TrollEye Security

Jeff Moore Episode

Conversations with CISOs, Security Leaders & Technology Executives
Podcast Episode

How a CISO Protects Billion-Dollar Brands

Jeff Moore shares lessons from leading security across global organizations, including how CISOs can understand business and brand culture, identify the risks that matter, make security decisions within real-world budget constraints, and build a more mature security program.

Security Leadership Business & Brand Risk Security Investment Program Maturity
Jeff Moore
Featured Guest Jeff Moore CISO at H&M
Featured Conversation Watch the Full Episode
Episode Takeaway

Protecting a global brand requires more than adding security tools. CISOs have to understand the business, identify where risk actually exists, work within real-world constraints, and build processes the organization can consistently execute.

Explore the Conversation

Episode Chapters & Full Transcript

Select any chapter or transcript timestamp to begin watching from that exact point in the episode.

Complete Conversation

Full Transcript

Sullivan Tuck
Sullivan Tuck

Welcome to Conversations with CISOs, Security Leaders and Technology Executives, where we sit down with the leaders shaping cybersecurity and enterprise technology. Today I'm joined by Jeff Moore to discuss how a CISO protects billion-dollar brands. Jeff, thank you for taking the time to join me today. To get us started, could you introduce yourself and tell us a little bit about your background and your current role?

Jeff Moore
Jeff Moore

I normally say I'm Jeff Moore, I do security shit. Yeah. Right, but I'll elaborate for you. I'm a CISO, right? And what all that entails is a headache in itself. I've been doing this for many years. I'm currently at the CISO at H&M and having a great time. Yeah, background I've been working in pharmaceuticals and medical research in medical devices, retail, I did a small stint in some rituals. So yeah.

Sullivan Tuck
Sullivan Tuck

Alright. So as you mentioned, you've led security across several different companies and industries, including Novartis, Draeger, Staples, Draeger. Draeger. I literally looked up before we did this how to say it and I still got it wrong. Draeger, Staples, Gap, and now H&M what challenges have followed you from company to company despite the differences between them?

Jeff Moore
Jeff Moore

It's interesting because I talk about this quite a bit. There's very few challenges that differentiate any of those sectors. The largest thing that you'll see that crosses all of them is asset management, first of all, and vulnerability management. Those two are the, shall we say, the concrete shoes of every CISO when he walks in, they're still there. He's left one with the same problems and comes into another one with the same problems. We do get better at it for a while. And then depending on if you buy a new company or you're de-vesting a company or you're moving data centers, then the asset management goes hay-wire again. But it's always a challenge to try and keep those the number one priority of an organization.

Sullivan Tuck
Sullivan Tuck

So how do you approach those? How have you gone about approaching asset management, vulnerability management at your organizations?

Jeff Moore
Jeff Moore

Well, it depends on first off the culture of the organization, right? Because if you can match your strategy and direction to the culture, it's accepted and brought in and understood better. Right? But most of the time, it's actually going back to the basics, right? Trying to figure out why it's not happening, right? And if you take like some in retail, if you take an example, there's also a blackout period. And in that blackout period, they try not to do much because that blackout period is normally when you've got Black Friday or Christmas sales and all stuff. So they're trying not to make too many changes to the environment and scared of whatever changes happen is gonna maybe impact the sales. Which is a valid point, right? Because some of these areas are where they make maybe 50 % of the profit for the year. But also if you take pharmaceutical companies and... research companies, some of those things can't be touched because they're doing computational work or in some cases, you know, they're manufacturing systems and may not have some of those. But getting understanding the assets you have and what patch level they are also helps you figure out what mitigating controls you can have through the environment. And quite often, depending on your organization or where you are, you're building more mitigating controls and actually being able to patch them. Because in a couple of my organizations, some of those systems couldn't be patched because those companies weren't around anymore. But the technology was still being used massively. And it is a challenge. I'll be honest, every company is challenge.

Sullivan Tuck
Sullivan Tuck

So on the culture aspect, what are some cultural challenges you've experienced in your experience and how have you gone about working through those?

