logo
Lessons From (Re)Building A Security Company From Scratch

Lessons From (Re)Building A Security Company From Scratch

Forbes21-04-2025

Christofer Hoff is the Chief Secure Technology Officer of LastPass.
getty
I've always admired the Roman architect Vitruvius, who once said that if you're going to build something, it ought to be beautiful, strong and useful. After spending the past two and a half years building the software and platform engineering teams, as well as a new security organization, at LastPass, I've come to truly understand how right he was.
I joined LastPass in 2022 as its chief secure technology officer (CSTO)—combining security and technology into one role—an opportunity I couldn't resist.
The business was taking the first of many steps to spin out from its parent company and form a stand-alone company. A whole new executive team of industry veterans was at the helm, setting out to deliver on the promise of tackling the decades-long, ever-complex challenge of passwords—making them more secure and more convenient for people and organizations.
This was my opportunity to integrate security by design, not just into the company's operations but throughout the entire product development life cycle. I would work alongside the leaders we had assembled to build something beautiful, strong and useful from the ground up.
Three months after I joined LastPass, the company was the target of a sequenced set of two security attacks that spanned multiple months and threatened to derail everything we were working toward. But in the end, it didn't. In fact, the security incident acted as an accelerant for the people, process, technology, controls and infrastructure initiatives we already had planned to build while establishing a new company from scratch.
In reflecting on this experience, I hope to offer something relatable in its honesty, strong in its lessons and useful to anyone tasked with rebuilding—not just systems, but trust. Here is how you can do it.
From day one, I knew that security couldn't be a checklist—it had to be a blueprint. If you want to drive innovation while keeping trust intact, security, privacy and engineering must be tightly coupled.
It's important to consciously embed security into every phase of decision-making and build the right teams around it—architecture, threat intel, governance, detection and response. We did it intentionally and with buy-in from across the company, leveraging the outcomes of decades of experience to understand where security can be a differentiator and become a business-enabler.
As an example, and something unique among password manager providers, we built a dedicated threat intelligence team. With backgrounds in counterterrorism and financial services, this team monitors threats, delivers actionable insights and automates threat response to help protect our customers, data and company. It's not just a line of defense—it's a proactive, strategic asset that keeps us a step ahead. That's what it means to design with security at the core.
Security and engineering won't click together on their own. You need to define how they'll collaborate—and then back it up with process, structure and, most importantly, the right people. We hired brilliant engineers from world-class companies and combined them with our existing team. The mix gave us a rare advantage: experience, new ways of working and belief in the mission.
Hiring great people is step one. Step two is giving them the space, clarity and support to do their best work—especially under pressure. As a leader, your job is to make sure they know you trust them and to give them the resources they need to succeed.
We built an entirely new development infrastructure in months because the team believed they could. And they were right. Transparency was our prerogative, and that's why we documented how we made LastPass secure. We have a trust center where we reflect, and we've also created a publicly available compliance center for close to real-time monitoring of LastPass systems and access to the latest certifications.
We didn't just rebuild the platform; we reimagined it through the lens of the customer's experience. What did users need? Where were the friction points? What would make them feel safe, confident and in control?
That's what drives decisions—from introducing stronger password recovery options and implementing secure sharing to strengthening master password protections and encrypting sensitive data fields. Through hackathons, we've started to integrate new features and functions like AI into our platforms.
Under pressure, perfection is a luxury. Progress is a necessity. There were days when we moved fast because we had no other choice. But every sprint, every decision, every hard call got us closer. You need to be flexible, decisive and focused on what matters most—especially when time and attention are scarce resources.
I'll never forget the conversations I had with dozens of CISOs from our customer base—internalizing their concerns and their wishes for the new LastPass. The first time a CISO asked me, 'How are you doing?', I was moved to tears. Imagine possessing such empathy and grace.
This—the security and experience of the people behind our product—was our raison d'être, fueling us through every 20-hour workday. So here is my advice: Talk to your customers. Listen. Internalize what they're worried about. Let it shape your work. Then build something worthy of their trust.
That's what we did. We started with a mission, built a blueprint for success and responded to adversity with momentum through our people, empowered and enabled by the support of our leadership. We've seized a once-in-a-lifetime opportunity. We have built something beautiful, strong and useful—and so can you.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

The Dreadful Policies Halting Archeological Discoveries
The Dreadful Policies Halting Archeological Discoveries

