Staying Ahead in Cybersecurity
CIOREVIEW >> Cyber Security >> NEWS

Edita Food Industries

Khaled El-Bagoury, Cyber Security Manager

Staying Ahead in Cybersecurity

Khaled El-Bagoury, Cyber Security Manager
Khaled El-Bagoury, Cyber Security Manager, Edita Food Industries

How did your career in IT and Cybersecurity begin, and what experiences shaped your growth along the way?

I stepped into the IT world during a pivotal era: the early 1990s.

IBM, once the undisputed king of Corporate IT, was beginning its decline. This period offered me a unique advantage, as I actively coordinated several projects focused on modernizing legacy systems. We transitioned from IBM Token Ring networks to the more agile Ethernet, migrated from IBM Lotus Notes to Microsoft Exchange, and replaced IBM AS/400 ERP systems with SAP.

These experiences ignited my interest in the details of IT Migration Projects, particularly in the planning, risk assessment and execution areas. It was through these challenges that I discovered my passion for project management.

Later, armed with PMP and CISM certifications, my professional trajectory became clearer. Managing CyberSecurity projects developed my skills to understand the elements and ingredients of the sophisticated CyberSecurity management world. As one cannot manage something that you don’t understand its structure from the bottom up.

What are the toughest challenges you face in IT and Cybersecurity today, and what are you learning from navigating them?

Gaining management engagement for CyberSecurity projects and funding is a persistent challenge. It's a fact that we -as humans- are hardwired to favor tangible and quick ROIs. The long-term, often preventative nature of CyberSecurity -protecting data and organizational reputation- isn't always perceived as immediately tangible. This makes it a tough sell, compared to initiatives with clear and direct revenue generation.

  Stay curious and be a ‘student’ to all branches of knowledge, technical and soft-skills  

However, I can see that the CyberSecurity community is indeed making steady progress in articulating this value. Professionals are increasingly focusing on translating technical risks into business impacts, demonstrating how robust CyberSecurity directly contributes to operational resilience, brand trust, regulatory compliance and sustained business competitive advantage.

How do you balance strict regulatory compliance (such as ISO 27001, PCI, and Cyber Laws) with the need for operational agility?

Balance: Strict regulatory compliance should be balanced with operational agility in IT environments, requiring an approach that integrates security into the core of IT operations, rather than treating it as a separate, inhibiting function. It's about deep understanding and cultural alignment, not just ticking boxes in a due diligence report!

Deep Engagement: The cornerstone of this balance is deep engagement and mutual understanding between CyberSecurity and IT operations teams. Instead of CyberSecurity imposing rules, both teams need to collaborate from the outset.

IT operations must view security as an inherent part of their role, not an external mandate. This requires awareness of ‘the Why?’ behind compliance requirements. For example, explaining how ISO 27001's Asset Management controls, directly aid operational efficiency by reducing Shadow IT and eliminating security backdoors.

Integrated Framework: Adopt a CyberSecurity framework (like NIST or ISO 27001) that can be mapped to IT operational processes. This helps IT understand how their daily tasks contribute to compliance. Instead of perceiving a ‘CyberSecurity framework’ as an additional burden, it should be seen as a structured approach to managing Information Security Risks that ultimately benefits operational stability.

Change Management: A strict, yet adaptive, Change Management policy is crucial. Not all changes carry the same risks; categorize changes based on their potential impact on security and operations. Ensure all stakeholders, particularly IT operations, understand the Change Management process, approval workflows and timelines. Transparency will prevent delays and frustration.

Security by Design: New projects, especially those involving new systems or services, must incorporate security requirements from the very beginning. This includes secure architecture reviews during the planning phase. Trying to bolt on security later is invariably more expensive, timeconsuming and less effective.

Compliance as a Project Requirement: Just like budget and timeline, compliance requirements (such as PCI DSS for payment systems, GDPR for data privacy) should be non-negotiable project requirements. This forces early consideration and allocation of resources.

In brief, achieving this balance means moving away from a siloed ‘security vs. IT operations’ mindset, towards a unified approach where security is seen as an enabler of operational excellence and business resilience.

A culture where compliance is viewed not as a burden, but as a framework for building trustworthy and efficient IT systems.

Which emerging CyberSecurity technologies or trends are you most excited about, and why?

CyberSecurity professionals should be enthusiastic and excited about the transformative potential of Artificial Intelligence (AI), Zero-Trust Architecture and Post-Quantum Cryptography.

AI promises unprecedented capabilities in real-time threat detection, attack pattern analysis, anomaly identification and automated incident response. Drastically reducing human reaction time saves the business valuable time consumed in decision-making during aggressive cyber-attacks.

Zero-trust architecture is crucial for remote work and cloud environments; it will significantly reduce the attack surface and greatly enhance the overall security posture of the organization.

Post-quantum cryptography is vital for safeguarding data against the future threat of quantum computers, which will render current encryption methods obsolete!

However, alongside the excitement, a cautious approach is needed here.

AI, while it’s powerful for defence purposes, can also be weaponized by attackers to launch more sophisticated and automated attacks, creating a continuous Arms Race!

Zero-Trust Architecture can be complex, demanding significant resource investment and potentially causing friction with the business if it’s not carefully planned and aligned.

Assessing the risks and challenges of any new technology or a security framework implementation is essential in the current sophisticated and growing business environments.

What advice would you offer aspiring IT professionals who want to follow a similar leadership path?

Don’t compromise with the quality of your work. Your brand and reputation will follow you wherever you go.

In the IT world, never ever bury or hide anything! Audits, assessments and even day-to-day operations will reveal the truth sooner than you expect, and you don’t want to be in a position where fingers are pointing at you with ‘unprofessional’ or ‘unethical behaviour’ charges.

Stay curious and be a ‘student’ to all branches of knowledge, technical and soft skills. You don’t stop learning when you leave school or college, as a matter of fact, you’ve just started!

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.