
Lessons From (Re)Building A Security Company From Scratch
getty
I've always admired the Roman architect Vitruvius, who once said that if you're going to build something, it ought to be beautiful, strong and useful. After spending the past two and a half years building the software and platform engineering teams, as well as a new security organization, at LastPass, I've come to truly understand how right he was.
I joined LastPass in 2022 as its chief secure technology officer (CSTO)—combining security and technology into one role—an opportunity I couldn't resist.
The business was taking the first of many steps to spin out from its parent company and form a stand-alone company. A whole new executive team of industry veterans was at the helm, setting out to deliver on the promise of tackling the decades-long, ever-complex challenge of passwords—making them more secure and more convenient for people and organizations.
This was my opportunity to integrate security by design, not just into the company's operations but throughout the entire product development life cycle. I would work alongside the leaders we had assembled to build something beautiful, strong and useful from the ground up.
Three months after I joined LastPass, the company was the target of a sequenced set of two security attacks that spanned multiple months and threatened to derail everything we were working toward. But in the end, it didn't. In fact, the security incident acted as an accelerant for the people, process, technology, controls and infrastructure initiatives we already had planned to build while establishing a new company from scratch.
In reflecting on this experience, I hope to offer something relatable in its honesty, strong in its lessons and useful to anyone tasked with rebuilding—not just systems, but trust. Here is how you can do it.
From day one, I knew that security couldn't be a checklist—it had to be a blueprint. If you want to drive innovation while keeping trust intact, security, privacy and engineering must be tightly coupled.
It's important to consciously embed security into every phase of decision-making and build the right teams around it—architecture, threat intel, governance, detection and response. We did it intentionally and with buy-in from across the company, leveraging the outcomes of decades of experience to understand where security can be a differentiator and become a business-enabler.
As an example, and something unique among password manager providers, we built a dedicated threat intelligence team. With backgrounds in counterterrorism and financial services, this team monitors threats, delivers actionable insights and automates threat response to help protect our customers, data and company. It's not just a line of defense—it's a proactive, strategic asset that keeps us a step ahead. That's what it means to design with security at the core.
Security and engineering won't click together on their own. You need to define how they'll collaborate—and then back it up with process, structure and, most importantly, the right people. We hired brilliant engineers from world-class companies and combined them with our existing team. The mix gave us a rare advantage: experience, new ways of working and belief in the mission.
Hiring great people is step one. Step two is giving them the space, clarity and support to do their best work—especially under pressure. As a leader, your job is to make sure they know you trust them and to give them the resources they need to succeed.
We built an entirely new development infrastructure in months because the team believed they could. And they were right. Transparency was our prerogative, and that's why we documented how we made LastPass secure. We have a trust center where we reflect, and we've also created a publicly available compliance center for close to real-time monitoring of LastPass systems and access to the latest certifications.
We didn't just rebuild the platform; we reimagined it through the lens of the customer's experience. What did users need? Where were the friction points? What would make them feel safe, confident and in control?
That's what drives decisions—from introducing stronger password recovery options and implementing secure sharing to strengthening master password protections and encrypting sensitive data fields. Through hackathons, we've started to integrate new features and functions like AI into our platforms.
Under pressure, perfection is a luxury. Progress is a necessity. There were days when we moved fast because we had no other choice. But every sprint, every decision, every hard call got us closer. You need to be flexible, decisive and focused on what matters most—especially when time and attention are scarce resources.
I'll never forget the conversations I had with dozens of CISOs from our customer base—internalizing their concerns and their wishes for the new LastPass. The first time a CISO asked me, 'How are you doing?', I was moved to tears. Imagine possessing such empathy and grace.
This—the security and experience of the people behind our product—was our raison d'être, fueling us through every 20-hour workday. So here is my advice: Talk to your customers. Listen. Internalize what they're worried about. Let it shape your work. Then build something worthy of their trust.
