A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the CIOReview Advisory Board.

Delta Cafes
Leading Cybersecurity Innovations


David Marques
Bio: Having more than 15 years of experience in various fields of Cyber Security, David Marques is a passionate professional. His expertise spans from deep technical topics to high-level topics such as cybersecurity governance and management. Apart from academic study, he has several certifications in the industry, which led him to self-motivation and a search for continuous improvement An active member of the Portuguese information security community, he actively collaborates on several projects for the general public and cybersecurity professionals. Curently, he works as Head of Cybersecurity for Grupo Nabeiro.
1. Can you share some insights into your professional journey and the key experiences that led you to your current role at Delta Cafés?
I started my career working on a very specific role related to information security, which was the creation and implementation of the first Portuguese data recovery laboratory. Working a couple of years on this role, I went on to a Digital Forensics role. After technically leading these two teams, I decided to broaden my knowledge. Subsequently, I went to take the role of leading all the technical delivery of cybersecurity technology services within the company.
Moving forward, I started working on consulting projects related to Information Security, ISO 27001, ISO 220301, GDPR, among others. In the end I became the Cybersecurity Business Unit Manager, responsible for managing all aspects of the division. Then I accepted the challenge offered by Grupo Nabeiro / Delta Cafés to build the Cybersecurity Division from scratch and becoming their Head of Cybersecurity.
2. What are the most significant trends and technology advancements that you believe will impact cybersecurity in the retail space?
There are a couple of trends and technology advancements which will become very important in the near future. I will mention two of them. First, of course AI will have an impact on cybersecurity. I think the first two to three years of AI are necessary to go from a buzzword to effectiveness, as companies will start to look at AI, not just as a market trend, but also as a way to help them achieve their goals with specific use cases that will justify the investments in technology and people. AI will be of great help to cybersecurity professionals, as I believe it can augment our limited resources and capabilities and to speed up the incident response process, which is of great importance to contain and remediate attacks. Other area where I think there will be a lot of technology advancements is OT. The latest decades, cybersecurity was very focused in IT environments, but of course, production sites depend almost 100 percent on OT environments and a lot will be done to foster the challenges related to OT Cybersecurity.
3. What do you see as the biggest challenges in the retail security landscape over the next decade, and how are you preparing to address them?
One of the main challenges will be addressing the needs for interconnection of OT and IT environments, what will force significant changes in the security landscape. It will be very difficult to adopt new technology solutions and integrations on the retail environments, like AGV’s, and automate as much as possible, when there’s still a huge gap in the security landscape of both environments. We are addressing this challenge by having a multi-step approach, by first working with technology solutions and with internal teams to have a clear understanding of our environment, because we can’t protect what we don’t know that exist, and then by defining processes like vulnerability and patch management, logging and incident response.
4. Can you describe the cybersecurity technology stack currently in use at Delta Cafés? What considerations went into selecting these tools and frameworks?
We have built our technology stack based on our threat landscape, culture and future goals. Our architecture comprises four distinct layers. The first layer is our External Attack Surface, which examines what we have exposed to the internet and ensures secure access for those outside the company network. The second layer focuses on network security and the flow of data in and out of company resources. The third layer is asset and data security, concentrating on protecting all our assets. The fourth layer involves continuous monitoring and auditing, constantly monitoring our assets wherever they are and regularly auditing to identify and fix issues before attackers do.
5. What advice would you give to other users looking to adopt emerging cybersecurity technologies and consulting approaches? What are the key considerations and potential pitfalls they should be aware of?
I would say that I’ve seen over the years when I was providing services and consulting to others, two main pitfalls and the results of them. One is looking at cybersecurity from a compliance perspective, as if cybersecurity maturity could be measured by ticking some checkboxes. Of course, compliance is important, but it’s an enabler for cybersecurity, but cannot be the main motivation, or else companies will stop as soon as they have the checkbox filled. Attackers do not have any kind of compliance mechanisms and still they are successful. A second pitfall I often see is not having a clear roadmap for cybersecurity and being dependent on technology providers to define their roadmap. Of course, technology providers are very important to achieve your goals, but they can’t set your goals, as for that it’s important to understand the company business, culture, values and objectives, and that has nothing to do with technical solutions.