Cobham Satcom builds the satellite and radio systems that military, government and maritime operators depend on. Lemuel Valdez, its Chief Information Security Officer, explains how CSIS helps the company hold its own operations to the standard its products promise — protecting the factory floor as well as the corporate network, and rehearsing its incident response before it is needed.
Two problems set Cobham Satcom’s requirements for a security partner.
The first was regulatory. Selling into defence, government and maritime markets means complying across a range of regimes at once — "the regulatory landscape, where we needed to comply and ensure compliance across a lot of different regulations."
The second was visibility. That meant being able to spot any unusual activity across its systems — both the production systems on the factory floor and the corporate IT that runs the company — rather than learning about a threat only once it had spread. He needed to ensure "we have visibility in place across all of our operations and business."
Lemuel gives two reasons for choosing CSIS.
The first was the quality of attention. He wanted a security monitoring provider that treated Cobham Satcom as more than an account number — something "more personalised."
The second was scope. CSIS "did not just provide security monitoring," but added insight into the threat landscape and services relevant to this specific business: a manufacturer of communications hardware for high-stakes environments.
"What is really important for us is developing products that are developed securely, safely, with trust and resilience in mind," Lemuel says.
Cobham Satcom manufactures satellite antennas at sites in Kgs. Lyngby and Aalborg in Denmark, with operations reaching California, Singapore and Shanghai — so what needs protecting spans production systems and corporate IT, across three continents.
Lemuel puts it plainly: "What is important is to protect our operational technology, but also ensuring that we have resilience in place where it needs to be."
So the work goes beyond monitoring. Protecting operational technology takes preparation, not just detection — Cobham Satcom now uses CSIS to develop resilience exercises and incident response exercises, rehearsing the response before it is needed, rather than discovering the gaps during an incident.
The personal attention Lemuel wanted at the outset has continued. He describes ongoing "interaction and relationships with the right and relevant stakeholders" at CSIS. That means continuity of contact with people who know the account, and access to the right specialist when the question demands it.
That counts for more as the threat landscape changes. "Especially with the introduction of AI," as Lemuel puts it.
He has extensive hands-on experience with AI-driven security tooling, naming Darktrace, a CSIS technology partner, and Vectra AI among them. What CSIS adds is not another model. It is "a sounding board," something that "enables me to think of things a little bit more differently to what I'm used to."
That matters as AI reshapes both attack and defence. Tooling scales detection. Judgement decides which detections deserve attention, and what to do about them.
What Lemuel values, finally, is "having a partner that doesn't restrict us, but also collaborates and gives us ideas on how we should develop and how we should orientate."
Sign up for our newsletter and get the latest cybersecurity analysis, reports and events from CSIS delivered straight to your inbox.
CSIS Security Group A/S is a leading European pure-play provider of tech-enabled cybersecurity and intelligence services. Operating 24/7, we deliver Managed Detection & Response, Incident Response, Security Consulting across all sectors, and provide a world-class threat intelligence capability through our SecAlliance brand. Accredited by organisations including CREST, we actively support global security initiatives to positively impact the cyber community.