The technology sector evolves at a relentless pace, and that forces all connected industries to scramble to keep up. For many companies, this scramble looks like prioritizing the adoption of new tools, systems, and software, which makes sense on the surface—integrate new technology as it comes out, and the company will never fall behind, right? The downside of this approach to innovation and technological development is that the people using those tools, the team that makes the company function, are never able to properly learn the tools in time to optimize their usage. In cybersecurity, this problem can be even more significant, with the potential strengths of new tech offset by their potential security weaknesses, and the complexity of resulting problems compounding out of control.
There may be a better approach, and it has seen success through history. Cybersecurity expert and the Chief Information Security Officer (CISO) for the Analysis and Resilience Center for Systemic Risk (ARC), Douglas Lemott Jr., has seen it all in his years of experience, and much of his success has come from a simple paradigm: “people, processes, then tools.” Even in times of rapid change and progress, the best result, in Lemott’s eyes, comes from focusing on empowering the people first, analyzing processes second, and putting the new innovations and tools last.
“In my leadership roles, I’ve found that the key is embedding innovation into the operational lifecycle—not as a bolt-on, but as a natural part of how we improve,” explains Lemott. “Cultivating a culture of experimentation and creative problem-solving within highly structured environments starts with acknowledging that defined processes and creativity are not mutually exclusive—they’re complementary when properly aligned.”
Empowering People With Experimentation
Given his leadership experience in both the United States Marine Corps and the private sector, it’s no surprise that Douglas Lemott Jr. takes a people-first mentality to effective work and innovation. At the core of any initiative, whether it be the creation of new technology, the development of a new process, or solving a problem, is trust. If the people on a team don’t feel safe to challenge assumptions, propose novel new ideas, or merely ask questions, then they aren’t going to be able to do their best work.
“I make it clear to my teams that processes are there to support outcomes, not stifle initiative,” Lemott says. “I encourage them to challenge assumptions safely and constructively. That means creating psychological safety where someone at any level can ask, ‘What if we tried it this way?’ without fear of being dismissed or penalized.”
Douglas Lemott Jr. understands the value of experimentation, especially in the agile and creative environment of cybersecurity, and thus empowers his team to experiment in safe sandbox environments, red-team/blue-team exercises, and internal ‘innovation sprints’. Security must be disciplined, but it must also be flexible and creative; by providing these opportunities and encouraging his team to engage in these controlled experiments, Lemott’s team can produce insights that improve or even rewrite existing processes. This efficiently creative environment creates solutions focused on the mission, without wasting any time or energy.
“Every creative solution is aligned to the mission—whether that’s reducing risk, improving resilience, or enhancing efficiency,” Lemott explains. “I teach teams to ask: ‘How does this help us serve the mission better, faster, or more securely?’ That question becomes the bridge between structured processes and creative thinking.”
Bottom-Up Trust And Communication
The other critical step in empowering the team is the simplest one: listening to them. Trust is critical for any enterprise, but is especially so for an industry charged with protecting the systems and data of hundreds of thousands of people. Lemott builds trust by building an environment where psychological safety and accountability coexist; the alternative is a workplace context where people have ideas but no venue, no permission, and no confidence that they’d be heard if they spoke up.