CIO Applications Europe
About UsConferencePartner With Us
Close
  • Applications
      • Business Intelligence & Analytics
      • Call Center Solutions
      • CRM & Customer Experience
      • Data Center
      • Digital Transformation
      • E-Invoicing
      • Intelligent ERP & Automation
      • Risk Management & Compliance
      • Unified Communications (UCaaS)
  • Industries
      • Automotive & Mobility
      • Construction & Infrastructure
      • Financial Services
      • Healthcare
      • Retail & E-commerce
      • Telecom & Media
      • Travel and Hospitality Tech
  • Technologies
      • Cloud
      • Cybersecurity & Resilience
      • Data Engineering & Analytics
      • Generative and Agentic AI
      • IoT & Edge Computing
      • Robotics
  • Platforms
      • AWS
      • IBM
      • Microsoft
      • Salesforce
      • SAP
      • ServiceNow
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • CXO Awards
    • Europe
      • US
  • Topics

  • Menu
      • Business Intelligence & Analytics
      • Cloud
      • Digital Transformation
      • Generative and Agentic AI
      • Microsoft
      • Risk Management & Compliance
      • Travel and Hospitality Tech
      • Unified Communications (UCaaS)
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Generative and Agentic AI
  • Digital Transformation
  • Business Intelligence & Analytics
  • Cloud
Topics
  • Topics

  • Business Intelligence & Analytics
  • Cloud
  • Digital Transformation
  • Generative and Agentic AI
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Unified Communications (UCaaS)
  • Home
  • Risk Management & Compliance

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

Lookers Plc

Matt Foster, Head Of Information & Cyber Security

Enhancing Security to Mitigate Cybersecurity Risks

Matt Foster is Head of Information and Cyber Security at Lookers plc. His expertise in cybersecurity helps companies uphold social contracts by managing risks and deterring and denying threat actors. He has extensive experience in global operating structures, including risk management, regulatory compliance, policy development, security architecture, and cloud security.

What are some of the major challenges and trends that have been impacting the Enterprise Security space lately?

We’re definitely not talking about ‘the new normal’ anymore – because it’s already here.

The current global crises in health, social justice, climate change, war and conflict now demand a rapid rate of change that show no signs of abating any time soon.

Our business and social evolutionary needs are existential in nature but that mustn’t mean we descend into anarchy and throw risk management away.

In today’s challenging and dynamic business and economic environment, enterprise security has never been so important and getting the right architecture in place is paramount. Now, more than ever, we must be able to take pragmatic risk-based decisions quickly.

Firstly, with so many sectors forced into digital transformation by the impacts caused by the pandemic, CISOs have a brand- new set of stakeholders to educate and feed the right information into key decision making.

Secondly, we’re also seeing increasing awareness of the criticality of our supply chains in both physical and digital forms. The risks we saw as unpredictable ‘Black Swan’ events only a few years ago are almost everyday occurrences now, with supply chains more fragile than we may have ever realised.

What keeps you up at night when it comes to some of the major predicaments in the Enterprise Security space?

We’ve been talking about the risk that Shadow IT – the use of information technology systems, devices, software, applications, and services without explicit IT department approval – present for a long time.

For me, it’s the areas where we don’t have good control visibility in the broadest sense that keep me awake. A failure in Enterprise Security tends to be catastrophic in terms of impact, even if the probability is, or at least used to be, vanishingly low. That may well not be a first party one. A successful ransomware attack can be just as devastating down the supply chain – and that worries me.

Just because we have put in defences for our structured data and systems, the ransomware threat does not necessarily go away. Unless we continue to manage vulnerabilities and have robust, air-gapped, and regularly-tested recovery capability, we may as well be crossing the road with a blindfold on.

Can you tell us about the latest project you have been working on, and what are some of the technological and process elements you leveraged to make the project successful?

It’s critical we have confidence in our defences and control effectiveness. Maturity assessments, supplier audits, third-party party assurance only go so far. I need to be confident our locks can’t be circumvented, and we do this through Purple Teaming – ‘mystery shopping’ for Enterprise Security.

It’s early days yet, but I’m going to sleep a lot easier knowing it’s not just the bad guys testing my defences.

Which are some of the technological trends which excite you for the future of the Enterprise Security space?

At a purely geek level, homomorphic encryption provides an exciting opportunity to allow us to not depend on purely contractual controls in the cloud when we really care.

More importantly, I think we’re starting to see a shift in recruitment behaviours. Hybrid working has changed the job market forever, removing geographics boundaries in a way we’ve never seen before. The threat landscape changes too rapidly for us to focus on talent with five years’ experience in technology Z or in defensive capability Y.

Instead, we must, and I think are beginning to, focus on bringing diversity of thought process and problem solving to the security workforce.

I’m certainly proud of the results I’ve achieved with bringing fresh young talent into the cyber security profession.

How can the budding and evolving companies reach you for suggestions to streamline their business?

You can always contact me on LinkedIn (https://www.linkedin.com/in/ mattfoster42/).

Do the basics well, don’t get hung up on the latest and greatest, build security in from the start and most crucial of all – measure everything.

It’s not good enough simply to ‘do’ either. We need to demonstrate we’re doing it – every single day.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping construction technology and innovation. Participation is by invitation only. It features leaders who are not merely observing technological change, but actively contributing to it through digital transformation and execution-driven insights.
EDITOR'S CHOICE
  • Willis Towers Watson

    Legal & General

    Building Technology Foundations That Last

    Mark Hall, Group Chief Technology Officer

  • Willis Towers Watson

    Adp Uk

    "Shift left" Defect Discovery using Agile and DevOps

    Keith Watson, Director Of Devops

  • Willis Towers Watson

    Motor Oil

    Trust, Security Strategy and the AI-Driven Threat Landscape

    Syngelakis J. Christos, Group Data Protection Officer

  • Willis Towers Watson

    Swiss Re [SWX: SREN]

    A Future of Enhanced Human Work

    Sergio Chelli, IT Procurement Manager at Swiss Re [SWX: SREN]

Weekly Brief

loading

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

×
#

CIO Applications Europe Weekly Brief

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from CIO Applications Europe

Subscribe

loading

THANK YOU FOR SUBSCRIBING

CIO Applications Europe
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@cioapplicationseurope.com
  • sales@cioapplicationseurope.com
  • marketing@cioapplicationseurope.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 CIO Applications Europe. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://risk-management-and-compliance.cioapplicationseurope.com/leadership-perspective/enhancing-security-to-mitigate-cybersecurity-risks-nid-3267.html