
Loading summary
A
You're listening to the Cyberwire network, powered by N2K. If you like what you're hearing so far and want to learn more, add our recent episode with Cynthia Kaiser from Halcyon into your queue. In this episode, we discussed how to build defense in depth strategies to address the threat of ransomware and what designating ransomware groups targeting hospitals as terrorist organizations would mean for thwarting cybercrime. Now let's get back into the episode with Matt.
B
Backups are 101 for it. If you're not doing any backups or you don't have a provable backup position, you may as well not do anything else.
A
Hello and welcome to Data Security Decoded. I'm your host Caleb Tolan, and in this episode I sat down with Andy Wells at the allmac Group to discuss the lessons he's learned across IT and security. After nearly three decades of running technical programs for a global pharmaceutical company, let's get into it. Well, welcome to the Data Security Decoded podcast. I'm really excited to have this conversation with you. And you've been at the allmat group since 1998 for the past, like three decades. And you've watched the entire digital transformation of the pharmaceutical and life sciences industry from the inside. So when you look back over the past three decades, how do you think about security in the early 2000s versus today? What's the biggest shift that you've noticed and how has that affected your thinking?
B
Well, security is now front and center rather than being something that was a checklist at the end of implementation. So we have shifted where the security team gets involved in the development life cycle. If we are building something and if we're buying, we have them there. Day one with the RFI RFP process and then with all of the vendor demos and so on. And we insist on a baseline of evidence that the vendors must show us, otherwise they're not really in the game. And you'd be surprised that they can't make that more often. Well, not more often than not, but on several occasions they won't produce the evidence we asked for. They won't be able to give us a statement of applicability. And then, you know, we just have to end the journey with them at that point. We also have, given that we work well, given that it's good sense, and also that we're in a highly regulated industry from, you know, from government on, from our customers who are also wanting us to interpret the regulations the same way they do, we have a significant burden. Well, it's not fair to call it a burden, but we have a significant compliance workload to allow us to deal with maybe 200 audits a year across all the sites. Now when people hear me say that, they go, yeah, right, 200 audits a year, but it's actually true, you know, and majority of those are customer audits. But there would also be maybe half a dozen or so full on government audits, including American fda, European Medicines Agency, I think it is. And then in the UK now we have the reconstituted MHRA and a post Brexit scenario and we have two coming up next week and they pick a site and then focus on what you do at that site. And sometimes now increasingly you're not necessarily getting an early view of the agenda. So things have changed a little bit in that regard as well. But infosec is now square on in the center of everything we do.
A
Right. And so you think from your perspective over these past couple of decades we've made the appropriate shifts and you feel like infosecurity is brought in at the appropriate time at this point, or do you think that there's still room to be made there?
B
Well, I think they're brought in at the appropriate time. I think the value that they bring to the table needs to be constantly watched, you know, because you never want to get into a box ticking exercise where infoseca asked, yes, they were and they said it was okay. And are they actually dealing with what they're being asked to do correctly? And so there's always a need to keep an eye on that, as there is with all teams. Are you taking this seriously? Are you doing your job correctly? Do you understand why you're being asked? We're not just wanting to follow a tick box exercise. We're also, about four or five years ago we achieved ISO 27001 certification and that really helped us to get the teams working together and to make sure the controls crossed over the functions that were involved. Typically it could be service management and infosec or infrastructure and infosec. And you know, we're improving all the time, but we're all on a journey. You know, none of this comes to the point where you hit a stop sign and sit down and relax because the bodies, as we call them in the UK and Ireland are always trying to get you right.
A
And we'll get into a little bit more about the audits that you mentioned before and also chat a little bit more AI in a moment, but I have some questions for you there and I want to Talk to you a little bit about Almack's dual role as both protecting your own data and the companies that you serve. So what, what does that dual responsibility really look like in practice for security from that standpoint? And specifically, I know identity resilience is a big priority of yours as well now, so how does that play into the picture and what is your philosophy for addressing this challenge from a technological perspective in addition to process and culture?
