Invest in Your People — Whether it is the rollout of a security awareness and training program or establishing career journeys with technical training and certification paths, I’ve never not come out ahead by investing in the capabilities of my teams.

Today, more than ever, new products and software are under attack by a host of malicious actors. This makes the role of a C-Level Cybersecurity officer or a Chief Product Security Officer one of the most important lines of defense against cyber threats. What do you need to know to be a successful cyber executive today? To address this, we are talking to C-Level cyber executives who can talk about “What It Takes To Become A Cyber Executive, Today.” As a part of this series, I had the pleasure of interviewing Aaron Faulkner.
Aaron Faulkner is managing director of the Accenture Federal Services (AFS) cybersecurity practice across the US Federal Department of Defense, Intelligence Community, Public Safety, Civilian and Health sectors. He leads the design, development, delivery and operation of innovative cybersecurity solutions for clients with wide-ranging missions. Aaron will lead a dedicated, interdisciplinary team of advanced cyber and technology specialists who work together to apply automation, cloud and AI to help agencies defend systems, be responsive to changing mission demands and be more resilient in the face of persistent threats.
Aaron brings more than 18 years of experience in the delivery of advanced technology and cybersecurity solutions to public-sector and commercial customers. Through his career he has tackled critical cybersecurity challenges in digital identity, cyber defense, application security and managed security services.
Prior to joining AFS, Aaron served as vice president of cybersecurity and the lead executive responsible for growth and delivery of cybersecurity solutions at ECS, a science, engineering, cybersecurity and advanced technology solution provider. He also served as chief strategy officer and vice president for business development at InfoReliance, which ECS acquired in 2017.
Aaron received his bachelor of specialized studies in business administration and marketing communications from Ohio University.
Thank you so much for joining us in this interview series! Before we dig in, our readers would like to get to know you. Can you tell us a bit about where you grew up and what your childhood was like?
My wife and I hail from Erie, PA., a blue-collar town on the shores of Lake Erie, 20 miles west to Ohio and 20 miles east to New York. We both grew up in large, close, and loving families. Everyone worked hard and established a belief system of hard work and taking care of one another. We spent most of our childhood in and around Erie. (I didn’t travel much anywhere until after college.) For fun, my passions were golfing in the summer, mostly with my old man, and skiing in the winter at a tiny slope just over the border in New York. I cut my teeth with my first job at age 12 and have always had one since.
Is there a particular story that inspired you to pursue a career in cybersecurity? We’d love to hear it.
There is a lot of truth in the old maxim that it’s sometimes better to be lucky than good. In the early 2000s, the company I was working for had landed software engineering work for the White House. I made some great connections there (thank you, Vince and Adam) and happened to be in the right time and place when the new CIO of the Executive Office of the President said in a meeting that the organization needed a centralized security capability and she wanted to establish a Security Operations Center (SOC). I honestly had little insight into what that truly entailed, but a short while later we won a five-year and firm fixed-price, competitive task order to build out and operate the first-ever SOC for the White House. It was an exciting and rewarding time and one of the greatest learning curves of my career.
Can you share the most interesting story that happened to you since you began this fascinating career?
Most of my career was spent at a small powerhouse of a firm. We were rockstars in software engineering and were very early in cybersecurity and the adoption of cloud computing. Our teams rolled out the first-ever production instance of Microsoft Office 365 for a cabinet-level federal department. We deployed the first continuous monitoring solution across the Nuclear Security Complex and established a one-of-a-kind endpoint security operation, delivered as a turn-key managed service for the US Army worldwide. Our teams were always focused on delivering successful outcomes for our clients. The most interesting and challenging aspect of it all was when we decided to take a risk and launch a cybersecurity product company using some of the IP we had developed. That company, Tychon.io, is now the gold source tool for endpoint systems management, detection, and response capabilities for more than one million users in the DoD, to include most combatant commands. That experience of launching a product company while leading growth and strategy of a traditional defense contractor was by far and away the most interesting, challenging, and eye-opening time in my career.
You are a successful leader. What 3 character traits do you feel have been the most instrumental to your success? Can you please share a story or example for each?
- Demonstrate Transparent Leadership — I work with and lead extremely talented, experienced, motivated professionals, many of whom are veterans. They deserve to know the who, what, where, when, and why of our plans and ambitions. Without fail, the more that is shared with our teams, the more information they have to work from, and the better they deliver for their teammates and their clients.
- Put People First — My freshman year of college I studied utilitarianism and it’s one of the concepts that never left me. It’s the importance of making decisions that ultimately deliver the greatest potential benefit to the greatest number of people. My philosophy of putting others first has enabled me to build lasting, trusted relationships with key industry partners, clients, and coworkers.
