A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the CIOReview Advisory Board.

Roche

Bridging the Gap Between Cybersecurity and Business Strategy

Jonathan Sinclair

With over two decades of expertise in cybersecurity, Jonathan Sinclair is Head of Cybersecurity at Roche. He began his career as a developer, specialising in enterprise application integration, which provided him with valuable insights into the complexities of connecting large enterprises and managing everything from logistics to product delivery. Sinclair transitioned into risk assessments for emerging technologies and moved to a managed security service provider, where he led network migrations and security operations. He later headed Novartis’ information security assessment service as well. His passion for advancing security practices and his deep expertise in both software and hardware security empower him to drive cutting-edge solutions in an ever-evolving threat landscape.

In an interview with Enterprise Security Magazine Europe, Sinclair highlights the need for organisations to integrate cybersecurity into their operations and align it with business goals to mitigate risks and demonstrate value.

Cybersecurity is the Market Differentiator

Cybersecurity is a key component of business operations. Compliance adds a layer of complexity to operate in a highly regulated environment, as it requires organisations to adhere to regulatory requirements. There is a growing emphasis from regulatory bodies and countries on integrating cybersecurity into these regulations.

While compliance is crucial, the true value lies in integrating cybersecurity into development and operations. Today, organisations must showcase a strong cybersecurity posture not just to regulators but to boards, shareholders and executives—making cybersecurity a key market differentiator. It becomes even more critical in industries like pharmaceuticals, where trust is paramount.

That said, maintaining patient trust is non-negotiable when you are a global pharmaceutical company dedicated to saving lives. A company’s cybersecurity posture serves as a measure of its confidence. If an organisation’s security is compromised frequently, it raises questions about the integrity of the drugs they produce.

Cybersecurity ensures the organisation is not only safeguarding sensitive data but reinforcing its credibility and reliability among customers. In this sense, cybersecurity enables organisations to demonstrate their commitment to quality, safety and trust, strengthening the bond between the business and its stakeholders.

Building IAM Strategies for Modern Security Threats

We believe identity and access management (IAM) is critical to the overall security posture. Our approach involves mapping job functions, increasing the checks we perform on new employees and ensuring the appropriate roles and responsibilities are assigned to those job functions.

We have adopted a ‘don’t trust anyone, don’t trust the network’ mindset, which forms the foundation of our IAM strategy. We are actively implementing segmentation, zero trust and other compensating controls throughout the organisation to mitigate risks.  While zero trust as a concept has been around for a while, it poses significant challenges for larger organisations due to complexities like legacy systems, multiple directory environments and the sheer scale of operations. With more than 200,000 employees and multiple directory systems in Roche, keeping everything synchronised is a huge task.

"A company’s cybersecurity posture serves as a measure of its trust. If an organisation’s security is compromised frequently, it raises questions about the integrity of the drugs they produce"

In addition, role-based access reviews, endpoint controls for device validation and managing Bring Your Own Device (BYOD) policies add further layers of complexity. However, our focus remains on user identity. We are building the mechanisms needed to ensure that identity stays at the core of our security strategy.

Aligning Cybersecurity with Business Strategy

Technical expertise is vital for building a strong team. People skilled in incident response, forensic investigations and malware analysis are crucial for navigating the evolving threat landscape.

Business leaders focus on expanding market share, improving efficiency and adapting to demand rather than the intricacies of firewalls or segmentation. This creates a gap between technical teams and business objectives, making it crucial to find individuals who can translate cybersecurity risks into strategic value. Cybersecurity champions at various sites help bridge this gap, but hiring for such roles remains challenging.

Risk professionals excel at analysing strategic risks, particularly in new markets. However, they can sometimes be overly cautious, which may clash with a business’s need to take calculated risks for growth. While hiring for technical roles is easier by focusing on specific skills, the real challenge is finding professionals who combine technical expertise with a business-focused, proactive approach to security.

Security is often perceived as a blocker, making it essential to demonstrate the ROI of security initiatives. For instance, deploying tools like web application firewalls or intrusion detection systems must translate into organisations’ productivity gains or asset protection. Crafting these narratives requires a mindset not widely developed in cybersecurity, where the focus often remains on the ‘what’ instead of the ‘why.’ Business leaders may approve increasing security budgets year after year because they recognise the evolving threat landscape, but they still want to see measurable value.

As new threats like AI-driven attacks emerge, the industry needs a shift in mindset. Cybersecurity professionals must learn to articulate how their efforts safeguard critical assets, prevent disruptions and enhance productivity. Advancing into strategic roles demands not only technical expertise but strong business communication and a broader perspective.

Key Advice for Aspiring Leaders

Stop treating tech and business as separate entities. While some CFOs and CEOs are tech-savvy, they focus on business value. Discuss risk considerations, particularly cyber risk quantification. Present technology proposals with a clear ROI—for instance, show that while a solution may cost a certain amount, the potential losses from a cyberattack could be far more significant. Provide decision-makers with insights to drive informed choices based on measurable risk and impact.

Business leaders think about trade-offs, like where to invest based on costs and benefits. Speak their language by emphasising ROI and risk, not technical jargon. Step out of your comfort zone as a security leader and engage with senior leaders directly.

Avoid staying within technical teams or focusing only on delivering security KPIs. At the leadership level, it is about aligning security initiatives with business priorities. Business logic changes frequently due to board influence or market shifts and you must adapt. Immerse yourself in the business, interact with leaders and understand their concerns to align security with organisational goals effectively.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
Top