Jeff Moore
Jeff Moore

So let me just give you an idea of some of stuff. You have multiple cultures in companies. So I'm hiring right now for a couple of positions. And problem is when this comes out, all people listen to it, those positions may be gone. So just qualifying that right now. But I've been talking to some people, like some Americans, some British, and something else wants to culture the company. And I said, well, actually, quite often, I have to talk about four cultures. I talk about security culture, which is one which is integrated with the IT culture in a way. It's not completely integrated like anything, but we have ties over. Then you have the corporate culture, which your cultures are involved in, and then you got the Swedish culture, which is outside. And you have to understand a lot of those to be successful as a person working in Sweden, but also a person working in H&M and it's the same when it was Gap. Gap had their certain cultures, IT culture was different to the design culture and all this stuff, but they are overlying on technology. Once you understand those and talk that language and understand those tribes, you can actually build a better rapport and understanding. If you try and change cultures or you want to be very different from the other culture, then you're not accepted as well. So if you can understand the culture, then you can move into it. But what is also very interesting, an example is when I was a... like the GAP culture and the Adidas culture and in some of the H&M corporate culture is very much the same. Everybody thinks they're unique, but it's very much the same. So when I moved into GAP, I had a meeting with the finance team and the finance team wanted to explain to me their processes and everything and all that stuff. And one of the ladies there was like, Hey, Jeff, I remember you from Adidas. I was like, hi you were, and she said, I worked with this team. I was like, yes, I remember because my controller was like, says, do you want me to explain to you this in a Adidas speech? I'm like, yeah, I'd love it. 15 minutes later, she said, you get it now? I said, yeah. I rigged up and her boss was like, how do you now understand it all? I said, because a lot of this is the same. You're using the same technology, the same systems, just different names for it. So she explained it to me, I imagine. This meeting was an hour and 15 minutes. We were over in 20 minutes. And I told her boss, if you were listening, you could go now apply to Adidas. Yeah. Because it's so much the same, right? There's a lot of the same cultures, the way brand companies are. You've got to understand that a lot of companies, even though they're a fashion company or they're a retail company, actually they're a very brand company, right? And the brand is very important. And this permeates through the organization, which it should, do not get me wrong, right? And if you understand how to fit that part of the brand and talk about how that brand or whatever you're doing affects the brand, and they have multiple small brands, but it's just one brand view, right? with that communication and understanding those cultures and those different brands, you are lot more effective.

Sullivan Tuck
Sullivan Tuck

So when a CISO enters a billion-dollar organization, obviously as you just stated, they gotta understand the culture, but they also have to determine where the greatest risks actually are. So how do you do that when you enter a new organization?

Jeff Moore
Jeff Moore

It's actually interesting because I'd love to say this one way, right? But one of the first things I do is get the last four breaches they've had or massive incidents, right? It doesn't have to be a breach that was outside the world, but the biggest incidents they had. And then go through the root cause analysis, right? And then have a look at the remediation, what was done, what was not, right? Because a lot of these go in with really big ideas and they really want to make change and then after a while it doesn't get to where it needs to go. The other thing I do is I tend to spend a lot of time with my peers and my business partners because if you ask what do they see as the biggest risks, they're gonna see it in their area. And then you take that and you're spectating it across all the other areas that you're hearing and seeing what are the commonalities. You'll see quite a bit of commonality across the board, right? And that should start fitting into your 30-, 60-, 90-day plan, right? I never come up with a plan of where I'm going until I'm at the 90 day because based on who you talk to, right, is always interesting. Because you'll get from your team like, you know, infrastructure is not great and this is all their problems. You go to infrastructure and they're like, security doesn't help us and we're having problems and there's a lot of friction and all that stuff. And you realize that's not a risk, but it's adding to the risk. Because we're not fixing it. So the idea there is then to try and understand getting everybody together. So once you get people more working together, those risks are more discussed in an open tape. So once we get those, we get them documented, I put together a plan and I communicate it in one meeting with everybody where this plan is going. Because it's not good going to multiple stakeholders with each one telling them the plan. If you talk about all of them, and then quite often all of them will comment at the same time about what's going on, you can make it a quicker, more effective meeting. And then sometimes you're having to put risks in the risk register, and then you have to explain it. But I tend to try and focus on understanding the people who work there. And then the very interesting one is finding out who should I talk to, because you'll find out there's a very interesting underground of people who know more of the risk in the organization that at the top don't. So you'll go further down and meet with other people. And as a CISO, you should go as far down an organization you can't talk to people because you'll know and find out more and more. Right. And the more you find out, it is not fun, Ha. but it helps build a better plan.

