ScotlandIS Member Spotlight: Wagar Enterprises
In this Member Spotlight we hear from new Startup member, Wagar Enterprises, about the need for stronger regional technology networks across Scotland, and on joining ScotlandIS to become more connected with the tech and cyber security community, particularly in the north of Scotland.
Who is Wagar Enterprises and what do you do?
My name is Drew Wagar. I am a CISM-certified Fractional CISO and cyber security adviser, with senior leadership experience including serving as CISO at Lloyd’s of London.
I help organisations understand cyber risk, strengthen governance and resilience, and turn complex security issues into practical, proportionate action.
I work with boards, executives and technical teams, either directly or alongside consultancies and managed service providers.
Tell us something unique or interesting about your organisation.
I’ve been fascinated by technology from a very early age. I learnt to program on a ZX Spectrum in the early 1980s, and my career has since spanned text-based terminals, client-server computing, and the rise of the internet in the 1990s and beyond.
I worked for Sun Microsystems, whose former Linlithgow facility is now home to ScotlandIS—a lovely piece of nostalgia and a pleasing way to circle back into the Scottish technology community.
What is your biggest achievement as an organisation?
I am particularly proud of a role I held during the COVID-19 crisis. I joined an organisation with limited cyber security capability and little awareness of the risks this created. At the same time, we had to support the rapid introduction of home working, despite the organisation having made little prior provision for it.
The work was frantic, exhausting and hugely challenging, but ultimately very rewarding. We significantly improved the organisation’s cyber security maturity, enabled the transition to remote working and established a more sustainable security function. As the crisis began to ease, I was able to recruit and develop a full-time CISO to take the work forward.
What prompted you to become a member of ScotlandIS?
I joined ScotlandIS to become more connected with the Scottish technology and cyber security community, particularly here in the north of Scotland.
I am keen to collaborate with organisations that may benefit from additional senior cyber leadership, independent assurance or client-facing CISO support. I also want to contribute more widely through mentoring, education, training and engagement with universities, schools and people entering the profession.
What do you see as the main challenges for the tech industry in the UK and Scotland?
One of the biggest challenges is ensuring that people entering the industry are equipped not only with academic knowledge, but also with the practical, interpersonal and commercial skills needed in the workplace. Universities provide an important foundation, but mentoring, placements and meaningful engagement with experienced professionals are essential if we are to close the skills gap.
Scotland also has a particular geographical challenge. Much of the technology sector is concentrated around the Central Belt, while there is a great deal of talent and potential across the Highlands, islands and north-east Scotland. Remote working has helped to open up opportunities, but we still need stronger regional networks, better access to mentoring and training, and more ways for people outside the major cities to participate fully in the sector.
At the same time, we must not lose the value of face-to-face communication, collaboration and informal learning. This is especially important for students and people at the beginning of their careers, who often learn as much from being around experienced colleagues as they do from formal training.
AI presents both tremendous opportunities and significant risks. Organisations need to understand how to use it responsibly while managing issues such as data protection, intellectual property, misinformation and increasingly sophisticated cyber threats.
Alongside all of this, the industry must continue doing the less glamorous work well: maintaining systems, patching vulnerabilities, managing identities, training staff and sustaining good cyber hygiene. Emerging threats attract attention, but many serious incidents still result from neglecting the fundamentals.
Get in touch if you’d like to find out more at cism@wagar.org.uk or visit www.wagar.org.uk