An interview with its founder and global cybersecurity thought-leader JC Gaillard
JC, before we discuss the Foundation’s future, tell us why you created the Security Transformation Research Foundation in the first place.
The Foundation was created because, together with my business partners at the time, we increasingly felt that many of the biggest challenges facing cybersecurity were no longer technical—they were organisational, managerial and strategic.
We were also shocked by the recurring nature of some topics in cybersecurity conversations: Why are we still talking about the reporting line of the CISO, or the difficulty in convincing the Board? What is this telling us about the real nature of cybersecurity leadership in large firms?
For decades, our industry has invested enormous amounts of energy into developing better technologies, better frameworks and better standards. That work remains essential, but it has also become clear that many cybersecurity failures occur despite organisations having access to significant resources and technology.
The missing ingredient is often execution; in particular cross-functional execution.
Large organisations struggle to transform themselves. They struggle to sustain long-term cybersecurity programmes. They struggle to align business priorities with security objectives. They struggle to maintain executive attention once the immediate crisis has passed.
These are management and cultural problems far more than technology problems.
The Foundation was established to study those issues objectively and independently, free from commercial pressures or vendor agendas, deliberately taking the problem beyond the tech agenda, into leadership, governance and cultural areas.
Why did you choose to create an independent foundation besides your commercial activities?
Because independence matters.
Every cybersecurity vendor naturally promotes its own technology. Every consulting firm naturally promotes its own practices. There is nothing wrong with that—it is how businesses operate.
But very few organisations can afford to step back and ask broader questions about why large-scale cybersecurity transformation succeeds in some organisations and repeatedly fails in others.
That is the space we wanted to occupy.
Our objective has never been to sell products or consulting engagements.
Our objective has been to advance understanding.
We wanted to create a platform where open and honest conversations could take place without commercial bias. Conversations rooted in the common sense and real-life experience of practitioners across all functions, not just CISOs, but also CIOs, CTOs, auditors, compliance experts.
Your research often argues that cybersecurity failures are leadership failures rather than technology failures. Is that still your view?
Absolutely.
Technology continues to improve at an extraordinary pace. The same cannot always be said about organisational capability.
Many organisations still approach cybersecurity as a sequence of disconnected projects rather than a matter of long-term business transformation.
Executive teams often underestimate the complexity of organisational change.
Boards frequently receive metrics that describe security activity rather than security effectiveness.
Leadership teams continue to focus heavily on annual budgets while transformation requires sustained commitment over many years.
These challenges have very little to do with selecting the right technology.
They have everything to do with leadership, governance, organisational design and cross-functional execution. Those are the topics the Foundation focuses on.
How has the Foundation evolved since it was launched?
Initially, we focused almost entirely on publishing research, articles and thought leadership.
That remains an important part of our mission.
However, over the last few years we have realised that research alone is not enough.
Publishing ideas is valuable.
Creating conversations around those ideas is even more valuable.
The cybersecurity community increasingly needs neutral forums where senior executives can openly discuss strategic issues without immediately turning every discussion into a product demonstration.
That observation has shaped our next phase.
The Foundation is now moving towards organising events. Why make that transition?
Because meaningful conversations happen when people meet.
Research provides ideas. Events create dialogue. Dialogue creates communities. And communities are ultimately what drive change.
Our ambition is not to organise another technology conference.
The industry already has many excellent conferences showcasing products and technical innovation.
Our focus is very different.
We want to create executive-level discussions around cybersecurity leadership, governance, organisational transformation, resilience, board engagement, and the future evolution of the CISO role.
Those conversations deserve their own platform.
What will make these events different?
First, independence.
The programme will not be driven by product launches or vendor marketing cycles.
Second, seniority.
Our target audience is the people responsible for making strategic decisions—boards, CEOs, CISOs, CIOs, CROs, regulators, investors and business leaders.
Third, quality of discussion.
We want honest conversations about why transformation is difficult. Why organisations accumulate security debt. Why many cybersecurity programmes lose momentum. Why governance often breaks down. And how organisations can realistically improve.
Our ambition is to build forums where people leave with new perspectives rather than simply collecting another bag of promotional material.
You are now inviting sponsors to support these initiatives. What are you looking for?
We are looking for organisations that genuinely believe in advancing the cybersecurity profession.
Of course, sponsors receive visibility. That is entirely appropriate.
But what we are really seeking are partners who share our commitment to raising the quality of strategic conversations across the industry.
Sponsors will help create an independent platform that benefits the entire cybersecurity ecosystem.
The return is not simply brand exposure. It is participation in shaping the future direction of cybersecurity leadership.
Does sponsorship influence the Foundation’s research or editorial independence?
No.
That principle is non-negotiable. The Foundation’s credibility depends entirely on its independence.
Sponsors support the platform. They do not determine the conclusions. They do not influence the research agenda. They do not edit our publications.
That separation is essential.
Without it, we would lose the very thing that makes the Foundation valuable.
Who do you hope will participate?
Our ambition is to bring together people who rarely have the opportunity to exchange ideas openly.
- Senior business executives.
- Cybersecurity leaders.
- Government representatives.
- Academic researchers.
- Investors.
- Technology providers.
- Professional associations.
- Regulators.
Different industries face different challenges, but many of the underlying organisational issues are remarkably similar.
Creating dialogue across those communities is where want to make difference.
What topics do you expect will dominate the Foundation’s agenda over the next few years?
It is going to be difficult to avoid talking around Artificial intelligence and its governance, but besides that, several other topics stand out.
- Cybersecurity transformation in an increasingly uncertain economic environment.
- Post-quantum cryptography and long-term preparedness.
- Cyber resilience and what it really entails.
- Board engagement and how to make it work in real life.
- The evolution of executive accountability.
- The future operating model of cybersecurity functions and role of the CISO.
Most importantly, I believe we need to move beyond discussing “what” organisations should do and spend much more time discussing “how” they can actually achieve sustainable change.
That “how” question has fascinated me for over twenty-five years.
It remains the industry’s biggest challenge.
Finally, where do you hope the Foundation will be five years from now?
I would like it to be recognised as one of the leading independent forums for strategic cybersecurity thinking.
A place where serious conversations take place. A place where executives can challenge conventional wisdom and vendors agenda. A place where research informs practice.
A place where practitioners, academics, business leaders and policymakers come together to improve how organisations protect themselves.
Cybersecurity has become one of the defining leadership challenges of modern organisations.
If, in five years’ time, the Foundation has helped shift even part of the industry’s attention from technology alone towards leadership, governance and successful execution, I will consider it to have fulfilled its purpose.
Read more on our Security Transformation Leadership publication here on Medium
