Manoj Bhatt, CEO and Founder, Cyberhash: “As an industry, we can’t afford to be stuck in our ways”

Few careers in cybersecurity begin by accident, but that’s exactly how Manoj Bhatt found himself in the profession. Tasked with leading a major cybersecurity programme for the Ministry of Justice shortly after a headline-grabbing HMRC data breach, he found himself at the centre of one of the UK’s largest governmental security initiatives.

20 years later, as Founder and CEO of Cyberhash, Manoj continues to help organisations implement security strategies that move beyond technical necessity to create genuine business value. We were lucky enough to catch up with him for this fascinating interview.

Cybersecurity has always been about staying ahead of threats, Manoj points out, but that task has become significantly more challenging in recent years. Businesses must now operate as an “interconnected world,” he says, one in which third parties are just as important as internal teams. With this expansion in attack surface, leaders need to prepare for incidents that extend well beyond their own infrastructure.

Although AI and emerging technologies dominate much of today’s cybersecurity conversation, Manoj points out that the organisations seeing the greatest success are those that have strong and consistent fundamentals. “Successful companies focus on the basics in cybersecurity hygiene,” he explains, from properly implemented multi-factor authentication to well-practiced incident response planning.

Rather than treating security as purely technical, the most resilient organisations are recognising that cybersecurity depends as much on culture as it does on technology.

Having entered cybersecurity by accident himself, Manoj is a strong advocate for diverse career paths into the profession. He believes that technical expertise is only a part of the equation, and that we in fact “need people in cyber from non-technical disciplines”.

In a field like cybersecurity where threats are continuing to evolve, Manoj sees fresh thinking as every bit as important as technical skill, going as far as saying that some of the best cyber individuals he’s worked with have come from non-cyber backgrounds. 

With different perspectives being so valuable in his view of the field, we wanted to start by asking more about Manoj’s own “accidental” path into cybersecurity. One, incidentally, that earned him a place in the CSO Hall of Fame in 2024…

Could you please introduce yourself to our audience and share how you ended up working in cybersecurity?

I’m Manoj Bhatt, CEO and Founder of Cyberhash. I started my cybersecurity journey completely by accident.

In 2007, I was working as a project manager within the UK prison service. In November that year, HMRC (the UK’s tax, payments, and customs authority) suffered a security breach where they lost details of around 25 million individuals. This caused a huge stir across the UK government. All departments were asked to focus on their data to ensure that the same would not happen to them or spread elsewhere.

My role was a simple one: start a cybersecurity project alongside some consultants and practitioners from across the prison service, before eventually handing it over to a more experienced cybersecurity programme lead.

That other person never came. So, there I was, running the largest cybersecurity programme at the time for the Ministry of Justice, reporting our progress to ministers and engaging with teams across the entire criminal justice network.

After this, I continued running cybersecurity projects for the Ministry of Justice before joining Accenture, where I really got a taste for cybersecurity consulting beyond the public sector. It taught me the importance of cybersecurity, not just in governments where there were defined frameworks and guidance, but in the private sector, where it’s not as clear-cut.

I’ve since held senior cybersecurity roles at Sopra Steria, Company85, and then Telstra, helping solve complex challenges across multiple sectors and embed security more strategically across businesses.

Over time, I realised I was most motivated by helping organisations move beyond checkbox compliance and towards cybersecurity programmes that deliver measurable, real-world outcomes. That ultimately led me to found Cyberhash.

What are the biggest cybersecurity challenges those in leadership roles are facing?

Leadership has been facing cybersecurity challenges for a long time now. However, today, the challenges are accelerating in speed and impact.

Not long ago, we were transitioning to the cloud, and then we had to suddenly adapt to a remote workforce driven by the pandemic

Today, we’re seeing rapidly developing threats, risks, and opportunities presented by AI. AI feeds on data. So we are starting to see incidents where AI engines are spilling and publishing data that they shouldn’t.

Leadership has to grapple more and more with these technological advancements in a world where consumer behaviours are changing and evolving, and the macroeconomic challenges push boards continually.

Third-party risk is another big challenge. We are seeing increasingly blurred lines between a business’s boundaries and its third parties (i.e. any external individuals or organisations that the business must interact with to operate). We live in an interconnected world where third parties are just as important as internal teams, and an incident with a third party can be just as impactful, if not more, than an internal incident.

Related to this is the challenge of corporate identities – identifying who is accessing what data, whether they are human, non-human, or third-party. This involves controlling access to data, but firstly understanding what data is being used.

Finally, companies are struggling to plan for incidents effectively. Many times, the response to an incident puts a company in a worse situation than the actual incident. Leadership should focus on testing and practising for when things might go wrong.

Despite these growing challenges, cybersecurity is only one of many things that leadership has to face, and sometimes it’s not the most important thing that a business needs to consider. That’s why it’s always worth looking for help.

What is your take on ethical hackers and their role in cybersecurity?

