Why People Can Be Digital Security's Strongest Link

Mathieu Manalo, CISO at leading finance and leasing company ORIX METRO, explores the best way to keep employees engaged on best security practice
WRITTEN BY
PRODUCED BY
Oliver Reek
Why People Can Be Digital Security's Strongest Link

Why People Can Be Digital Security's Strongest Link

Mathieu Manalo, CISO at leading finance and leasing company ORIX METRO, explores the best way to keep employees engaged on best security practice
WRITTEN BY
PRODUCED BY
Oliver Reek
Why People Can Be Digital Security's Strongest Link
Share this article
Prioritise Us on Google
Share this article
Mathieu Manalo, CISO at leading finance and leasing company ORIX METRO, explores the best way to keep employees engaged on best security practice

Human error continues to be a significant vulnerability in digital security, often targeted by attackers using social engineering and phishing to breach IT and operational technology networks. However, Mathieu Manalo, Chief Information Security Officer (CISO) at ORIX METRO Leasing and Finance, challenges the view that employees are the weakest link, emphasising that with proper training, they can become a company’s greatest asset.

​“We have a saying in security that people are the weakest link in the chain. But I would like to challenge that idea and say if you can train your people, they can be the strongest link in that chain – [but] only if you can train them well.”

Mathieu, ORIX METRO’s first CISO, joined in July 2025, marking the company’s increased focus on digital security. His goal is to position security as a business enabler rather than a barrier. “I wanted to change the perspective that security is not a blocker, but it's an enabler to a secure way of doing business.”

He notes that the main challenge in transformation is employee adoption, particularly within a multi-generational workforce. “The biggest challenge is adoption because everyone is afraid of change. Change is scary for everyone, especially when we have different age demographics at ORIX METRO. So the rate of adoption is our biggest challenge, not really technology or budget or anything like that,” he says.

From the outset, he encountered significant fragmentation in the company’s solutions and infrastructure, requiring a nationwide shift in work practices. “When I joined ORIX METRO, there was a lot of fragmentation across the different solutions, the different infrastructures that we have. We have transformed the way our people work across the nation,” he explains. 

To promote adoption among the company’s 1,200 employees, Manalo was added to the “ORIX Transformers”, a team of champions who encourage colleagues to embrace new digital platforms. This team addresses the challenge that "the rate of adoption varies greatly per generation".

If your employees' day-to-day tasks. If you combine that, that's how you secure the organisation while keeping your employees happy,” he concludes.

Creating a culture of security relies on continuous engagement, interactive training, and practical workplace policies. Credit: Getty Images

To strengthen technical defences, ORIX METRO partnered with Antarex to implement a Managed Security Operations Centre (SOC) to address a “glaring gap” left by the previous on-premises team, which only monitored during office hours. Importantly, ORIX METRO retains all remediation and decision-making authority: "They do not have administrative access to all of our assets.  You still have to have that semi-trust issue with all of your vendors, because you cannot assign full trust to someone not part of your ecosystem, because that's how you retain your status quo of security posture,” Mathieu says. 

Manalo’s awareness strategy emphasises repetition and automation. After launching the first annual Cybersecurity Awareness Month roadshow with 90% national attendance, the next challenge was sustaining engagement. “You cannot just have a month-long programme and just leave it at that because that's not how you retain awareness. You retain awareness through repetition,” he adds

Current initiatives include weekly quizzes and a partnership with Proofpoint to automate security training. If an employee fails a scenario, such as a complex QR phishing attack, the platform assigns targeted content. “It's about automating and keeping the quality of the training and the intention that ‘Hey this is for you, we're doing this for you, we want you to be secure, not just in the workplace, but also in your personal lives,’” he says.

Finally, Manalo ensures that security policies, which follow ISO 27001 and US federal standards, are practical and easy to follow, avoiding "compliance theatre." “It has to be easy to understand and it doesn't have to impede on all of your employees' day-to-day tasks. If you combine that, that's how you secure the organisation while keeping your employees happy,” he concludes.

Company portals

Executives