The changing business of cybersecurity
HNSecurity’s Derek Dodds on evolving threats, executive responsibility and why cybersecurity can no longer be left solely to IT
Derek Dodds is helping clients take a broader, more practical approach to cybersecurity as online threats continue to evolve. — Photo courtesy of Derek Dodds
For Derek Dodds, cybersecurity has always been about more than technology. His career began in telecommunications in Scotland in the late 1990s, when data security was only beginning to emerge as a major business concern. After moving to Jersey in the Channel Islands at 21, Dodds found himself working in the island’s finance sector, where protecting sensitive data and assets was critical. That experience sparked a lasting interest in building secure environments and eventually led him to Vancouver, where he founded HNSecurity in 2009.
Since moving the company to Rossland in 2018, Dodds and his team have watched the cybersecurity landscape change dramatically. HNSecurity has evolved from primarily providing technical design and implementation to helping leadership teams understand security as a business-wide risk, with services including strategy, incident response planning and ransomware tabletop exercises. Now, with the launch of The Cyber Guys, Dodds is taking that philosophy beyond the business world, working to make cybersecurity more practical and accessible for everyday internet users. In this Q&A, he discusses the evolution of HNSecurity, the rapidly changing threat landscape and why cybersecurity should be something everyone can understand.
What first led you into security, and how did that evolve into starting HNSecurity?
I started out in telecommunications in the late 90s after finishing my studies in the west of Scotland. At that time data security was not front and centre of business operations, but it was clear even then that it was going to become more important.
It really took hold when I moved to Jersey in the Channel Islands at 21. Jersey has a large finance sector and so security was critical. That is where I found myself genuinely drawn to building environments that keep people’s data and assets properly protected.
I moved to Vancouver in 2009 and not long after that started HNSecurity. My idea for the business was to take the practical, no nonsense approach to security I had learned through working in the finance sector and apply it across a wider range of industries.
Over time, this has become a core value for our team, not just helping organisations stay secure, but making cybersecurity something people can actually understand and use. We were fortunate to have the opportunity to move to the Kootenays in 2018 and have been operating out of Rossland ever since.
What did those early days of the business look like?
We were lucky that we were busy from the start. We actually had more work than we could support, which was a good problem to have.
A lot of that came down to relationships and reputation. We found that once you deliver well in this industry, word travels quickly. Our challenge wasn’t finding work, it was making sure we could deliver it properly without overextending ourselves.
How has the company changed or evolved since you started?
At the start, a lot of our work was focused on technical design and implementation, building secure environments and putting the right controls in place.
Over the last few years, that has shifted. Business leaders now recognise that security is not just an IT problem, it starts at the top and flows through the whole business. This means we are spending more time working with leadership teams, helping organisations take a top-down approach to cybersecurity
This includes assessing and developing practical strategy to mitigate security risks, developing incident response plans and running tabletop exercises where executive teams can experience how something like a ransomware event might actually play out.
It has been a natural evolution, moving from purely technical delivery to helping organisations think about security in a more complete and realistic way.
What have been some of the biggest milestones or turning points along the way?
The biggest milestone for us and the one we are most proud of is the longevity of our client relationships. Some clients have been with us for 17 years, which speaks to the trust we’ve built over time.
Another key milestone has been the development of The Cyber Guys. That is a bit different for us, as it is focused on making cybersecurity accessible to everyday people, not just businesses. We are still in the early stages, but it is something we care deeply about and see as an important part of where we are heading.
What have been some of the biggest challenges over the past few years?
Like many businesses, we have seen some slowdown over the past 12 months, particularly across a few of our contracts. Things are starting to pick up again now, but it gave us a moment to step back and reassess.
We used the quieter time as an opportunity to think about where we can add more value and how our services should evolve. That has led to expanding what we offer, particularly around advisory services and making cybersecurity more accessible beyond our traditional enterprise clients.
What are some key lessons you've learned as a business owner during that time?
One of the biggest lessons has been the importance of thinking ahead, while still delivering in the moment. We’ve learned to balance staying focused on our existing customers and the work we are delivering today while also paying attention to future growth opportunities.
How has the security industry changed in the last few years?
The pace of change has accelerated massively, particularly with the rise of AI. The time between a vulnerability being discovered and it being actively exploited has shortened dramatically, which leaves very little room for delay. This means incident preparedness is a key focus for organisations — not only ensuring data and assets are as secure as possible, but also being ready to act immediately to mitigate damage if something goes wrong.
At the same time, cybersecurity has shifted from being seen as a technical issue to being recognised as a business-wide responsibility. If an organisation is connected to the internet which almost every business is, it’s essential to understand the level of exposure and how it is being managed.
That is probably the biggest change. Security is no longer something that can be simply left to an IT department to manage, it is something every business has to take seriously at every level.
How has HNSecurity adapted to those changes?
We are still evolving, but the key shift has been moving beyond technical delivery to helping organisations understand and manage security as a business risk.
What are your goals for the future?
A big goal for us is improving cybersecurity for everyone, not just businesses. For a long time, day to day security has been for people to install antivirus software to their computers or keep their device up to date, but that is not enough now.
People depend on the internet for everyday things like banking and government services but are still expected to manage the risks without really knowing what they are.
What we need is a better approach, something that gives non-technical people real confidence that they are secure. That is a big part of what we are working towards, making cybersecurity more practical, accessible, and relevant to everyday life.
We are in the process of launching The Cyber Guys, an online service that helps people keep their accounts and devices safe. We’re very excited about this as it is new for us and really speaks to our core value of making cybersecurity accessible for everyone, especially those that don’t have technical know-how.
Is there anything else you would like to add?
The main thing I would add is that cybersecurity does not need to be as complicated or intimidating as people think. A lot of the risk comes from not knowing what to do, rather than a lack of technology.
If we can make it simpler and more accessible, we can help people feel more confident in how they use the internet day to day. That is something our business cares a lot about and will continue to focus on.


Comments