Sullivan Tuck
Sullivan Tuck

So once you understand those risks, which security decisions do you typically prioritize first?

Jeff Moore
Jeff Moore

That's interesting. Because right now, there's a whole bunch of stuff in every organization. And if you look at what risk you prioritize, it kind of moves depending what's going on. But what I tend to prioritize is not the risk, it's where the organization is. Because if you look at the current risk, it may not be there if you know the organization's moving in the next six months somewhere else. So even though it's a high risk, you may actually lower it because where they're going, you need to actually fix before it becomes a risk. But quite often, I also always try to ensure if I don't have one, build a risk committee. Because in some cases, I also want them to sign off on these risks of where I'm going and understand the risk because. Quite often I may be coming for them for the support because I can't do everything or budget, right? Or last but not least, actually support to go and talk to another part of the organization and all that. And quite often once everybody understands the risk, we're all talking the same language, right? And it's very interesting because I've gone into some organizations, right? And... and evaluated risk and to me this was high risk-based on the different people I talked to and they got actually the true business leaders in there and they go actually we know about this and actually it's marked lower because we know this over here and you're like I didn't know about that so it actually your balance starts figuring that out from that risk committee and there are companies that do risk committees every six months all right but when you're starting out, it's always good to do them as often as possible. You align with them because they're all busy. Let's be honest, we have so many meetings. But I try very hard to align with them and get them more in. Once we understand them, we start getting this in a better place. We can do this every six months a year, but also it gives us the ability to show to our auditors, to our insurance brokers that we are actually talking about this very often. And they're very supportive. But there are some that you cannot say we can't do. you actually take that before a risk committee to the right stakeholders and talk it through. And then sometimes I've had to go, look, we know we can't fix it and get the CEO or part of the board to sign off on it. I don't like the board signing off on it because they're outside of the situation. It has to be CFO, board, CIO, depending where it is a new organization. If an organization is very flat and you have multiple brands in there, Sometimes a brand accepts a risk but doesn't realize that actually they're in the same pool. So whatever happens in that pool, everybody's going to be affected. So if one person pees, we're all swimming in it, right? So then it goes up to the CEO or the CFO and they'll, hey, this is actually the true risk. They want to accept it, but you own the whole pool. So are you going to accept somebody peeing in your pool?

Sullivan Tuck
Sullivan Tuck

Right. So as you identify risk and you get you know, maybe you get the investment to deal with it, how do you know whether an investment in risk reduction is actually helping?

Jeff Moore
Jeff Moore

So there's two things, right? I talk, people talk about, you know, we buy things based on risk and actually we don't buy things based on risk. Nobody does. No CISO buys based on risk. Unless you've got an unlimited budget, right? You look at the risk, right? And let's say the risk is, let's take it to a car, right? We take a car, right? You and I, we both want a Maserati. We love a Maserati. That's what we want. want four wheels, drives real fast. States is kind of boring because you can't drive real fast, but we're in Germany at the time, Ha. right? So we four wheels we want to But actually Maserati costs, you know, it's a good six figure number, but you and I only have four figures. may even have three figures, but let's go with four figures. But actually it's a low-end four-wheel. I hope you have at least four figures if you're trying to buy a car. So we ended up buying a Volkswagen Golf. It's fast. Right? It's great. can go top speed on it. Because truly you're doing budget-based security. Right? I need four wheels. Right? So when you look at whatever you're doing, yes, the risk is this, but actually what you're buying is budget-based, not risk-based. Right? Because your budget doesn't able to cover the complete risk. Or if it does, it may not be the best product because you don't have the budget for it. So if the product is a million dollars and you have a hundred thousand, you may not be buying that Palo Alto, you may be buying that FortiGate, right? Because it has 80 % of the features and you still have some of that risk involved. So you have to document that, I couldn't do everything, right? And this comes down to the same conversation every CISO should be having and every security leader should be having with their vendors. The first question you should because what does your product do extremely poorly? Because they're going to tell you every great thing it does, but the part that it doesn't do well is what you either have to find a compensating control, somebody to do it, or a technology that covers that part. And it's the same question you should be asking in an interview. What do extremely poorly? Because if I'm hiring a guy who's going to have a big budget and says, finance isn't great, I'm hoping that I have somebody that can do the finance for me. My officer of the CISO so that he can focus on what he's really good at, right? Because even if I send him to all these math classes and his budget classes, he may only be mediocre. And I spent more effort trying to get him there. So knowing your budget, what risk you can cover in that money. Is the key part and then documenting what it's not covering. Sometimes you'll get the additional money later, maybe later in the year. Maybe you'll have to do it next year, but it truly, we all do budget-based security. We don't do risk-based security. The risk helps us in some cases, but the budget is exactly what we have to buy. And that's why saying we don't all have unlimited knowing what that tool, that thing you're doing doesn't cover is the outlier. Add some additional risk.