- Be Entrepreneurial — It is ok and necessary to take risks. This is how you stand out — leading and not following. I have been fortunate to work for companies that have all embraced my desire to strike out and delve into emerging markets and create differentiated solutions. Not all endeavors were successful; there was a multi-million-dollar plan for an online marketplace that went up in smoke, for example. But there were many, many others where the risk was truly rewarded.
Are you working on any exciting new projects now? How do you think that will help people?
Yes! We’re working on the cutting edge of cybersecurity. I’m excited about our capabilities in areas like SOC automation, critical infrastructure security, post-quantum cryptography and the emerging crypto-ability platforms, and solutions we’re developing to automate cumbersome processes like NIST’s Risk Management Framework. This past year my teams deployed some extraordinary innovations, such as bringing the UNITY gaming programming framework into SOC operations. This provided for a first of its kind overlay view of the physical (buildings and military bases) with network topographies for our analysts. This allowed them to “see” connections, defenses, and inbound attacks in ways that had not been previously possible.
Very interesting! Thank you for all that. Let’s now shift to the main focus of our interview. The Cybersecurity industry seems so exciting right now. What are the 3 things in particular that most excite you about the industry? Can you explain or give an example?
Here are three 3 things I find particularly exciting:
- The federal government’s relatively relentless focus on cybersecurity. It was a long time in coming, but now it is definitively here and we’re fortunate to have many outstanding leaders in government at the helm.
- The consolidation of cyber tools and the emergence of highly capable and comprehensive security platforms. This is exciting because if you’ve been in cybersecurity for some time, you know that it is an industry of point solutions. Each point solution is separately acquired, needs its own operations and maintenance (further exacerbating the manpower shortage), and rarely do the tools play nice together, even with the maturity of SOAR. This new era of mega consolidation that is happening right now and rationalization of tools into comprehensive platforms and software-as-a-service is an exciting and much needed game changer.
- The cyber workforce. It is awesome, serious, and they have come to play. For years, there has been a massive gap between the cyber workforce needs and the availability of trained and experienced cybersecurity professionals. Every day we are interviewing world class students early in their college experience with the vision and ambitions to be leaders in our industry. Not that long ago this pool of emerging and focused talent simply didn’t exist. Between commercial and public sector programs to accelerate the development of the cyber workforce and the strong and loud beating of the drum of government leadership, especially in this current Administration, we are finally starting to see that the much needed catch-up is finally happening.
What are the 3 things that concern you about the cybersecurity industry? Can you explain? What can be done to address those concerns?
- Cyber remains extremely complex. There are added regulatory requirements, yet ever more capable and commoditized threats. We’re moving further away rather than closer to an easy button.
- Cyber is not always prioritized nor is it embedded into solutions from the get-go. Whether it is an application that supports citizen services, or a targeting system used in the DoD, we still suffer from a culture where security is not an equal consideration, meaning that security needs to be fundamental in every facet of a systems lifecycle — from architecture and engineering to continuous monitoring and ultimately delivering extreme capability and resilience.
- Security industry remains far too reactionary. The reality is that 99.99% of the time we are still reacting. This is due to the omni-present vulnerabilities in systems. Cloud computing will continue to provide mitigations, but thousands and thousands of legacy applications remain. Without better coding, better vulnerability management, better and faster patching, technology stakeholders will remain in reaction mode until we can fully automate the basics of IT hygiene.
Looking ahead to the near future, are there critical threats on the horizon that you think companies need to start preparing for? Can you explain?
We need to get really serious about resilience. No matter the type of attack, preparation, and maturity of the process for continuity of operations, the ability to rapidly remediate and restore services should be the primary objective of all high-value system owners. There needs to be an eyes wide open mentality and proactive efforts, such as tabletop exercises, adversary emulation, and continuous penetration testing. Over the past year, my teams have ramped up significantly to include employing third-party crowd-sourced penetration testing with great partners like SYNACK.
As you know, breaches or hacks can occur even for those who are best prepared, and no one will be aware of it for a while. Are there 3 or 4 signs that a layperson can see or look for that might indicate that something might be amiss?
Statistically most attacks still emanate from email, the lowest hanging fruit. The average person can take advantage of numerous free services provided by ISPs, CSPs, and email providers and ensure that they are using hygiene basics such as MFA. Just like an enterprise, individuals should have backups should they fall prey to an attack like ransomware. Password compromises are also an all-too-often occurrence and recommendations, such as a password manager, is something everyone should consider adopting. DHS CISA produces timely and easy threat information as well, worth subscribing to if you lead or run an organization. They also often co-produce publications with the NSA on best practices for cybersecurity and IT hygiene, yet another example of how solid and forward leaning our federal cyber leaders have become.