That's what we did. We started with a mission, built a blueprint for success and responded to adversity with momentum through our people, empowered and enabled by the support of our leadership. We've seized a once-in-a-lifetime opportunity. We have built something beautiful, strong and useful—and so can you.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Eater
5 hours ago
- Eater
A Titanic Vietnamese Cafe Opens After Much Hype in Portland
is the associate editor for the Northern California and Pacific Northwest region writing about restaurant and bar trends, coffee and cafes, and pop-ups. The most successful cafe in Vietnam is about to open its first location in Oregon. Trung Nguyên Legend Cafe opens for business on Saturday, August 2. This opening was first teased earlier this year. The new outpost on 8435 SE Powell Boulevard will be open 7 a.m. to 4 p.m. every day of the week. The business's big new space — the 1,800-square-foot former restaurant and billiard hall Pho Le II — sits in the western chunk of the Powellhurst-Gilbert neighborhood. Owner Brad Tran confirms he has secured a second lease for Beaverton. That space is set to open in November. He says opening a business in Portland is wildly difficult, with a laugh, and that this weekend is more of a test run to get staff at the SE Powell Boulevard location up to snuff. After that, there'll be a big party. He plans to extend hours to 9 p.m. when they start cooking a full menu. Trung Nguyên Legend Cafe The drinks are what's made Trung Nguyên Legend Cafe line-inducing. There are the Ottoman and Roman ice milk coffee sets, each a pretty display in singular serving vessels. The Thien Coffee is the most popular signature drink for the business, served in a small black pot. Though the cafe is beloved for its rendition of kopi luwak — a regional specialty coffee that traditionally uses beans digested by civet cats — Tran says everything the company sells is made in a factory now rather than with the animal. On the food side of things, it's all counter items available as grab and go for now. Think croissants and a few cakes. That full menu down the road will feature fusion Asian food, as Tran puts it. Such dishes include banh mi, pho, and rice platters. This type of cafe within the company's matrix is called the Legend 'Coffee World.' For Trung Nguyên Legend fans, that distinguishes this outpost as one of the nicer versions, like a Starbucks Reserve rather than one of the typical cafes. (Those more common cafes are called E-Coffee, which uses a lower grade of coffee bean.) This Portland location has indoor seating for about 60 customers with room outdoors for about 10 people. In the United States, there's just two other outposts, a majorly popular Los Angeles location that opened in 2023 and a brand new shop in Texas that opened in early June 2025. According to a press release from the company, the cafes are pushing further into the United States and China going forward. Trung Nguyên Legend Cafe Trung Nguyên's wide array of flavors that are worth trying, and the ornate presentations, is unusual for most American coffee fans, Tran says. It's new to the Western market, he adds, and nothing like the Starbucks most are familiar with. 'Vietnamese coffee's been getting a lot of traffic in Western culture,' he says. 'Especially this brand. The bean is number one rated in Vietnam.' Trung Nguyên Legend Cafe (8435 SE Powell Boulevard) opens Saturday, August 2, and will operate 7 a.m. to 4 p.m. every day of the week.


Business Journals
2 days ago
- Business Journals
Eneida Roman of ALX and Kristin McSwain, senior advisor for early childhood, on charting a new path for child care in the region
Subscribe to C-Speak so you never miss an episode. Listen on Apple Podcasts, Spotify or wherever you get your podcasts. In this episode, Saskia Epstein, SVP PNC Bank in New England, sits down with Eneida Roman, president and CEO of ALX, and Kristin McSwain, senior advisor for early childhood and director of the Office of Early Childhood for the city of Boston, to discuss the state of early childhood education in the region. McSwain shares how she became interested in early childhood education and what led her to become involved in The Boston Opportunity Agenda, as well as to spearhead development of programs for young people and child care in the Office of Early Childhood. 'I think it's really important for our child care providers to see themselves as business leaders,' McSwain says. 'They're providing those first formative four or five years for our littlest learners that are really important for the economic prosperity of our region.' In the episode, Roman discusses the fact that a significant amount of child care providers in Massachusetts are Latina and how she has focused on providing programs for those individuals to set children up for success. 'I have this immense awareness of how important it is to make sure we have a structured child care space for children so that when they're ready to enter a school, they have the basic knowledge and tools to be able to be successful,' Roman says. Listen to hear more about:


Business Insider
4 days ago
- Business Insider
Google's (GOOGL) DeepMind Introduces AI Model for Ancient Roman Inscriptions
Researchers from tech giant Google's (GOOGL) DeepMind recently introduced Aeneas, an AI model that is designed to help historians understand and interpret ancient Roman inscriptions. These writings, which can be found on monuments, everyday objects, and even graffiti, are important for learning about Roman life, but are often incomplete or damaged. Traditionally, analyzing them required a lot of manual work. However, Aeneas solves this problem by finding similar texts, restoring missing pieces, and placing inscriptions in their historical context much faster than before. Elevate Your Investing Strategy: Take advantage of TipRanks Premium at 50% off! Unlock powerful investing tools, advanced data, and expert analyst insights to help you invest with confidence. The model was created by the University of Nottingham in partnership with the Universities of Warwick, Oxford, and the Athens University of Economics and Business. It builds on a previous tool called Ithaca, which focused on Greek inscriptions, but has been expanded to add Latin and uses a much larger database of over 176,000 examples. Interestingly, Aeneas can process both text and images, which allows it to figure out where an inscription came from and fill in gaps even when the missing length is unknown. This makes it especially useful for damaged artifacts. Notably, Aeneas has already proven to be useful in debates about famous inscriptions, such as the Res Gestae of Augustus. Instead of predicting one exact date, it provides a range of likely dates and explains the clues it used. In addition, tests with professional historians showed that the tool improved their accuracy and helped them spot connections they might not have noticed otherwise. As a result, Aeneas is being shared openly to support research and museum work, with plans to add other ancient languages and artifacts in the future. Is Google Stock a Good Buy? Turning to Wall Street, analysts have a Strong Buy consensus rating on GOOGL stock based on 27 Buys and nine Holds assigned in the past three months. Furthermore, the average GOOGL price target of $215.09 per share implies 12.5% upside potential.