THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Noah Davis is currently the VP and Chief Information Security Officer at Ingersoll Rand. He has gained extensive experience internationally as a result-driven technologist who resolves technical problems within global Fortune 500 diversified sectors. At Ingersoll Rand, he oversees the company’s global cybersecurity function. He has been successful in partnering IT with businesses, streamlining operations, and reducing costs.
Noah Davis, VP, Chief Information Security Officer (CISO), Ingersoll Rand
Please share your journey over the years in the industry and shed some light on your current key roles and responsibilities at your organization.
I have earned a degree with a quadruple major in finance, accounting, computer information systems and international business. I have worked on the big scandals of the time and written papers on Enron, WorldCom, and Tyco. Soon, I joined Tyco for an IT audit after learning about the opening. Then, I joined forces with Ingersoll Rand as a senior IT auditor, where I was responsible for looking after ERP implementations on a large scale for 11 years. Eventually, I was hired as a senior manager at Bombardier in Berlin, Germany. I was in charge of the end-user computing department and handled pioneering projects like Dynamic Desktop. I returned to Ingersoll Rand when I was called to establish their global IT audit department and advance the development of a cybersecurity audit program. This was during 2010 when nation-state actors were getting popular; I was running the IP audit department.
My job role was evolving within cybersecurity, encompassing various aspects of the domain. I also worked in leadership positions at Trane Technologies and back at Ingersoll Rand for a $4 billion acquisition. This is how I have gained extensive experience in a vast area of cybersecurity.
What are some of the major challenges that the CISOs are facing today?
One of the major challenges that the CISOs are facing in the industry is the lack of communication in navigating technical cybersecurity risks within organizations, particularly for non-technical executives and board members. The cybersecurity poverty line, which encompasses numerous Fortune 1000 companies, doesn’t bother about their risk exposure since they don’t know the consequences. To overcome this challenge, translation of technical threats is essential within the business context, aligning with the business language of finance, accounting or operations. The role of CISO is to understand the organization's core operations to better analyze the risks associated with cybersecurity, particularly in understanding operational impact and not merely technical terms. This approach can align with cybersecurity strategies and business goals.
How can CISOs be prepared to face these challenges, or is there a strategy that should be implemented in their organization?
I believe we should be proactive from the beginning to handle issues effectively. Our cybersecurity strategy is designed for Fortune 500 with revenue of $7 billion and deals with two major approaches. Firstly, we protect the house by improving our security posture, patching vulnerabilities, and conducting detailed employee training. This is done through regular phishing simulations and frequent sessions for cybersecurity awareness. Secondly, the strategy is designed to engage third-party experts to examine the organization’s understanding of frameworks like NIST CSF. Our organization's risk tolerance helps guide our maturity level, aligning with the defined process (level 3) and highly optimized automation (level 5), adhering to the compliance of the manufacturing sector.
Is there any recent project initiative that you have been a part of and you were successful in implementing?
Generative AI is prone to both challenges and opportunities in the domain of cybersecurity, fueled by the excessive use of the internet, particularly in the late 1900s and early 2000s. Although generative AI is advanced in providing efficient solutions like detecting cyber threats, it also facilitates the hacking process, especially in email security. In today’s digital landscape, traditional secure email gateways that are based on bad hashes are getting elusive. This drives organizations to shift towards AI and ML-based email security options against single-serving cyber attacks. Modern cybersecurity tools have also facilitated detection and response processes within multiple admin consoles. So, centralized security platforms work in a unified platform, significantly enhancing incident resolution times by streamlining workflows.
How do you envision the industry's future amidst the transformations and disruptions, and how should CISOs adapt to the changes?
Amidst the transformations and disruptions prevailing in the industry, CISOs fosters great collaboration and communication in the cybersecurity domain. Adaptation of new changes becomes easier by embracing flexibility and openness. This helps in developing strategies and sharing experiences and insights with team members in defending digital assets from cyber threats.
"We blend advanced cybersecurity tools with neurodiversity in defending cyber threats and managing every digital asset effectively. our approach to developing security process is to bridge the communication gap in understanding technical threats within the business context"
We prioritize collective networks and shared information to improve cybersecurity practices and manage the security process collaboratively. This approach bridges the communication gap, assessed by the threat actors, emphasizing the need for similar cohesion within the blue team that encompasses defense-oriented cybersecurity professionals.
What advice or suggestions would you like to impart to your fellow CISOs?
To enhance the communication process in the cybersecurity community, I follow the approach of “BBG,” which means to be brief, bright, and succinct in communicating cybersecurity strategies. I focus on addressing specific questions rather than anything in general to demonstrate clarity in understanding organizational risks aligning with business goals. The aim is to ensure stakeholders that cybersecurity is managed efficiently through risk strategies and investment standards.
Another important aspect of attaining success in the cybersecurity field is to embrace neurodiversity and develop the skills to manage a diverse group of people. For instance, a lot of DHD and autistic people perceive the world differently, so we need to be flexible enough to manage these people distinctively. They have the ability to complete their work efficiently within fewer working hours, which other employees might not be able to do. Therefore, be open to accepting these differences in the working space because this could serve as a superpower in terms of cybersecurity defense.