Sullivan Tuck
Sullivan Tuck

So speaking of budget-based security, what tends to separate a organization that has a genuinely mature security program from one that's just simply funded and filled with tools?

Jeff Moore
Jeff Moore

They both think they're mature. it. That's actually a very good question, right, because I think a lot of people actually don't think about that. And the thing for me is, that's one of the first things I ever think about when I go into a new job. What's their landscape look like, their tool landscape look like, and how do they think they are, right? And it's a very big difference to, if I have every tool in the universe, you end up talking to the SOC people and like we're burnt out because we just get thousands and thousands of alerts. We're not correlating properly and all that stuff, but you know, the board are like, but you've got all these great tools and providing us with great metrics and you know, and we asked your people the NIST CSF and the Euro 3.5 and you're like, well actually I'm not, right? You know, and I need to go back in to look at this. Mature companies have the right processes. The problem is the right processes are not useful if nobody's following the process, right? So they think they're mature, but the process is there, but nobody's doing it, right? So I don't think I've ever, and I've worked in a pharmaceutical company that has huge regulations. I've worked in retail. I've worked in... I've never truly found a true mature company, right? And I'll go in the interview and they're like, we're really mature. We have this and we got that. And we do this and we do that. You know, our click rate on phishing is so low and all this stuff. And then when I get in and start digging and realizing, well, it's actually not what you think it is. It's just because you're looking at sections and not added in together. And if you put the big picture, right. And I don't think, truthfully, that all our CISOs out there can actually build a really mature security organization because you have to have a thousand percent buy-in from all the other areas around you, right? You know, and you know, we can put as much policy and process in place, but if people go around it or, you know, you have shadow IT and now shadow AI that negates some of those, you're back to being not mature. Right. I think we all get to the best we can based on our reach. Right. The acceptance from the organization and security. Right. You know, banks. I worked with banks and talked to some CISOs like, know, we would love to be at this level of maturity, but we will never get there because we have these technologies behind us, right? I had the same issue with pharmaceuticals. You couldn't go that far, right? You know, because half of my backend systems can only have eight character passwords that are just numeric, right? You know what I mean?

Sullivan Tuck
Sullivan Tuck

So what's the balance?

Jeff Moore
Jeff Moore

Passwords are one thing, but the maturity is across the organization. Do people understand security? Because maturity isn't just your organization. It has to be outside as well, because IT has to be mature to understand how working with a mature security organization is right. If your organization is certified, and the rest of the organization isn't, are you mature and they're not? They might be actually following their processes and you're only mature in this universe, or mature based on your... compliance, right? And if you look carefully, PCI keeps changing their compliance because they're to mature their way. I know, It decided to zoom in. PCI, get in there. It is trying to mature their processes to help companies mature their PCI environment, right? Because, you know, they want to protect the credit card data. Well, actually trying to protect credit card people and customers at last, but they are trying to protect them in a way. So it's a very interesting balance, right? Maturity is also very subjective, right? And maybe that's the reason I've never been in a mature company, because how I think of maturity is maybe too high,

Sullivan Tuck
Sullivan Tuck

right? Right. So what would you define as a mature organization?

