You Are The Strongest Link

You Are The Strongest Link

Share this article
Share this article
Prioritise Us on Google
Mathieu Manalo, CISO at finance platform ORIX METRO, explores the best way to keep employees engaged on best security practices

Human error is still a major vulnerability in digital security. Sometimes it happens by accident; other times, because of bad intentions; and it’s often outside the control of security teams. Attackers usually rely on social engineering and phishing to gain access to networks.

Attackers might send realistic emails to steal login details, then move from IT systems to operational technology networks. Even after years of training, human error remains a common entry point, showing that education by itself isn’t enough to keep systems secure.

But for Mathieu Manalo, Chief Information Security Officer at ORIX METRO Leasing and Finance, employees can actually be a company’s greatest strength when it comes to digital security.

“We have a saying in security that people are the weakest link in the chain. But I would like to challenge that idea and say if you can train your people, they can be the strongest link in that chain – [but] only if you can train them well.

“I wanted to change the perspective that security is not a blocker, but it's an enabler to a secure way of doing business,” he says.

“The biggest challenge is adoption because everyone is afraid of change. Change is scary for everyone, especially when we have different age demographics at ORIX METRO. So the rate of adoption is our biggest challenge, not really technology or budget or anything like that.

“When I joined ORIX METRO, there was a lot of fragmentation across the different solutions, the different infrastructures that we have. We have transformed the way our people work across the nation.”

As ORIX METRO's first Chief Information Security Officer, Mathieu leads the organization's cybersecurity strategy, governance and digital security transformation. His career has evolved from networking and telecommunications into enterprise cybersecurity, combining hands-on technical expertise with governance, risk management and executive leadership. He joined ORIX METRO in July 2025 after building experience across technology, outsourcing and financial services.

ORIX METRO Corporation is a joint venture between ORIX Corporation in Japan and Metrobank in the Philippines. The company mainly offers financial leasing, leasing products, fleet services, warehouse and insurance services.

“My main job is to oversee and, of course, develop the information strategy and the overall security roadmap of the company and its subsidiaries.

“I also lend a hand in digital transformation since transformation without security is like a very fast car with no brakes.”

Cybersecurity starts with people, not just technology (Credit: Getty)

Transformers assemble

To help with digital integration across the business’s 1,200 employees, Mathieu is part of the “ORIX Transformers,” a group that encourages and supports colleagues in using new digital platforms.

“The ORIX Transformers is a select team of the champions of digital transformation in the organisation. The journey is estimated to last three years, and we are chosen based on our strengths and how we spread the message of enterprise-wide adoption,” Mathieu says.

“The challenge for us as the Transformers is that you have a different spread of employees because you have people from Gen X, from the boomer generation, from millennials to Gen Zs. And the rate of adoption varies greatly per generation. You can have one subset of a group that's adopting faster than the other subset.

“And that's the reality: how people adopt these solutions and the changes we're bringing to the company.”

Leading digital transformation across every generation (Credit: Getty)

Wraparound care

To boost the company’s digital security, ORIX METRO partnered with Singapore-based cybersecurity firm Antarex. Together, they set up a Security Operations Centre to monitor and protect the company’s digital systems.

“Before we moved to a managed security operations centre setup, we had an on-premise team,” says Mathieu. 

“We had analysts on the ground in the office but there was a gap. And that gap was that we were only monitoring during office hours. And that was it. There was no extended visibility, so to speak. There were no after-hours, there were no weekends, no holidays.

“That was a glaring gap that we had to fix. So we came up with a way to outsource it to a reputable partner, [and] we chose Antarex to be our partner for the Managed Security Operations Centre.”

Although Antarex provides comprehensive digital security monitoring, Mathieu believes the company shouldn’t rely solely on a standard security solution or hand over all responsibility to a partner.