Yahoo

time15 hours ago

  • Yahoo

The Dreadful Policies Halting Archeological Discoveries

Thanks to the creative application of new technologies, the 2020s are quietly shaping up to be a golden age of archaeology. In 2023, then-21-year-old Luke Farritor (now with the Department of Government Efficiency) combined machine‑learning pattern recognition with high‑resolution CT scans to decipher the first word from the Herculaneum scrolls—a Roman library charred by Mount Vesuvius in 79 A.D. Fully decrypting the library could ultimately double the surviving corpus of Ancient Greek and Roman literature—an unprecedented bonanza for classical scholarship. Analysis of ancient DNA has resolved long-debated questions about human migrations. After sequencing hundreds of Bronze Age human genomes, David Reich's research team at Harvard positively identified southwest Russia as the geographical origin of the Indo-European languages, while other genomic work has dated Homo sapiens-Neanderthal interbreeding to 47,000 years ago, several millennia prior to earlier best guesses. Fossilized human footprints in White Sands, New Mexico, have been conclusively dated to about 23,000 years ago—proof that people were in North America during the last Ice Age and forcing scholars to rethink when and how humans first crossed into the New World. Lidar has recently revealed massive ancient cities under jungle canopies, from the Mayan platform of Aguada Fénix in Mexico—larger than the Great Pyramid of Giza—to mysterious urban centers in the ancient Amazon. These developments—whether driven by artificial intelligence, the decryption of ancient genomics, or airborne lasers—promise to momentously expand society's understanding of humanity's past. Notably absent from this bounty, however, are the fruits of traditional, physical, Indiana Jones-style archaeology. The world of bits, as has often been the case these days, is leaving the world of atoms in the dust. While the storied bits over atoms problem is a complicated one, legal mechanisms are straightforwardly to blame for throttling archeological discovery. The case of Italian antiquities policy is paradigmatic. Since the 1930s, Italy—along with Greece, Turkey, and Egypt—has vested ownership of all antiquities in the state. Commerce in freshly unearthed artifacts is outlawed, and unauthorized excavation is punishable by hefty fines and sometimes prison time. Even using a metal detector requires a permit. Edward Luttwak, a historian and author of The Grand Strategy of the Roman Empire, explains that in Italy, "if you find something, you report it to the authorities. The authorities take it, goodbye. Most often, what they take from you, they put in a depot, a basement, a warehouse, and it never even gets shown." This is the unfortunate lot of the fortunate discoverer of an Italian artifact. Report a Roman coin? It'll be confiscated. Find an Etruscan urn while planting olives? Your land will be turned into an archaeological site the government may never have time to excavate. It's unsurprising, then, that Italians frequently don't report their findings to the government. Many artifacts end up on the black market (in 2023, Italy's Carabinieri Art Squad seized nearly 70,000 illegally excavated artifacts), or are even simply destroyed or hidden away. Private hoarding is an especially pernicious problem: When "illegally excavated" (read: most) Italian artifacts are privately held in people's houses, they are lost both to scholarship and public view. "You could fill twice the museums that exist in Italy from what people have hidden in their houses," says Luttwak, "which they wouldn't hide if you could report [them] to the authorities like they do in England." The British model provides a striking contrast. Since the 1996 Treasure Act, British law has required that significant archaeological finds be reported. Instead of simply seizing them, if the state wishes to retain an item, it must compensate the finder and landowner at its full market value. To capture the far larger universe of objects that fall outside the law's narrow legal definition of "treasure," the state-sponsored Portable Antiquities Scheme (PAS) established a voluntary nationwide program through which average Britons can log any find, whether or not the state intends to acquire it, into an open scientific database. As of 2020, over 1 million objects have been logged in PAS. According to Michael Lewis, head of Portable Antiquities and Treasure at the British Museum, over 90 percent of PAS-recorded items are found by metal detectorists on cultivated land, indicating how the scheme has turned what was once seen as a threat into a fountainhead of archaeological data. Thanks to these policies, Britain has been increasingly outpacing Italy in Roman archaeology despite its relatively modest classical history, as seen in this viral map of the provenance of hoards of Roman coins. Notice the sheer quantity of Roman coin discoveries reported in the U.K., far surpassing those in Italy. This disparity isn't explained by Roman Britain being richer than Roman Italy (quite the opposite), but by modern Britain recognizing and leveraging incentives to bring history out of occultation. The Great Stagnation of physical archaeology is a choice. The failure of policymakers to get the basics right—to make physical archaeology worth anyone's time—renders the richest landscapes fallow. Luttwak's attention is on one such landscape: the confluence of the Busento and Crati rivers on the edge of Cosenza, Calabria. Contemporary accounts record that in 410 A.D. the Visigoth chieftain Alaric—fresh from sacking Rome—was buried beneath the temporarily diverted river along with the treasures of the Eternal City. "Alaric's treasure is located in the southern part of the city of Cosenza," says Luttwak. "It was documented by an eyewitness." Alaric took "gold and silver objects…statues, and all kinds of things—possibly even the Temple menorah….When Alaric died in Cosenza, he got as the king one third of the treasure [to be] buried with him." "It could be found," explains Luttwak, "with hovering metal detectors, because he was buried with his weapons, too." Alaric's hoard—and maybe Judaism's most iconic physical symbol—should be discoverable today with an aerial anomaly survey and some clever hydraulics. The technology is ready; the incentives are not. Change the rules, and the payoff could be extraordinary. The post The Dreadful Policies Halting Archeological Discoveries appeared first on

