Security Starts Within
Building Serbus’ Security DNA from the Inside Out
For us, security and resilience start from within. If we are going to design, build and operate secure communications infrastructure for the UK’s most critical national services, those same principles need to be part of our own security DNA, embedded in every fibre of how we operate.
Driving this approach across the business is Group IT Information Security Manager Jimmy Wright. Drawing on more than four decades of experience across highly regulated and critical environments, Jimmy brings first-hand expertise of what the highest standards of security, governance, assurance and resilience look like in practice. Here, he offers more insight into his experience, the lessons he has learned along the way and how they are helping to shape our security DNA from the inside out.
With more than four decades of experience spanning industries such as automotive, insurance, Civil Nuclear, Policing and other highly controlled and regulated environments, Jimmy understands exactly what it takes for organisations to operate securely, especially when resilience, governance, assurance and the management of sensitive information really matter.
He began his IT career in the 1980s as a UNIX/LINUX System Administrator, under what was a very different technological landscape. Since that time, he has experienced first-hand every major technological shift, moving from systems that were once largely isolated to the highly connected IT, OT and communications environments organisations rely on today.
Jimmy’s career has seen him carry out senior information and cybersecurity roles across America, Canada, Africa and Europe, building extensive skills and expertise, not only in information security, but in the governance, infrastructure and processes needed to manage increasingly interconnected technology.
Most importantly for his role today, Jimmy has seen first-hand what the highest standards of security, governance and resilience look like in critical environments, and what it takes to embed them into day-to-day operations, rather than simply document them as policy.
Building our Security DNA
A key part of Jimmy’s role at Serbus is to embed our security DNA throughout the organisation. “Security DNA goes far beyond cybersecurity or achieving individual accreditations,” he says. “It is about establishing the governance, processes, behaviours and standards that allow us to operate securely and resiliently. Working in sectors such as Civil Nuclear and Policing gives you a real understanding of that. If we are going to advise, design, build and operate secure services for customers working in critical environments, we need to apply those same principles to ourselves first,” Jimmy explains. “The standards our customers expect from us externally have to start internally. We need to hold ourselves to the same standards we take into our customers’ critical environments.”
As we continue to expand organically and through acquisition, Jimmy’s focus is not simply on maintaining security today, but ensuring our governance, security, compliance and assurance processes evolve at the same pace as the business.
“A large part of my role is making sure we have the right foundations in place to support our growth,” he says. “That covers everything from creating a secure environment where colleagues can work and collaborate effectively, to making sure we have repeatable processes for bringing new businesses into the Group securely.
“Acquisition brings together different businesses, people, technologies and specialist capabilities, so having consistent standards around governance, security, risk and assurance is incredibly important. It’s also an important part of building one Serbus. As specialist businesses and capabilities come into the Group, consistent security and governance provide a common foundation, while allowing us to retain the expertise that made those businesses succeed in the first place.”
Taking experience into critical environments
Jimmy’s experience has a direct connection to many of the customers and markets we serve.
His time within UK Policing, for example, has given him first-hand understanding of the governance, assurance and resilience required within an organisation responsible for critical services and sensitive information, governed through the Home Office’s Digital Police Service. Those principles transfer directly into the environments Serbus supports today, including Police, Government, NHS and Fire and Rescue Services, where the availability and resilience of communications can be every bit as important as their security.
The same applies to his Civil Nuclear and earlier industrial experience. As IT, OT, networks and communications have become increasingly interconnected, the boundaries between them have blurred – making it more important that security is considered across the whole environment rather than sitting within an individual system or function. That convergence is increasingly relevant to Serbus as we bring together secure communications, digital infrastructure and services across environments where IT and OT operational communications can no longer be considered in isolation.
Making security part of the process
For Jimmy, the key to successful secure communications and secure infrastructure is ensuring that security is considered from the outset.
“Secure by Design has to become the norm,” he says. “It means thinking about security throughout the whole lifecycle, from how we advise and design, to how we build, operate and monitor services. It needs to be part of the process from the beginning, not something considered at the end.
“The process must also be ongoing. You have to keep learning and improving, investing in systems and processes, adopting best practice, implementing it and then looking at how you can make it better. Technology is constantly changing, business is constantly changing and with them the risks change too. This is particularly important in the critical environments we support, where security is as much about resilience and continuity as it is about preventing an attack.”
Compliance and accreditation provide an important foundation, but for Jimmy, they are not the ultimate measure of good security.
“Compliance gives you an important framework and baseline. From here the objective is to build a secure and resilient organisation where those standards are reflected in how people actually operate every day.
“When I first worked in information security, the security team was often viewed as the people who told you what you couldn’t do,” Jimmy says. “Today, security should be an enabler. For Serbus, the right governance, assurance and processes give us the confidence to innovate, integrate new businesses and grow within highly regulated and critical markets with relevant risks understood and managed. It’s about enabling the business to move forward securely, rather than putting barriers in the way.”
Ultimately, our Security DNA connects how Serbus operates with how we deliver for our customers. By holding ourselves to the same standards we take into critical environments, we can grow with confidence while continuing to deliver the secure communications infrastructure and services our customers and the UK rely on.