B
Well, I'll start with the culture. Right. So ALMAC exists to improve human health. That's its sole function. We're not a company that takes a profit dividend to give to shareholders or to give to directors or anything like that. We're actually structured as a. I don't fully understand this, but we're a foundation. The Maclay foundation owns Almack. Almack comes from Alan Maclay. So this was all established to protect his legacy. And we need to make enough profit to have enough money to reinvest to continue to grow the business. So that's the focus on financials and EBITDA and so on. But it's not to make two or three individuals super wealthy. And for the rest of us to not end up in that scenario. You hear an awful lot of companies who say our people are our number one asset. Right? Corporate social responsibility, whether that's in an eco scenario or in just genuine looking after the community that you work in, we were practicing that long before it became trendy. I remember seeing two of the very senior executives looking out of their office, the Sheridan office, looking out of their window on a, oh, Friday afternoon, full car park. And thinking is not great. We're creating enough wealth here to keep our employees happy to them. They can feed their families, they can take them on holiday, they can have a decent standard of living. And at the same time, we're improving human health. You're very much respected as an employee and our customers are number one equally with our employees in terms of trying to satisfy their demands and their needs. So that was the culture. The process then, in terms of looking after the data is very much based around gxp, which is the governing principles that look after pharmaceutical processes. And we call it GXP because there's gmp, good manufacturing practice, glp, good laboratory practice, and then gcp, good clinical practice. And we need to cover, depending which business unit, all of those. And they're based around a solid core. It's not 300%, it could be 140% based on the differences between the solutions there. But we, as strictly as we can abide by those guidelines. And they would have started off maybe years and years ago. You have to have standard operating procedures, you have to have policies, you must be trained. You can't do any actions in a GMP environment if your training isn't up to date, signed off by a supervisor and so on. And now while we've moved on from paper records and so on into more digital records, those same principles apply. We look after the data by making sure that only the correct level of access is given to the data. We're very focused on it, good practice in terms of having least privilege access to IT and making sure there's role based access control to the systems. And that then forms typically part of the overall validation pack of any system that we're putting in place. Validation again is a key, a key principle of txp. You design a system, you document what you want the system to do, you design it, you build it and then you validate that. It does that and then everything else goes under central change control. And I think from a non IT perspective, if you follow those principles, your data's in a good state in terms of separation and ownership and documenting who, who accessed it and when. And in particular you have to sign off why you're doing something. And so I would sign as I, Andrew Hillison, modifying this field for reason X, sign off and commit that to a store that has to be around for whatever the QMS is for that particular division. So from the technology perspective, then again, it's good IT practice. You have to have backups. I always use an American term to describe backups. Backups are 101 for it. If you're not doing any backups or you don't have a provable backup position, you may as well not do anything else. And also the capability of the solution in terms of what IT can back up and what it can give you assurance on in terms of, well, is that data clean? Is it as was, Is it immutable? All of that good stuff, which has been a game changer for us because, you know, it's a big enough exercise to change a backup vendor, you know, as we saw them at the time and very glad we did that. And we've got a much better foundation there now for other services such as the stuff that's very relevant to today, which is the minimum viable company and recover times and the confidence behind those recovery times. And also you've got the data here, then you've got your cloud services where you've got data and then you have Your identity stores, which can very often come in more than one. I don't know if that fully answers what you were asking me there, but I think it probably covers most of the points there in terms of the data. We also use industry standard technology here. There's no open source or anything in Almax environment. It's all, you know, some of the larger IT manufacturers providing a database that you're pretty sure if you put data into it, you're going to get it back out, which hasn't always been the case. So.
A
Yeah, so when I have conversations with different technology leaders, a lot of times it's with someone or in an industry where people don't have all of these best practices already implemented and you seem to have some kind of secret sauce. And that's what I really want to get to the ingredients of your secret sauce because. And you've been at Olmec for almost, nearly 30 years now. And I want to get at what has happened over the course of those three decades that has gotten you to the point where you have implemented all of those foundations.
