Dave Southard

Cybersecurity: Major Priority

Aeromag’s Changemakers November 25, 2024
The Portraits of Changemakers series focuses on visionary individuals who work at Aeromag and who, every day, demonstrate a willingness to make a difference in the world. Among them, Dave Southard, System Administrator and Cybersecurity Specialist within the Group.

Dave has been part of the Aeromag family for ten years. He first joined the team as a Deicing Technician before holding several positions in operations including Bay Lead and CTM. He was then introduced to the IT team and held the positions of IT Support and System Administrator. Dave is currently responsible for IT system administration and cybersecurity.

What makes him passionate about cybersecurity is the balance between structure and flexibility. While there are established frameworks, best practices, and goals to guide us, he has the freedom to design procedures that fit these frameworks while addressing the specific needs of our organization. This allows Dave to create meaningful, customized solutions to real-world problems. His main responsibilities include ensuring up-to-date security across systems, creating and sharing comprehensive security procedures, providing station support, conducting audits, maintaining an IT incidents register, and overseeing the upkeep of our IT infrastructure.

Each of these tasks contributes to a robust security posture, and I find it rewarding to see how my work helps protect the organization from evolving threats.

Cybersecurity challenges at Aeromag are similar to those faced by many organizations. One of the primary challenges is balancing security with usability, ensuring strong protections without hindering employee productivity. The high pace of the industry and the coverage of stations in different countries requires us to be creative and collaborative in addressing security needs. With the increasing shift to the cloud, securing cloud environments and maintaining data control is another challenge, which requires careful coordination with third-party vendors. Employee awareness and behaviour are critical, as human errors, such as falling for phishing scams or mishandling data, remain a common vulnerability. Finally, the management of parallel computing (unauthorized software or devices used by employees outside company policies) presents a security risk, but we mitigate it by using firewalls and advanced detection systems.

At Aeromag, cybersecurity follows a comprehensive, multi-layered framework tailored to address the unique needs of each environment and individual. The approach begins with risk assessment, identifying critical assets and evaluating potential threats and vulnerabilities. Security is implemented through layers such as network protection (firewalls, intrusion detection), endpoint security (antivirus and device management), and application security (fixing vulnerabilities). Data security is prioritized with encryption and strict access controls, including multi-factor authentication and role-based access. Continuous monitoring detects anomalies, while a well-defined incident response plan ensures rapid action against threats. Employee training on security best practices, regular audits for compliance, and routine updates and patching further strengthen the defence. Finally, robust backup and recovery plans safeguard against data loss from incidents like ransomware.

Over the past 12-15 months, several projects have significantly improved our cybersecurity. One major effort was strengthening the security of our platform, where we enhanced multi-factor authentication (MFA) and implemented additional policies and reporting improving the compliance and security of our systems. The audit by an external partner has also been a valuable project, highlighting areas in need of better protection and intensifying our focus on cybersecurity. Additionally, building new software products with a security-first approach has been both challenging and rewarding, as it allowed us to design robust infrastructure while learning new technologies. These initiatives have had a meaningful impact on enhancing our overall security posture.

Dave might use his determination and sense of collaboration to reach new heights as a team, but he isn’t the only changemaker at Aeromag. Discover the other fascinating portraits of the key players in our big family.