The Rome EDITION hotel in Italy secures €96m refinancing
The Rome EDITION hotel in Italy secures €96m refinancing

Yahoo

time2 days ago

  • Yahoo

The Rome EDITION hotel in Italy secures €96m refinancing

Hospitality-focused real estate investment firm Global Hospitality Investment Group (GHIG) has concluded the issuance of €96m ($109.26m) in senior secured notes for the refinancing of The Rome EDITION, a recently opened luxury hotel in the heart of Rome, Italy. Structured with a London-based credit-focused hedge fund, this deal provides long-term financial stability for the property, which launched in summer 2023. The financing enables Gruppo Statuto, the owner of The Rome EDITION, to refinance its current development loan. This strategic move is set to optimise the hotel's operations and increase its value on the market. GHIG vice president Sebastien Gottraux said: "This transaction marks GHIG's first deal in Italy after many years of exploring the market for the right opportunity. 'We are delighted to be involved with a landmark asset like The Rome EDITION and are eager to remain active in the Italian market, pursuing both acquisition and financing opportunities." Designed by hotelier Ian Schrager, The Rome EDITION offers 93 guest rooms and suites, which include 19 expansive suites. The property features a range of amenities, encompassing an Italian restaurant Anima, offering both indoor and outdoor dining; a speakeasy-style bar Punch Room, marble-made Jade Bar, a rooftop bar The Roof, complete with a swimming pool. Guests at the hotel have access to a 24-hour gym with treatment rooms. Its location places guests within walking distance of Roman attractions including Piazza Barberini, Via Veneto, the Spanish Steps, the Trevi Fountain, and the Borghese Gardens. Three Stars Capital Partners, under the leadership of Mauro Savoia, advised Gruppo Statuto on the transaction. GHIG Europe managing director and head James Gibbs said: "We are pleased to support Gruppo Statuto with the refinancing of The Rome EDITION. This flexible financing solution is designed to ensure the continued success of such a trophy property in one of Europe's leading leisure markets. 'Our team leveraged its operational expertise and deep understanding of the local market to thoroughly assess the hotel's robust business plan, enabling us to provide a highly compelling and tailored structure for the borrower." "The Rome EDITION hotel in Italy secures €96m refinancing" was originally created and published by Hotel Management Network, a GlobalData owned brand. The information on this site has been included in good faith for general informational purposes only. It is not intended to amount to advice on which you should rely, and we give no representation, warranty or guarantee, whether express or implied as to its accuracy or completeness. You must obtain professional or specialist advice before taking, or refraining from, any action on the basis of the content on our site. Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data

Rhône Valley's Côtes du Rhône and Côtes du Rhône Villages AOCs Increase Focus on Wine Tourism
Rhône Valley's Côtes du Rhône and Côtes du Rhône Villages AOCs Increase Focus on Wine Tourism

Yahoo

time3 days ago

  • Yahoo

Rhône Valley's Côtes du Rhône and Côtes du Rhône Villages AOCs Increase Focus on Wine Tourism