B
Well, I think we have been. I mean, it is expensive. Let's not try to pretend it's anything other than that. Right. But once you. And we started off very much as a startup, you know, there was a business reorganization in 2001 where everything effectively went back to square one. Revenues, EBITDA employee count was just a couple of hundred employees. We were very much like a startup, you know, and the commercial guys had to go out and win the business and mature the commercial approach. And as those all matured and moved forward and profitability returned to levels that we could invest, then the board, I'm not claiming any credit for that. The board then saw that they had to not only concentrate on manufacturing and labs, but they had to concentrate on the infrastructure that would support a group of best in class companies or wanting to be best in class companies. You can't take shortcuts in pharma. You will be caught out and then you lose clients and you lose business and it's a very quick trip to the bottom. So the board have been very supportive of anything we have asked and then we as an IT management team just have this ethos of we're going to try and do best in class here. Now, it doesn't always lead to happy conversations, whether that's with the board. Andy, Wednesday's going to stop or indeed perhaps the staff will be feeling a bit put upon at times if they get something else to do. So we take our time we try and make the correct decision and then we try to get that implemented kind of before we need it so that we're looking at it and then are able to adopt it going forward. And it's the same right across the entire stack here, whether that's when do we adopt cloud, when do we adopt Office365, you know, when, when, when which all has spend associated with it. And then it, as you will know better as well as anybody, is cyclical, you know, So I used to have a laugh with the cloud salesmen that used to come into us in the early days because our customers are very, what's the word? They're very cautious, they're very happy to audit us and to make sure that our controls are looking after the data that we store on their behalf. Right. It was a long time before they trusted the cloud vendors to do that. So therefore we had to be in alignment with them, cloud as appropriate. So you're not doing cloud for the sake of it, you're not born in the cloud, you're not doing cloud first. Each individual use case was the way we treated that and that has worked out relatively well for us, you know.
A
Right, right. Well, I'm glad to hear it. So going back to some of our conversation about your security posture, it seems like you have done something that is really influential for your organization and it's really admirable. And I think what you're doing is the goal of many organizations. So I want to pressure test some of the things that you've implemented. Have there ever been moments, you know, through like a tabletop exercise or audit findings, anything that has merged in your threat model that has specifically, maybe even from an identity perspective, since that's now one of your big focus areas, kind of helped shape that central lens for your security strategy.
B
There probably have. I'm not going to pretend we haven't had the odd heart stopping moment over the years, but we've always been able to avoid it or to recover from it without having any customer impact. You know, it's a classic scenario where somebody's credentials get phished or. And then all of a sudden what are we doing? So we started to see a lot more of that when we implemented Office 365 or M365 as it was known at the time, started to see a lot more of that in terms of attempts and impersonation and so on. So in that same sort of timeframe we recognized that, look, we can't do this on our own. We just either don't have the capabilities or we don't have enough people to respond in time. So we went to the market for SOC Security Operations center and this is one of the few, the few services that we genuinely outsource. Right. So we've now got a. We're on our second SOC in that journey. This one is much more automated, much more in fact they're just releasing an agentic society to deal with the agentic threats and they have really been able to cut down on so much of the noise that we just couldn't keep up with. Where if you're going from assessing the capabilities of a package or something, you're going to buy to all day, every day dealing with alerts about phishing emails or because. And then you've got to worry about all they still enjoy working here, they've got to move on and so on. Because some of that churn, as you know, can be quite costly. But we're in a good spot at the minute. We have very little churn in our infosec people. We have a great leader.
A
Well, it sounds like you have a really great culture too.
B
Well, we do have a good culture, but we have a great leader of information security who we can absolutely get an authoritative response from. So we're lucky in that way. He's not the sort of person who said well you could do A, B, C or D. He'll come back and say but he is the right way to handle this particular situation and that inspires his own team and the rest of us.