What are the most common data security and cybersecurity mistakes you have seen companies make that make them vulnerable to ransomware attacks?
Far and away, the most vulnerable find themselves in their position because of these three things:
1. Poor cyber hygiene
2. Poor cyber hygiene
3. Poor cyber hygiene.
When things go sideways or leaders need to know what’s happening on their network, I have observed countless times they have blind spots due to lack of investments in security basics and prioritizing asset visibility, vulnerability scanning, and rigorous processes for patching. In addition, core network security, tools, or managed services to consider that will mitigate the vast majority of threats include a secure email gateway coupled with a protective DNS resolver platform (readily available from companies like Cloudflare and Google). Organizations should also strongly consider EDR capabilities from companies like CrowdStrike and Trellix. My other key recommendation would be to implement a comprehensive security awareness and training program. Statistics show that organizations who invest in security training for their own people tend to be far better off than their peers. Enough can’t be said or done on this front.
In today’s environment, in addition to computer systems, hackers break into the software running many products, such as cars or robotics, for malicious purposes. Based on your experience, what should manufacturing companies do to uncover vulnerabilities in the development process to safeguard their products?
This is an incredibly complex issue that stems predominantly from countless sources of commercial and open-source software libraries along with system misconfigurations. Having rigorous standards and processes for supplier management, coupled with capabilities that provide open-source insights into companies, will provide manufacturers with a solid baseline to build from.
Ok, thank you. Here is the main question of our interview. What are the “5 Things You Need to Create a Successful Career As A Cybersecurity Leader Today” and why?
- Remain Curious — Cyber is one of, if not the fastest changing industries and it is important to have a habit to carve out time every day to read, listen, and learn about what is happening in our field of practice.
- Be a Swiss Army Knife — Ten years ago, a security professional could operate successfully being singularly focused on a given security discipline, say firewall administration as an example. That is no longer the case as the network perimeter has been completely obliterated. Today’s cyber leaders and operators must have broad awareness and understanding of dozens of interrelated disciplines and technologies and success requires maintaining an understanding of all and an awareness of where distinct capabilities are heading in the future.
- Regulatory Vigilance — It will not be long before the policies implemented in other parts of the world, Europe especially, make their way to the US. There are numerous, highly impactful regulations that are now in effect. These often increase reporting requirements, resource needs, and overall demand on budgets.
- Invest in Your People — Whether it is the rollout of a security awareness and training program or establishing career journeys with technical training and certification paths, I’ve never not come out ahead by investing in the capabilities of my teams.
- Build a Cyber Network — Having a strong community of cybersecurity professionals and trusted relationships that you can lean in with is a priceless investment of time. You never know when you might need a certain insight or skillset to tap into, or when you can benefit from a peer group’s lessons learned.
You are a person of great influence. If you could inspire a movement that would bring the most amount of good to the most amount of people, what would that be? You never know what your idea can trigger. :-)
Wow, that’s a BIG question. I think that if I could inspire one broad movement or trait in people it would be to inject a bit of skepticism in everyone along with some healthy habits towards understanding the complete picture of what’s happening around us.
How can our readers further follow your work online?
My Accenture Federal Services team, along with our 15,000+ Accenture Security colleagues worldwide, are continuously producing valuable insights and sharing innovations in cyber defense, threat intelligence, applied security, and managed services. You can follow Accenture Security on LinkedIn and download security content accenture.com/security.
Thank you so much for joining us. This was very inspirational, and we wish you continued success in your important work.
About The Interviewer: David Leichner is a veteran of the Israeli high-tech industry with significant experience in the areas of cyber and security, enterprise software and communications. At Cybellum, a leading provider of Product Security Lifecycle Management, David is responsible for creating and executing the marketing strategy and managing the global marketing team that forms the foundation for Cybellum’s product and market penetration. Prior to Cybellum, David was CMO at SQream and VP Sales and Marketing at endpoint protection vendor, Cynet. David is a member of the Board of Trustees of the Jerusalem Technology College. He holds a BA in Information Systems Management and an MBA in International Business from the City University of New York.
David Leichner
Editor & Journalist · Authority MagazineEditor and journalist at Authority Magazine, sharing in-depth executive interviews, leadership insights, and empowering stories from world-class founders and creators.

Exclusive, curated interviews with the leaders and changemakers shaping tomorrow. Leadership lessons, industry deep dives, and executive profiles.
More from Authority Magazine
See all stories →Brandon Wade & Dana Rosewall on Why ‘Yes’ People are a Liability and the “Painful” 180-Degree Redemption Story
