News & Views

From The CISO’s Desk: Beyond The Code

From The CISO’s Desk: Beyond The Code

Beyond the Code: Ethics Is the Real Firewall

In this week’s blog, From The CISO’s Desk, CyberNorth’s interim CEO, Jon Holden, discusses ethics and security practices.

I’ve been thinking about something this week.

I’ve spent over 20 years in cyber building banks, modernising platforms, sitting in incident rooms at stupid o’clock in the morning, and then explaining it all to boards and regulators a few hours later.

And one thing has always been true:

The tech is rarely the hardest part. The judgement is.

The recent stories about Jeffrey Epstein trying to build links with high-profile hackers and security circles made me pause. Not because of the headlines we all know how those play out but because of what he was actually looking for.

It wasn’t code, it wasn’t capability. It was proximity, credibility and access.

That’s the bit that matters.

In our world, technical skill is neutral. It’s powerful but neutral. The same knowledge that protects a hospital or a bank can be misused if it lands in the wrong context.

What separates professionals from opportunists isn’t intelligence.

It’s restraint.

It’s the ability to say, “No that doesn’t sit right.”

And here’s the thing I genuinely love about the cyber community, especially here in the UK and up in the North East where I spend a lot of my time, we do have an immune system.

People talk.

Reputations matter.

Standards matter.

The fact there’s no evidence Epstein ever gained real foothold in those circles says something. Communities protect themselves when they care enough about integrity.

In financial services, trust is oxygen. Without it, nothing works. Customers don’t separate your ethics from your architecture and neither do regulators.

So when we mentor the next generation through CyberNorth, CyberFirst, universities, apprenticeships, we need to be explicit about this stuff.

Ethics isn’t the soft bit.

It’s not the optional module.

It’s the foundation.

“Grey hat” might sound interesting when you’re 19. It looks a lot less impressive when you’re accountable to a board, a regulator, or a million customers.

We aren’t just building secure systems. We’re safeguarding trust.

That’s a privilege. And it’s worth protecting.

Would be interested to hear how others draw their own red lines in this space. It’s not always black and white but your principles need to be.