"The scheme that we designed is that they do the monitoring. We keep all of the remediation. All of the decision-making stays with ORIX METRO. They do not have administrative access to all of our assets. You still have to have that semi-trust issue with all of your vendors, because you cannot assign full trust to someone not part of your ecosystem, because that's how you retain your status quo of security posture."

Sharing responsibilities to strengthen digital security

​Making the awareness stick

It’s all well and good to train employees on new systems and educate them on digital security. But human error can happen at any time. Mathieu is working on systems that help keep the company’s strongest assets engaged and aware of digital security risks on a continuing basis.

“What I did in my first three months was establish the very first annual programme that celebrates Cybersecurity Awareness Month every October. It was the very first roadshow that we had, and we had 90% attendees across the nation. It was very impressive. But how do you sustain that?

“Of course, you cannot just have a month-long programme and just leave it at that because that's not how you retain awareness. You retain awareness through repetition. So we do that. We challenge our employees on our very own internal social network.”

In addition to ongoing awareness within the organisation, Mathieu has implemented a security training programme to help employees regularly stay on top of their digital security.

“We have partnered with Proofpoint to automate the training needs of our vast employee base,” Mathieu says. 

“Let's say a person from accounting, he or she might fail in complex QR phishing attacks. The platform intelligently assigns content to that person related to the very thing that they failed at.

“It's about automating and keeping the quality of the training and the intention that ‘Hey, this is for you, we're doing this for you, we want you to be secure, not just in the workplace, but also in your personal lives.’”

“Complementing that with the annual programme that we do and the weekly quizzes that we have is part of how you sustain awareness in the company.”

Security leaders have to balance making information security policies strong enough to protect against new threats while also keeping them practical and easy for employees to follow.

If a policy is too strict or complicated, employees will often find ways around it, especially if they need to work quickly. This can increase risk for the company. On the other hand, if a policy is too relaxed, it can give a false sense of security and leave important assets unprotected.

“We have what we call in security a 'compliance theatre'. It’s where you have all of the policies on paper, but nobody really follows them. It's just there for compliance,” says Mathieu.

“That's a big no-no. Your policies should be the main governance on how you do things, how you implement new solutions, how you maintain solutions and how you secure every individual facet of your business.

“We align our security practices with ISO 27001 and the US federal government's information security standards. Why? Because it covers everything that ISO doesn't have. And I don't want to have gaps in my policies or in how we make sure they're followed.

“It has to be easy to understand and it doesn't have to impede on all of your employees' day-to-day tasks. That's how you secure the organisation while keeping your employees happy.”

Continuous learning to build stronger cyber defences

Continuous learning

As with his colleagues at ORIX METRO on digital security, Mathieu is also always looking to continually grow and learn. This even goes back to decisions he made earlier in his career, which he says put him in a good position to tackle his current challenge.

“I took a very scary leap at the time [and] took my training in penetration testing. I did real ethical hacking, so to speak. It was very fun. I was very passionate about it. And that's one of the key factors why I believe that I'm effective at what I do. Because I understand how data travels, because I spent most of my career in network, I know how adversaries think, how they attack, how they do research on their targets

“And my proficiency in Governance, Risk, and Compliance, well, that's also a bonus, but I think that makes me a well-rounded CISO. I wouldn't say 'great,' because you can't be the greatest or smartest person in the room; that would just leave you complacent. And I don't want to be complacent. I'm very competitive with myself. I always push myself.”

In May, Mathieu spoke at the Fortinet Accelerate event in the Philippines. He believes that taking part in events like this helps broaden your perspective and find shared experiences.

“When you engage with different leaders from different verticals, from different industries, you get an insight as to what the challenges are that are different in their vertical and what you have in common. How did they approach it?

“You get to compare notes basically with another person and that's very valuable. Since I thrive on comparative data, I like to study the differences, and I get to offer my insights and how they can approach those problems.

“Getting the opportunity to be on a stage with different individuals in the industry, different experts, different executives, is also my way to share my insights, my inputs, and to give back to that respective community that I'm a part of.”

Company portals

Executives