The vibrant spirit and unique experiences put the region in a prime position to draw in visitors, both domestic and international, even further NEW YORK, June 4, 2025 /PRNewswire/ -- Inter Rhône, the organization that represents the Rhône Valley Vineyards AOCs, is happy to share that the Côtes du Rhône and Côtes du Rhône Villages AOCs, two significant appellations of the Rhône Valley, are concentrating on new and exciting wine tourism events and activities for consumers to explore this historic, dynamic part of the region. According to the French Ministry of Tourism, France is the world's leading tourist destination. The past few years have seen continued growth, with 2023 and 2024 seeing a record number of over 100 million visitors. The global wine tourism market is also expected to see continued growth over the next 10 years. The Côtes du Rhône, then, is poised to welcome visitors to this one-of-a-kind region: Imagine sipping wine under the sun, surrounded by medieval villages and rolling vineyards - the Côtes du Rhône is the ultimate getaway for adventure seekers, families, foodies, and culture lovers alike. Cultural and Historical WondersThe Côtes du Rhône is rich in history, with four UNESCO World Heritage sites, from the majestic Palais des Papes in Avignon, a 14th-century Gothic palace that once served as the residence of popes, to the Pont du Gard, an ancient Roman aqueduct that stands as a marvel of engineering. Stepping back even further, the Grotte Chauvet 2 cave in Ardèche, an accurate replica of the original Chauvet Caves, showcases prehistoric art that is over 30,000 years old. The stunning wine-producing villages of Séguret, Aiguèze, and La Roque-sur-Cèze truly capture the heart of the Côtes du Rhône with their beautiful scenery. Sip, Savor, RepeatFor epicures, the Côtes du Rhône is home to a wide range of wines, from expressive reds and crisp whites to delicate rosés, paired with local delights like black truffles, creamy goat cheese, and Nyons olives for the ultimate tasting experience. Gastronomic experiences abound in the Côtes du Rhône, including chic bistros and picnics in the vineyards. Festivals, Music, and Good VibesThe Côtes du Rhône is known for its exciting fêtes, from lively music festivals to gourmet food events. Whether tasting through a wine festival or experiencing a traditional celebration, there is always a reason to raise a glass! Nature, but Make It FunFor visitors looking for outdoor adventures, the Côtes du Rhône is full of activities, from cycling through the vineyards on the scenic EuroVelo 17 (aka 'Via Rhôna'), hiking through breathtaking landscapes, to taking a guided wine walk. Sustainability is key here, and the region is dedicated to preserving its natural beauty. Wine Tourism: A New EraWineries here are leaning into consumer interests - moving away from stuffy tastings and shaking things up with even more hands-on experiences, such as blending workshops, themed tastings, sensory tastings, massages in the vineyards, and overnight vineyard stays. The Côtes du Rhône region is appealing to those who are wine newbies, as well as to seasoned connoisseurs, with a wide range of unique experiences and something for everyone. Tourists interested in planning an unforgettable trip to the Côtes du Rhône can for insider tips and must-visit spots. About Côtes du Rhône and Côtes du Rhône Villages AOCsCôtes du Rhône and Côtes du Rhône Villages AOCs are two significant appellations within the Rhône Valley wine region of France, renowned for their diverse and high-quality wines. Côtes du Rhône AOC (Appellation d'Origine Contrôlée) is one of the largest and most renowned appellations in France, covering vast vineyard areas along the Rhône River. It encompasses both the Northern and Southern Rhône regions, allowing for a wide range of grape varieties and wine styles. Produced in 172 communes on rich and varied terroirs, regional Côtes du Rhône is notable for its diversity, its character and a blend that guarantees a quality wine. Côtes du Rhône Villages AOC represents a step up in quality and specificity within the Côtes du Rhône appellation. This designation is reserved for wines that meet stricter production standards and come from specific communes or villages within the Rhône Valley. The regulations limit yields and dictate stricter guidelines for grape growing and winemaking practices, ensuring higher quality standards. Within the Côtes du Rhône Villages AOC, there are also specific villages entitled to append their name to the label, denoting even higher quality standards. There are 21 such villages, each recognized for their unique terroir and historical winemaking traditions. For more information, please visit and for photos, please visit Press Contacts:Erin HealyColangelo & Partnersehealy@ Béatrice MialonInter Rhônebmialon@inter-rhô View original content to download multimedia: SOURCE Inter Rhône Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store