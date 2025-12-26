Information security used to be a game of rules, not relationships. The job was simple: protect the system by sticking to the rulebook. Security teams were like referees on the pitch — watching for fouls, enforcing the rules, and blowing the whistle at the first sign of trouble. If the policy didn’t allow it, the answer was no.

But that’s not the job anymore. Modern security isn’t about putting up barriers; it’s about using judgment, influence and communication to help the business make smart decisions. Today’s security professionals aren’t gatekeepers — they’re problem solvers, coaches and collaborators. The shift is driven by a simple reality: digital systems are now woven into every corner of the business, risk moves faster than any rulebook can and security must be a defender that enables innovation rather than becoming a barrier to it.

That’s why information security has evolved from a technical niche into one of the most dynamic, people-focused roles in technology.

The Evolution of the InfoSec Role

When I started in information security more than 25 years ago, we typically worked within closed systems. At AstraZeneca, where I began my career (Zeneca back then), the mainframes weren’t connected to the internet. The biggest risks were misconfigurations and insider errors — problems you could often fix by tightening controls and enforcing a strict, zero-tolerance approach to anything outside the security policy.

Then came the internet, cloud computing, social media and mobile. Suddenly, the digital perimeter disappeared. Businesses became interconnected, always-on, and globally exposed. It has been a period of incredible innovation but with it, each new channel has expanded the surface area of attack and introduced fresh opportunities for exploitation.

As the risk environment expanded, so did the role of the security professional. Information security evolved from a solitary pursuit into a team sport spanning infrastructure, cryptography, data analysis, compliance and human behavior.

From Safeguard to Strategic Priority

Part of what’s made information security so compelling today is how visible it’s become. Data breaches, ransomware and nation-state attacks dominate the headlines. That visibility has reshaped public perception and with it, the level of respect for the profession.

Today, boards and governments recognize cybersecurity as a strategic priority. But the role has become fascinating for another reason too: it demands judgment. There’s no playbook that can cover the pace of change. Every day brings new threats, new technologies and new dilemmas. That need for constant interpretation is why information security has become such a dynamic, people-centric discipline, and why it now demands a new skillset.

Creativity as a Core Security Skill

To me, the difference between science and art is adaptability. Science follows a formula. Art demands interpretation and cybersecurity sits firmly on the artistic side.