THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for finance technology leaders, nominated by our subscribers and vetted by the Insurance CIO Outlook Editorial Board.



Matthew Mudry is the Chief Information Security Officer (CISO) for HomeServe, overseeing Information Security, IT Compliance and Governance. He previously led the security programs for CareCentrix and Castleton Commodities International. He holds an Arts degree from Fairfield University and a B.S. in Information Security from Capella University. With over 25 years of IT experience, leadership and certifications like CISSP, CISM, GSEC and CCSP, Matthew focuses on business-aligned cybersecurity strategies.
My Journey In Technology And Leadership
I’m one of the lucky ones who found a passion for computers early in life. As a teenager, I was fascinated by how they worked and how they could be broken down and fixed. That passion led me to my first role as a desktop support engineer. From there, my curiosity grew as I explored networks, infrastructure and software deployment.
I was fortunate to move through different roles—desktop support, networking, servers and software teams—gaining a well-rounded understanding of IT. I also worked across various industries, learning how organizations use technology to engage customers and employees. These experiences shaped my career path.
A significant turning point came 16 to 17 years ago when I transitioned from hands-on technical work to management. Like many, I initially struggled with letting go of tasks I once handled myself. While I had no trouble setting roadmaps, giving up control was difficult—I felt my worth was tied to my work. With the guidance of great mentors, I realized leadership isn’t just about doing but also guiding and enabling others. Once I embraced that mindset, my focus shifted from improving my tech skills to refining my leadership—helping my team grow, become better technologists, and strengthen our security program.
Key Security Challenges and the Role of AI
Cloud security is a major challenge. In traditional IT, we had complete control over networks and systems, managing what came in and went out. Moving to the cloud means giving up some of that control and trusting cloud providers. The challenge lies in determining how much trust we place in providers based on their architecture, security and transparency.
Another issue is shadow IT—employees, consultants, or contractors signing up for cloud services without going through proper channels. While companies encourage innovation, this creates security blind spots. To address this, we monitor corporate email and web activity to track new cloud services, ensuring they undergo procurement and security reviews. We don’t just block services; we guide teams toward secure alternatives.
“Leadership Isn’t About Just Doing But Guiding And Enabling Others”
AI and automation play crucial roles in security. AI helps detect and, in some cases, respond to unusual behaviors. For example, if someone badges into the office and connects to a VPN minutes later, that’s a red flag. AI can flag these anomalies and trigger automated responses—locking accounts, isolating devices, or blocking suspicious actions.
AI also enhances threat intelligence. It continuously updates security controls with indicators of compromise, reducing manual workload. We use AI to identify patterns—such as users hopping between hosts, downloading large amounts of data, and accessing email. Automated responses may include network isolation, URL blocking, or further investigations.
Future Cybersecurity Trends And Strengthening Teams
Password compromise remains a top threat, followed closely by phishing and social engineering. These attacks persist because people are still the weakest link in security. Browser security is also emerging as a major concern, with malicious extensions capable of stealing credentials and monitoring activity.
The future lies in zero-trust identity—moving beyond traditional passwords, even two-factor authentication. Organizations must shift to identity-based security, incorporating device recognition, geographic factors and behavioral analytics. Passwords alone are no longer sufficient. Facial recognition, fingerprint authentication and certificate-based device verification are the way forward.
Combatting social engineering requires continuous training, but we make it engaging. We gamify security awareness, rewarding employees for reporting phishing emails or challenging unauthorized access attempts. If I catch someone practicing good security hygiene—like questioning an unbadged visitor—I’ll reward them on the spot with a gift card. Security culture needs to be ingrained, not forced.
As companies rely more on cloud tools, browser security is critical. Malicious extensions can steal data, record keystrokes and track financial activity. New technologies can isolate browsers, restrict extensions and control outbound data. As cloud adoption grows, this will be a key focus area.
Security teams must constantly evolve. I push my team to take security training each year to stay ahead of emerging threats. Attending conferences, industry sessions and training programs is non-negotiable. A stagnant team weakens an organization’s security posture.
I also instill structured security practices, like daily runbooks, that require teams to check intelligence feeds, review industry threats and proactively address risks. Manual oversight, paired with automation, helps keep security robust.
Essential Qualities for Leadership in Cybersecurity
Passion is essential in cybersecurity leadership. The field moves fast, and without passion, leaders can easily fall behind. Leaders must stay engaged, inspire their teams and drive innovation.
There are two common paths into cybersecurity leadership: one from policy, legal and compliance and the other from a technical background. I believe technical expertise makes for a stronger leader. Most risks originate from technical vulnerabilities and understanding the underlying tech allows for better decision-making and collaboration. It also ensures realistic expectations when asking teams to implement solutions.
Leadership requires knowing when to let go of hands-on work and focus on strategy, guidance and team development. Success isn’t just about securing systems—it’s about building and mentoring a strong team. I have conversations with my team to understand their career goals, whether they want to grow as technologists or transition into leadership. Collaboration, communication and a cohesive team culture are critical for a successful security program. When a team is aligned, security becomes second nature.