IT Tech Pulse Exclusive Interview with Feras Tappuni Chief Executive Officer and Founder of SecurityHQ

Stay updated with us

Feras Tappuni CEO and founder of SecurityHQ
🕧 16 min

Feras Tappuni, Founder and CEO of SecurityHQ, discusses how security performance, AI-driven SecOps, and human expertise are shaping modern cybersecurity.


SecurityHQ just appointed Martin Trower as CFO to support global scaling. What stage is the business at right now that made bringing in dedicated finance leadership the right move, and what does the next phase of growth look like?

SecurityHQ is at a stage where the opportunity is clear, and now the job is to scale it properly.

We have been in this market for more than 20 years, and we have a strong foundation: a global footprint, long-standing customer relationships, deep experience in security operations, and a clear view of where the market is headed. But as you grow globally, ambition is not enough. You need structure, discipline, and the right leadership around the business so you can keep moving without losing what made you successful in the first place.

That is why dedicated finance leadership matters now. It gives us the planning, reporting, controls, and operational focus we need to keep investing in the right markets, people, and capabilities.

The next phase for SecurityHQ is disciplined growth. We want to expand, but not at the expense of the customer experience. The focus remains the same: helping organizations improve their security operations’ performance in the real world.

You’ve described SecurityHQ’s approach as “Security Performance Engineering” focused on visibility, accountability, and measurable outcomes. How does that differ from how a traditional MSSP or SOC measures success, and why does it matter to a CISO?

Many traditional security providers measure activity. They can tell you how many alerts were reviewed, how many tickets were closed, how many tools are deployed, or whether an SLA was met. Those things are useful, but they do not necessarily tell you whether your security is actually improving.

That is the difference with Security Performance Engineering. The focus is not just monitoring an environment. It is continuously improving the environment’s security performance.

For a CISO, that matters because boardroom conversations have changed. Boards used to ask, “Are we covered?” Now they are asking, “Are we getting better?” Are we reducing noise? Are we making better decisions? Are we responding faster? Are we reducing the exposures that could actually hurt the business?

That is a very different conversation from simply saying, “Yes, someone is watching the alerts.”

You founded the company around two decades ago and now run six Security Operations Centers globally. As you expand into new regions, what’s the hardest part of scaling a 24/7 SOC operation without diluting service quality?

The hardest part is preserving context.

A 24/7 SOC cannot feel like a call center where every shift starts from zero. If something serious happens, the customer does not want to explain their environment from the beginning to someone who has never seen it before. They want someone who already understands their systems, their priorities, and what really matters if things go wrong.

That is why our designated service model is so important. We think of it as continuity of care. Customers work with the same team, so knowledge builds over time. The relationship strengthens, the understanding of the environment sharpens, and when pressure arises, the customer knows who is on the other end of the phone.

The value of six Security Operations Centers lies not just in having people in different locations. We can take intelligence, experience, and lessons learned from across the world and apply them back into each customer environment.

Also Read: IT Tech Pulse Exclusive Interview with Michael Cucchi Chief Product and Marketing Officer at Hydrolix

You’ve said the cyber skills shortage is the single most pressing challenge your clients face. How is that shortage evolving in 2026, and how is SecurityHQ solving it differently from in-house teams?

The skills shortage is not just about finding enough people anymore. It is about having the right judgment available at the right moment.

Security teams are already stretched. They are dealing with more tools, more alerts, more compliance pressure, more cloud complexity, and more demands from the board. Now add AI-automated attacks into the mix, and the problem becomes much harder. There are fewer skilled people than the market needs, and the attacks are becoming faster, more automated, and more convincing.

That is a difficult combination for any internal team to carry alone.

Where SecurityHQ helps is by giving customers a security partner, not another black box. We bring experienced analysts, automation, threat intelligence, and a team that builds real knowledge of the customer’s environment over time. The goal is not to replace the internal team. It is to stand alongside them, give them more capacity, and help them make better decisions when the pressure is on.

SecurityHQ runs over 2,000 automation playbooks and you’ve talked about “combating AI engines with our own AI engines.” Where is AI genuinely improving threat detection and response today, and where is the hype outrunning reality?