A
Right. Well you already kind of dove into a little bit of my next question which was all about AI usage and how you're approaching that. You already talked about your Agentix SoC. How else are you approaching AI deployment right now? Well,
B
it's no surprise that the board want AI. You know, every board does. Right. So we're no different from that. We made an investment in Microsoft because we have a big Microsoft both capability I guess, and also infrastructure and software and all that good stuff. So we started off with a very cautious approach. We did the deal commercially and then we spent six months trying to get our data correct so that we could maximize the value. Now, six months was only the start of it. There's a lot of work still to be done. And then also we put in place a champions program to make sure that people would take ownership within the business units. It wasn't an IT led initiative and would put what we called a council in place so that if people wanted to use AI or non Microsoft AI in their Business process. They had to request it from the council and then infosec commercial coo. I'll sit on that and get visibility of what people are attempting to do before it's too late. At the same time, the pharmaceutical regulators were taking a position on or trying to formulate a position on it and that guidance came out, I'm going to say last year and it was very much for critical as they described it, GMP operations AI was not to be used initially and then it has since. Well, there is a thought process now that as long as there's a human in the loop it's okay and as long as it is deterministic and not probabilistic. So there are a number of caveats that you can use. So if you look at it in terms of measuring a return. Well, a return on that. We've kind of done the ROE now which is return on employee as we call it. We can get busy project managers home to their families an hour quicker than they would have done because the minutes from the meetings and the summaries and conclusions are all in place. We have the Champions program that decides and delivers agents, sort of single use type agents, you know, for them and their peers. And we have unbelievably a couple of thousand of those now. Now they're all ROE type or a work group agent for maybe six salespeople working in a particular device. And we don't have anything significant in end to end business process. We're still trying to work out an ROI on that in terms of where it'll fit. But when you're telling yourself the position in your own head, it's maybe more, it feels more real to ALMAC than perhaps the board in Almac in terms of. Not that they're putting us under a huge amount of pressure, but they're very interested in the CEOs all over it because he needs to make sure that all of our operations are still valid and so on. But they've been very supportive. So we're now trying to address that and we're also trying to provide guidance for citizen developers so that all the pressure doesn't fall on it shoulders, but it falls on. Well, the AI developers are keen, they want to try and improve their lot so we want to try and cautiously encourage that. But again it has to be done with guardrails and controls and so on and those are difficult messages to pass through. Some person's been working a month and delivered something really actually quite useful, but he's done it at home on his home laptop on his home machine and he hasn't maybe used the tooling that we want them to use. And you know, so we just forget it. You can't do it because once you give one exception, then you're not him and you let them. So that has got a little angsty at times, but like it is always angsty.
A
Right, right. How have you managed to strike that balance? Kind of, you know, shift the perception of it and make sure that InfoSec is a bit more collaborative.
B
We'll be shifting them left. As I mentioned earlier on, they're not at the end of the process any longer. They're not saying no. And my mantra to them is it's not your job to say no. It's your job to safely enable what the business wants to do. And I think when you frame it in those terms, then a lot of that goes away. We're dealing with a slightly different scenario now in that we're not having infosec talking to a project team. There's a discussion between what we call the Copilot champions, which is our tool of choice for this agentic AI on the return on. Let me get this right on the return on employee gig and then they have access to Copilot Studio, but not to extend it by bringing in Python or bringing in other add ons into the tuning. So not only are we we trying to guard rail that, but then the big IT vendors are not making our life easier either because in an enterprise environment that almag is, albeit a medium sized enterprise, they're enabling some of these items that kind of go against good IT principles.
A
Yeah, well, I'll say I've already mentioned it a couple times. The way that you've approached the evolution of IT and InfoSec over the years has been very admirable for folks who are listening who haven't made all of those advancements that you've had and really want to get as much done as possible. What would you say are the three most actionable steps for a company? We'll keep it in the same sector, Life sciences, pharmaceuticals. How would you recommend they approach this?
