Inside the episode: What I learned from speaking with Jonny Mattey
In my chat with Jonathan (Jonny) Mattey, the recently appointed Chief Information Security Officer at Forge Holiday Group, we dove deep into what it really means to step up into enterprise leadership. Forge Holiday Group is a fascinating organisation, championing UK staycations through major, highly recognisable brands like Sykes Cottages and Forest Holidays, managing over 25,000 properties across the UK and New Zealand. Jonny has spent the last three years shaping their security posture, and his transition from Head of Cyber Security to CISO offers brilliant takeaways for anyone navigating the path from technical management to business executive.
More than just a title bump
When an organisation creates its first CISO role, there is always a danger that it is treated as a simple title upgrade but Jonny’s experience shows that a true directorship demands a fundamental shift in scope. He candidly admitted to me that when he took the role, he “naively was of the opinion that it was largely conducting the requirements of CISO already anyway”. The reality of the step change quickly caught up.
Along with the new title, Jonny inherited completely new functional units: data protection and enterprise risk management. As he explained, he now “looks after risk for the enterprise, rather than just trying to navigate integrating cyber risk to the broader capability”. That is a fantastic position to be in, but it represents an entirely different level of leadership.
This transition highlights a common trap for rising security leaders. We often think we are ready for the top job because we understand the technical security risks inside out. However, looking after risk for the entire enterprise forces you to lift your head above the tech and look at how risk ripples across the whole commercial operation. Reflecting on what he would tell his past self nine months ago, Jonny’s advice was stark: “you’re gonna be ready to be very ruthless with your prioritisation” and “don’t underestimate the workload”.
The tangibility of the digital shopfront
One of the most compelling parts of Jonny’s journey is his professional background. His first cyber security leadership position was running security operations for an oil refinery in the Northwest. Moving from heavy industry to travel and hospitality might seem like an extreme leap, but the underlying principles remain surprisingly consistent.
In oil and gas, the security focus is heavily weighted toward business-to-business relationships, integrity, availability, and physical safety. In travel, it shifts dramatically toward the consumer side - focusing heavily on data protection and confidentiality. Yet, Jonny pointed out that the pressure around availability is just as intense in the staycation business, even if the consequences are commercial rather than physical.
For an e-commerce hospitality brand, the website is everything. It is the shop front. As we discussed during our chat, a major outage is like turning the sign around and putting the “closed” one up at 3 in the afternoon rather than being open until later in the day. Framing cyber security around business disruption gives it immediate tangibility. When you can tell the executive team that a security failure doesn’t just mean an obscure technical alert, but effectively locking the front door of the business during peak hours, the conversation about risk becomes incredibly palatable, repeatable, and understandable for the executive team.
The psychological power of a seating plan
When Jonny first arrived at Forge Holiday Group, the cyber security function was a relatively greenfield environment. The business had invested in technology and hired a couple of analysts, but the team sat at the very end of the row of the IT operations team. One of Jonny’s first moves was changing the seating chart.
“One of the first things I did was move where we sat,” he told me. It sounds like a minor detail, but the psychological impact of physically separating cyber security from IT operations was massive. It sent a clear signal to the rest of the business that security was its own independent unit, not just an IT bolt-on. Crucially, it helped reduce the friction caused by the natural conflict between IT operational goals and cyber security priorities, preventing the analysts from feeling overruled.
While they maintained an excellent working relationship with IT operations, the move physically exposed the security team to other critical functions. It meant they improved the relationship with data protection and the legal team, exposing themselves to a completely different area of the business. Independence is as much about perception and daily visibility as it is about formal reporting lines.
Defining outcomes to prove value
Because cyber security is invisible when it is done well, security leaders constantly struggle to demonstrate value. Jonny and I talked about the critical framework of inputs, outputs, and outcomes. If a security team fails to define the ultimate outcomes they are driving toward, the business naturally defaults to focusing on inputs - how much money you are spending or how many alerts you are triaging.
To break this cycle, Jonny built an operating model focused on measurable outputs that directly link to business outcomes. Internally, his team tracks operational efficiency metrics like maintaining a sub-one-hour Mean Time to Triage. While these are useful for the security operations team and the CTO, Jonny doesn’t push these technical metrics up to the board. Instead, his team focuses on tracking true positive rates to ensure they are detecting the right threats.
The goal is to create a flywheel of buy-in: you define the big goal - such as experiencing no significant cyber security incidents - establish the metrics that give the team clarity on how to get there, and then use that consistent performance to demonstrate value back to the business. “If you aren’t effectively measuring outputs and performance… then there’s going to be questions asked and the business are going to question the value of cyber security because it’s inherently invisible,” Jonny warned.
Navigating the executive split
We wrapped up our conversation by touching on a nuance that many security professionals miss: the distinction between the board and the executive committee. In many conversations, “the board” is used as a catch-all term for senior leadership. But in reality, presenting to the day-to-day executive management team requires a very different approach than presenting to the full board, which includes non-executive directors who are there purely for governance, advice, and checks and balances.
Jonny’s journey over the last few years is a masterclass in how to build a mature, respected cyber security function from scratch. By focusing on physical visibility, commercial tangibility, and rigorous output modelling, he has turned security from a mysterious technical bolt-on into a core pillar of enterprise risk management. It is exactly the kind of strategic maturity we need to see more of across our industry.