AI is absolutely improving security operations when it is used in the right way.

It helps analysts move faster. It can triage alerts, remove noise, enrich incidents, correlate signals, and turn scattered data into a clearer picture of what is happening. That matters because in security, time really does matter. The faster you can understand what is real, what is important, and what needs action, the better your response will be.

Where the hype outruns reality is the idea that AI removes the need for human judgment. It doesn’t.

Detection is only half the problem. Once something is detected, someone still has to understand the customer’s environment, assess the potential business impact, and decide what to do next. That decision cannot just disappear into a black box.

Our view is AI-enabled, but human-led. AI should make analysts faster and better informed. It should help them see clearly. But accountability still has to sit with experienced people who know what they are doing.

Also Read: IT Tech Pulse Exclusive Interview with Ken Claffey Chief Executive Officer and President of VDURA

With threat actors ranging from state-funded groups to organized crime, what categories of attack are you seeing escalate fastest right now and what should enterprises be doing about them this year?

We are seeing growth across identity-led attacks, credential abuse, phishing, social engineering, ransomware, supply chain risk, cloud misconfiguration, and AI-enabled deception.

Attackers have better tools now. AI lets them move faster, scale more easily, and make attacks more convincing. But the fundamentals of defense have not changed as much as people think.

Enterprises need to know their own environment. They need to know where their crown jewels are, where they are exposed, which vulnerabilities actually matter, and what they will do when something goes wrong.

Too many organizations invest heavily in detection but do not spend enough time on response. The worst time to decide who owns the decision, what gets shut down, whether legal needs to be involved, or whether regulators need to be notified is during the incident itself. By then, people are under pressure, information is incomplete, and everyone wants an answer immediately.

That work has to happen before the crisis.

You’ve spoken about ending “heroic leadership” and building cohesive teams as the foundation of a SOC that lasts. How does that leadership philosophy shape how you hire, retain, and scale your global security analysts?

  • Hero culture doesn’t scale.

In a real incident, pressure comes from every direction. The board wants answers. Legal wants information. Customers are worried. The technical team is still trying to understand what actually happened. In that moment, you cannot rely on one person to save the day.

You need calm teams, clear processes, and people who know their role before the crisis starts.

That shapes how we hire and how we build the culture. Technical ability matters, of course. But we also look for people who are disciplined, curious, collaborative, and calm under pressure. Security is a team sport. The analyst who listens well, shares context, asks the right question, and keeps their head during a difficult moment is incredibly valuable.

We are building a culture that is mission-aligned, team-first, and customer-first. The goal is to make good judgment repeatable across the organization, not dependent on one heroic individual.

Thank you, Feras Tappuni, for taking the time to share your insights with us.

Write to us [wasim.a@demandmediaagency.com] to learn more about our exclusive editorial packages and programmes.

About Feras Tappuni About SecurityHQ

Feras Tappuni is the CEO and founder of SecurityHQ and is responsible for overseeing all the technical and financial aspects of the company. With over 25 years’ experience, he has dedicated his life to cybersecurity and is driven by the desire to offer his clients the highest degree of protection against today’s cyber threats. Feras has delivered complex security and engineering projects to prestigious clients globally. From harnessing the right technology, processes and people, he ensures that SecurityHQ delivers a truly enterprise-grade experience.

SecurityHQ is a global cybersecurity company that helps organizations engineer, measure, and continuously improve the performance of their security operations. Founded in 2003, the company delivers flexible and technology-agnostic solutions through its Security Performance Engineering approach. Built around each customer’s environment, the approach brings together managed detection and response, threat and adversary intelligence, exposure management, and advisory services. With 400+ analysts and engineers across six global SecOps Centers, SecurityHQ provides 24/7 human-led detection, response, and continuous improvement. Its work is focused on reducing noise, improving decision-making, and strengthening security performance over time.

  • Wasim Attar manages pulse networks editorial, delivering the latest insights and trends. As a PR professional, he drives brand visibility through guest posting, exclusive interviews, and impactful campaigns. Passionate about innovation and storytelling, he positions pulse network as a trusted platform shaping conversations in the digital technology space