B
Well, I think the first thing you need to do is know exactly what you have. Right. It used to be relatively easy because the network was the boundary of your state, your kingdom. Now, of course, it stretches from Tokyo to California and everywhere in between. And all these cloud services make things more challenging in terms of the connections and the trust models and so on. But you need to have an accurate view of what's on your network, what is in your alma. In our case, in the Almica step. And that is a difficult thing to achieve because things are dynamic nowadays. So you need a. In our case, we invested in a discovery tool that looks at every packet that goes anywhere on the network and that has brought us great value once we understood how to actually use it. Because some of the numbers it comes up with, you have to just go, hold on a minute, where did that come from? And then as you gradually get to use the tool and configure it in a way that makes sense, I don't want to see how many we've had over the past 30 days. Just tell me what we have now. We've implemented a significant number of dashboards there and they give us visibility on things like how many we have broken down by asset class and then further broken down by any vulnerabilities that it finds. And we can continue then to look at those vulnerabilities and address them and so on. So that's it. Knowing what you have and what you're dealing with. Right. Is one thing. Secondly, then I think the acceptance that you can't do it all yourself, you need help to do this, whether that's professional services from IT security vendors or product companies, or bringing in more experienced staff, making the case of the board, getting them to take information security properly seriously. Sorry, because I don't know. I know Oy almight does it. I couldn't really get. I mean, I've seen some of the headlines we talked about this morning, but you know, you know what statistics are like, how many of those board members are actually taking it as seriously as they should be? Is it just a box ticking exercise? You know, I told them they were meant to do that, but I didn't give them any funding or any. And then I think really have a plan to move from whatever your level of maturity is now to where you feel you need to get to. So we had ISO 27001 as a target. We told everybody we were going to do it. So that's a big enabler for things as well that you socialize these things. In our case, you go and explain it to the, the business unit heads. We see the pressure coming in on commercial RFIs and RFPs saying, Are you ISO 27001 certified? Are you NIST2? Are you X and Y and Z? And that was a big boost for us. Yeah. Because we were able to argue, look, we have to do this ifs or buts about it. Huge amount of work to get IT done. We got it done. We've been now through several years of inspections and so far so good. So know what you have. Devise a plan and get it sufficiently resourced to allow you to execute it. Because our problems are no different from anybody else's. You know, we've got a lot of regulatory scrutiny, but from an IT perspective, you need to be doing the basics correctly and making sure that you can follow those up and report off them and report progress. And I think also where we've been more successful in this than in any other maybe initiative is that we've had a dedicated set of resources to execute it and a company that has evolved the way we did. You might have multiple huts, doesn't really work in enfosec. You need the appropriate level resource to get it done in a timely fashion. I'm very much looking forward to this wave of agentic AI, sorry we'll call it AI based solutions here that are going to help, that are going to allow much quicker assessment of where we stand. Much quicker, sorry, ability to do virtual patching, to have these things stopped at the edge so that no less opportunity to get into telmic. And then also just the impact assessments. Doing an impact assessment is a critical skill and you'd be surprised how many aren't 100% correct because it's a complex thing.
A
Yeah. And I find this ROI model that you have for your AI implementation very interesting and I think a lot of other people will find it very interesting as well. So what are two inconvenient truths that the industry at large, not just healthcare and pharma, but generally IT and infosec roles. What are some inconvenient truths that they need to face about understanding AI implementation and what do they need to come
B
to terms with right now? I'm a bit of a cynic, as you may have worked out by now, I don't know, but I think a lot of, I can't remember a significant wave of IT change that has actually delivered exactly what it said it was going to do or what it was going to claim. So we would have had all the marketing. Just go and use AI. It's your best friend. It's going to turn you into the fastest, most agile company on the planet. And then you find out you can't really do that without redesigning your entire data set. You got to have these guardrails, you got to have visibility of what it's doing. So it's another problem solved, half a dozen created, which happens in it all the time. So I think that's an inconvenient truth that nobody wants to necessarily talk about.
A
Right.
B
And then from an infosec perspective, For me, for Almack, it's the approach and the level of acceptance or risk. We have a very low tolerance for risk because the nature of our business and that we're looking after on occasion, other people's data. So the tendency is not to accept any risk, and then you end up with more work to do and shorter time frames and so on. So the counter to that is that I think these promised virtual patching solutions and so on that are going to come from some of the tech vendors in the infosec space are gonna lower those risks.