Jeff Moore
Jeff Moore

I think that's a trick question. I think that's definitely a trick question. As a lot of my friends would say, that's a trap. But I think mature company is a company that works really well together, understands what security is, understands what IT is, understands how to do things right, follows process, policy, works closely with one another. Listens to both sides. Maturity starts truly with listening. If you understand what they're trying to do and where they're trying to go, you need to be there first. Right? So I always say to my leaders, it's like a climb up Mount Everest, right? Actually the climbers don't go first, the sherpas go first, they make sure the paths are clear all the way up there, they build the base camp, they build the camp so you get there, you're safe and all that stuff. That's what we should be. Security should know where you're excuse me, know where you're going, and like I was saying to my head of infrastructure a couple weeks ago, I need to know where you're moving next. So let's just say for example, you're moving into AWS. My forward team should be in AWS figuring out what controls you need to put in place, how the identity schemas are going to look. The how we're move logs and get all that stuff into my into my SIEM and all that before you even show up right and when you show up we've already got all those things in place right we've already figured out the security groups do we need firewalls additional firewalls this is going to talk to the outside world or not if it is let's figure out those controls really quick before you're even there so when you do move in there it's not like we're learning and slowing you down actually we're just watching now and making sure that you what is with this camera all of a sudden. You're evidence, pull back, big mountain. And that's where I feel like that's mature, because you're there, you're working, knowing their strategy and getting there first, putting those things in place really quickly so when they show up, it's most of the security controls are in there. There'll be additional security controls when you understand. What products they're bringing in how they're communicating across the different environments and all that stuff. Then there's additional stuff in, but you've already put the base security controls in place. That shows a level of maturity because when they get there, they don't feel security's holding them back, right? Because we're always that person holding them back because we're late. So if, as a CISO, and your direct reports are working very closely with the different parts of the organization, you will have a level of maturity. Sometimes maturity doesn't actually have to be about a process or a policy. It's actually making sure you understand where you're going and building those things forward. And in some cases changing those policies because where they are now going to, the policies you had before weren't good enough for it or just don't even match to what's happening there, right? So it is working really closely with all the others. And it's tiring, because you're constantly, you know, a good company is trying to sell or trying to change or design product and all that stuff, right? And when I say it's tiring, it's not because you're trying to be ahead of the game, but it's also exhilarating because if you beat them to all this stuff, they're effective. You know, I always say security is the people that help our business and enable us, right? And a true security team makes sure that business can operate without even knowing security is there. That is what I want every day. It should be transparent. You don't go into a bank and go, can I see the vault? Can I see the, what kind of password controls do you have? And all this. No, you're just expecting it there. That's what I want my organizations to think. Jeff's got it, and his team. And actually, it's more, Jeff's team's got it. Jeff's just the figurehead running around and making sure that he can get the data to his team if they're not getting anywhere.

Sullivan Tuck
Sullivan Tuck

Okay, so as we wrap up, what advice would you give to a security leader that is preparing to take responsibility for their first billion-dollar company?

