenge to get ahead and stay ahead keeps me energised and keen to learn more.”

Advertisement

Be the momentum

Martin’s career has spanned what she refers to as “a number of technology changes and ways of working”. As a result she finds she has faced the types of challenges common to “first movers”, several times over. While exciting and sometimes even risky, it has also opened her eyes to what can be achieved when you have a vision. 

She said, “Sometimes a process or way of working hasn’t been defined, and it’s down to you to work through the myriad of possibilities. In all instances you need to be able to fail fast, express yourself in simple, easy-to-understand language and trust the team around you.

“One highlight that stays with me is the early work building the infrastructure behind sub-sea cables and the UK internet backbone and being part of laying the foundations for things people now take for granted every day. At the time much of it was uncharted, and there was real satisfaction in solving problems no one had a template for.”

She further explained, the secret to keeping her more than 20 year career in the cybersecurity sector fresh and interesting is in understanding that “you never really reach a point where you can say you’ve mastered it.” The technology will change, attackers will adapt their tactics and “suddenly the assumptions you were working with six months ago need to be challenged again.”

Advertisement

She said, “AI is a fascinating example of that. We’re seeing it change both sides of the equation. Attackers can experiment and personalise at much greater speed, while defenders have new ways to identify patterns, automate repetitive work and make sense of huge amounts of information.

“That constant movement suits curious people. Some of the best people I’ve worked with in cyber are the ones who keep asking questions, particularly when everyone else thinks something has been solved. I think that’s a big part of why I’m still excited by it.”

Trending threats

Martin noted one of the predominant trends of 2026 so far is undoubtedly AI, which is a far more relevant topic when viewed through the lens of its impact on the speed of cybersecurity and the pressure being placed on organisations to adapt at a similar pace.  

She said, “That’s why I think we need to start talking about “Mean Time to Adapt”. For years we’ve measured things like ‘Mean Time to Detect’ and ‘Mean Time to Respond’, which are still important. But increasingly, I want to know how quickly an organisation can learn from what it is seeing and actually change.

Advertisement

“Can you reassess a risk, update a control, retrain people or change a governance decision quickly enough to respond to a threat that is continually evolving?”

She predicts this will be a key trend throughout the rest of 2026, where adaptability will become one of the clearest dividing lines between organisations. She said, “You can’t predict every attack or technology shift. What you can build is an organisation that learns quickly, changes quickly and is ready when the next one arrives.”

A core element of addressing challenges is in overcoming threats via an established team of skilled and nichely qualified professionals, however, for Martin, the cyber skills deficit being seen on a global scale is not solely a recruitment issue. 

She explained, “Recruitment only tackles one part of the problem. If we’re all competing for the same pool of experienced cyber professionals, we’re moving talent around rather than creating more of it. We need to think much earlier about how people find their way into cybersecurity in the first place. 

Advertisement

“That means engaging with schools and universities, mentoring people at the start of their careers, creating more visible role models and showing that there isn’t one fixed route into the industry. Cyber needs technical specialists, but it also needs people who can communicate, solve problems, understand risk and bring different perspectives to the table.

“The challenges we’re dealing with are becoming more complex and different experiences and ways of thinking help teams spot things others might miss and challenge established assumptions. If we want a strong pipeline of people with those skills and perspectives, we have to invest in developing them long before there’s a role to fill.”

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Advertisement

Source link

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version