A
I love it. I love it. All right, what is the single most important message you want to leave with our listeners today?
B
Know what you have. That's there's no point in fixing something and not knowing what you don't have, because that's where you'll get. You'll get hit.
A
Wonderful. Wonderful. Well, Andy, thank you so much for joining the podcast. Until next time.
B
Thank you. Foreign.
A
That's a wrap on today's episode of Data Security Decoded. If you like what you heard today, please subscribe wherever you listen and leave us a review on either Apple Podcasts or Spotify. Your feedback really helps me understand what you want to hear more about. And if you want to reach out to me directly about the show, email me at data-security-decoded2k.com thank you to Rubrik for sponsoring this podcast. The team at N2K includes producer Liz Stokes and executive producer Jennifer Ibin. Content strategy by Mayan Plow. Sound design by Elliot Peltzman. Audio mixing by Elliot Peltzman and Trey Hester. Video production support by Bridger Kirke Wilde and Sorrel Joppy. Until next time, stay resilient. If you like what you're hearing so far and interested in learning more about forensics behind an attack targeting critical infrastructure, check out our episode with Daniel Desantos from Forescout about a honey pot his team set up mimicking a water treatment plant. Now back to the interview.
Host: Caleb Tolan (A)
Guest: Andy Hillis, Allmac Group (B)
Date: July 14, 2026
This episode dives deep into how the Allmac Group, a key player in the pharma supply chain, has transformed its approach to data and information security over nearly three decades. Host Caleb Tolan interviews Andy Hillis, who’s overseen technical programs and digital transformation for Allmac since the late 1990s. The conversation explores the evolution of security―from tick-box compliance to central business enabler―and offers actionable insights for IT and security leaders in highly regulated and high-stakes industries like pharmaceuticals. Key themes include the role of organizational culture, identity resilience, audit & compliance, responsible AI adoption, and prioritizing fundamentals.
Security’s Shift to the Forefront
“We have shifted where the security team gets involved in the development life cycle… Day one with the RFI RFP process and then with all of the vendor demos.” — Andy Hillis [01:32]
Regulatory & Audit Burden
Company Mission & Foundation
GxP Principles and Technology
Backups as Foundational
Tech Stack Choices
Security is pressure tested via audits, tabletop exercises, and live threat response.
“We’ve always been able to avoid it or to recover from it without having any customer impact.” — Andy Hillis [16:32]
High-Touch Response to Phishing & Identity Threats
Culture & Leadership
“He’s not the sort of person who’d say ‘you could do A, B, C or D’. He’ll come back and say, ‘B is the right way to handle this situation.’” — Andy Hillis [18:36]
AI Demand & Cautious Rollout
“People had to request non-Microsoft AI… infosec, commercial, COO all sit on that and get visibility before it’s too late.” — Andy Hillis [19:10]
Adhering to Regulator Guidance
Cultural Adaptation & Guardrails
AI ROI: Return on Employee
Three Key Steps:
“Our problems are no different from anybody else’s… you need the appropriate level resource to get it done in a timely fashion.” — Andy Hillis [29:23]
Inconvenient Truth #1:
Inconvenient Truth #2:
“Know what you have. There’s no point in fixing something and not knowing what you don’t have, because that’s where you’ll get hit.” — Andy Hillis [32:30]
This episode serves as a masterclass in resilient, practical cybersecurity for highly regulated industries. Andy Hillis shows how Allmac Group overcame “box-ticking” mentality to build a culture where security truly enables business. The key takeaways are clear: put real resources into knowing your environment, never shortcut compliance or baselines, and adopt new technologies (including AI) only with proper controls, oversight, and patience. Above all, relentless asset inventory is the backbone of defense, and the rest is execution and culture. This session is packed with direct, actionable insights and hard-won wisdom from the pharma supply chain frontline.