The tools and techniques that hackers are utilising are always developing. Ethical hackers can help companies identify vulnerabilities before criminals do.

However, I see companies do two things wrong here. First, they don’t implement ethical hackers as part of a broader security testing programme that is reflective of the real threats. And second, they often don’t actually address the risks that are identified.

Many companies take a staged approach to using ethical hackers, i.e. starting at layer 1, they might implement vulnerability management and then focus on utilising ethical hackers. Most companies feel that this is sufficient. But in reality, this is just the beginning.

In today’s world of automation and AI, companies need to focus on continual ethical hacking systems that can scan systems for holes and vulnerabilities round-the-clock.

The next level of ethical hacking, called “Red Team,” allows a team of ethical hackers to carry out reconnaissance on a company, undertake research, and then attack the company in a more realistic fashion. This really starts to test the real impact of a cyber attack and replicates the same approach that criminals undertake. It’s worth bearing in mind that this is costly, and worth ensuring the other basics are completed first.

The other general problem is that businesses are slow or unresponsive to address the gaps and risks that are identified by ethical hackers. They gain visibility, but then don’t close the identified gaps.

That said, many businesses bury their heads in the sand and never utilise ethical hackers, which is a dangerous place to be in my view – especially for SMEs.

Which cybersecurity best practices are being adopted with the most success by companies?

Successful companies focus on the basics in cybersecurity hygiene. Lots of companies still get the simple things wrong. They focus on advanced threats and risks when the basic 101 of cyber is not followed. These techniques have not changed: patching systems, implementing multi-factor authentication, having an incident response plan and testing that plan, to name a few. Yet, the volume of companies that still don’t do this is worrying.

Successful companies also make sure cybersecurity is embedded across the organisation. Cybersecurity has traditionally been seen as a technical discipline solely handled by IT or a dedicated cyber team. But cybersecurity cannot sit siloed within one team, it should be something that the whole business feeds into.

Cultural awareness and education is also important, so that users can spot cybersecurity incidents and don’t click on risky emails. Having multiple eyes and ears on the ground means that a company’s defences are better than relying on just one department to spot everything. This also includes the board, because cybersecurity messaging has to come from the top.

Clever leaders also make the most of experienced specialist third parties – people who can provide independent advice and guidance on the latest threats and risks to businesses. Cyber threats now come from multiple angles, and a company cannot know all of these. Having a partner who can guide and support is critical.

Lastly, the top companies see cybersecurity as a competitive advantage rather than a cost. Implementing good cybersecurity hygiene could unlock new bids or new markets to sell to. More importantly, we are seeing investors wanting cybersecurity embedded throughout the company to increase and stabilise the value of the business.

What’s something that has drastically changed about cybersecurity since you first got started in the field?

When I first started around 20 years ago, it was always about securing the perimeter. Most companies used data centres, so we had a clear boundary and front door that we had to protect.

But then cloud computing introduced multiple entry points into systems. SaaS systems then introduced more complexities around identities and what identities are accessing what.

Today, we’re now seeing the growing risk of third parties accessing company data. Most recent cyber attacks have happened through third parties.

The next iteration of threats from AI will mean that the industry will change again.

When I first started in the industry, physical crime – such as breaking into banks – was very real, but this is almost unheard of today. Cyber attacks and digital crime have become the weapon of choice nowadays because they are extremely lucrative. The threat that companies face rises exponentially every day.

The one constant since I got into the field is that cybersecurity never sits still. The threats and risks are constantly evolving.

What advice do you have for aspiring professionals wanting to work in cybersecurity?

Never stop learning. Build communities and constantly learn about the new technologies and threats that we are facing.

Because technology moves as quickly as it does, you have to continue to learn and evolve, while still learning and respecting the basics of good cyber hygiene.

Also, as cybersecurity becomes more and more ingrained in the business, having a business acumen – as well as technical cybersecurity skills – is really important. Move around different departments, really understand the business. Only then can you start to protect it. I feel that too many people want a job straight into cyber. But most of the great cyber practitioners I know started somewhere else and then came into cybersecurity later. Being able to translate that business context into cyber and vice versa makes the most effective approach.

The importance of diverse backgrounds, both from a job perspective but also from a neuro and gender diversity perspective, is really important. This also means we need people in cyber from non-technical disciplines. Some of the best cyber individuals I’ve worked with have come from backgrounds such as legal, marketing, art, and elsewhere. We need people to push the status quo because the criminals are doing this, and they themselves don’t always come from cybersecurity backgrounds.

As an industry, we can’t afford to be stuck in our ways. Just because we did something previously in one way doesn’t mean it’s right. We have to be dynamic and come up with new ideas.

More interviews

About The Author

Rowan Campbell TechFinitive
Rowan Campbell

Rowan is a writer for TechFinitive focusing on technology companies doing interesting things all around the globe. He is currently studying philosophy at university.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.