Jeff Moore
Jeff Moore

I want to say runaway. Truthfully, find a couple of friends that are doing it. Find a mentor if you need a mentor. Find somebody who's done it. Do not be afraid to ask. Always remember that PwC, BCG and all this stuff, they're not the ones that are to give you the right answer because the true right answer is within your teams anyway. Right? They understand it. Also, do not be afraid to talk about what's not working with your leadership. Right? And remember also, you have two teams. You have your security team and your leadership team that you are with whoever you're reporting to. Right? People tend to forget that you're part of a bigger team. Right? And your head of infrastructure is a peer. He's a teammate. Right? Because he reports to the CIO. Not only him, he has his infrastructure team. Right? He has two hats, his hat of team with you and the hat of the team with the blow. So, you know, if he's been there 15 years, have a conversation with him. Understand where those issues are, right? Take time to work with stakeholders. You need to, and I hate the word manage, stakeholders because you're not managing them. That's rude. You are partnering with them, right? They are part of your team. You are understanding where they need to go. You're helping them get there and they're helping you get there. I had a great leadership team at NIBR, and I remember being in there talking to the CIO and my teammates and I said, I need an additional couple of million. And the rest of the people at the table said, well, you know what, I'll defer this project for six months and I'll defer this project for three months and we'll get you that money. That's the other team that you work with. Right. And they were fantastic. Right. And at H&M we just rebuilt a lot of that team. Right. When I came in, right, we have a new CIO, we have a new areas of domains and some people have been there a good amount of time. And we're all now rebuilding a team and being part of that conversation is like, let's help one another, right? Because we're all in the same game. And to not be afraid to ask. And also ask outside, right? You know, reach out to somebody you know who does this and ask those questions. We're all there to help because we've all been through it. Some of us have been doing it longer than others. Some of us will probably say, don't take that job because we know what's going on in that job, in that company. Maybe they asked you to interview for it, right? But the other part of it is also be yourself. Do not put on facades. Do not try to be anything you're not. Be yourself because you cannot be... one face to your team and one face to your other team and one face to the CIO. What happens if they're all in the same room together? You can't balance it. So be authentic, be yourself. My dad had a statement, never say you're authentic and I agree with him because that means you're not. But be yourself, right? They hired you to do this. And one of the number one pieces of advice I'll also give is don't try and do what you did before. Different company, different culture. spend those 30-, 60-, 90-days understanding it before you make a plan. Some of the stuff you did before may work, some of it may not, but understand it. Best I can do, mate.

Sullivan Tuck
Sullivan Tuck

Thank you very much. Well that theme we actually did an episode a few weeks ago on the first ninety days as a security leader and a lot of the advice was exactly the same.

Jeff Moore
Jeff Moore

It is interesting because I actually go through sometimes a different view of the 30-, 60-, 90-day way. And it's interesting when I go into an interview and somebody has an interview with me, I have friends of mine that have a very structured plan. Right? And I have a very different plan. Right? And knock on wood is being successful so far. Right? But I think that it also is successful based on the company you're in. And the culture, you're in right? And in some cases, to me, at the 45-day mark, I'm giving a presentation to the people I've met and what I've found so far, but not a plan, right? And then at the 90 days, I'm giving another presentation of what I've heard from the last 45 days, now and here's the plan, right? And then at the 120-day mark, I'm showing them what I've done and what fell off the plan, right? And sometimes at that 90-day mark, is what I'm telling them. Not going to be done, which is more important than what's going to be done. So yeah, no, I think it's good and people should learn from that 30-, 60-, 90-day because it's something you should take every time in your head. How do I want to do this? Right? And your direct report sometimes may even change it completely, right? Because of what they're owned and how things are going in the company. So don't be surprised and don't be mad. Some people, some people are so structured and rigid, they get mad when they can't go in that direction and that you should, CISOs need to be able pivot.

Sullivan Tuck
Sullivan Tuck

All right. Well thank you very much for joining me today. All right. thank you everybody for watching. If you enjoyed this episode, be sure to like, subscribe, leave a comment with thoughts or suggestions for future guests and topics. And thank you again to Jeff Moore for joining us.

Jeff Moore
Jeff Moore

Thank you mate, was a pleasure.

Continue the Conversation

Conversations With CISOs, Security Leaders & Technology Executives

Hear practical conversations with the executives responsible for protecting complex organizations. Each episode explores leadership, risk management, infrastructure, incident response, governance, and the decisions security leaders make every day.

Conversations With Security Leaders Practical insights from the people leading security
CISO Leadership
Risk Reduction
Incident Response
Cloud Security
Infrastructure
Governance
Compliance
Executive Strategy
Live Webinar

From Discovery to
Risk Reduction

Operationalizing CTEM in Modern Security Programs

Date September 24, 2026
Time 2:00 PM Eastern

Learn how modern security teams can move beyond finding exposures and operationalize every stage of Continuous Threat Exposure Management.

01 Scope
02 Discover
03 Prioritize
04 Validate
05 Mobilize
Reserve Your Spot

Free registration · Live discussion and Q&A

This Content Is Gated