Field Note Cyber defense is becoming an operating function for small teams Jonathan Steenland pairs machine-speed detection with human judgment His second brief: make cybersecurity careers visible before college Cyber defense is becoming an operating function for small teams Jonathan Steenland pairs machine-speed detection with human judgment

Person / Cybersecurity / Colorado Springs

Jonathan Steenland Wants Cybersecurity to Answer the Alarm

After defending a global enterprise, the ForceNow co-founder turned to a harder brief: giving small organizations an affordable security operation - and students a visible way into the profession.

At two in the morning, a cybersecurity dashboard is a rather expensive night-light. It can glow, chirp and arrange danger into tasteful little graphs. It cannot decide whether a strange login is a tired accountant in an airport lounge or the opening move of an intrusion. For that, somebody has to be awake, competent and permitted to act. Jonathan Steenland has built much of his career around that unfashionable final mile.

His route to it runs through the U.S. Army and Department of Defense, then through sixteen years at Fujitsu. He joined Fujitsu Network Communications as a security officer in 2000 and eventually became the company's first chief security officer in the Americas. For roughly six years he served as a CISO. The scale was corporate geography: a global business described as 500 companies, 170,000 employees and operations in 100 countries.

500companies in the global business
170Kemployees within the remit
100countries in the operating map

Large numbers can make a résumé look grand while concealing the actual labor. In Steenland's case, the work included building programs with names only a security committee could love: Security Resource Planning, Enterprise Security Intelligence and the Advanced Security Innovation Center. The telling detail is not the acronyms. It is that these ideas had to travel through a complex international company, collect allies, survive questions and receive resources before becoming real operations.

Steenland studied computer science at Cameron University before his long corporate chapter. His early Army and Defense Department work placed security inside a mission rather than a sales brochure. At Fujitsu, that habit translated into programs explicitly aligned with business needs. Protection had to support the company while the company kept moving. A defense that prevents useful work is only a different kind of outage.

He also spent four years as executive vice president of InfraGard's North Texas chapter, part of the FBI-sponsored network that brings public and private operators together to share information about threats to critical infrastructure. The appointment fits the architecture of his later career. Cyber risk ignores the tidy borders between one company, its suppliers, its customers and the place where they all live. The response depends on relationships built before anyone needs an urgent favor.

A colleague who watched that process described Steenland pitching and socializing the innovation-center idea until it was funded. His manager of sixteen years remembered a restless appetite for new approaches and joked that the enthusiasm could be exhausting. The compliment lands because it contains a little grit. Innovation inside a giant company is rarely a lightning bolt. It is closer to carrying a piano through several customs offices.

The smaller client

After Fujitsu came a series of roles that narrowed the distance between advice and execution. Steenland co-founded the security consultancy Zyston in 2016. In 2018 he moved to Colorado Springs to become chief operating officer of the National Cybersecurity Center, later serving as chief strategy officer. He then joined secure-document company Botdoc as chief innovation and security officer. Each stop added a different view of the same object: the institution, the advisory room, the startup and the public mission.

Pre-2000U.S. Army and Department of Defense
2000-16Fujitsu security leadership and global program building
2016-19Zyston, National Cybersecurity Center and Botdoc
2020ForceNow, co-founded with retired Rear Admiral Hank Bond

ForceNow began in 2020, at the start of the pandemic. Steenland and his co-founder, retired Rear Admiral Hank Bond, saw attacks rise as smaller organizations became more dependent on scattered devices, cloud services and improvised remote work. Their target customer was not the enterprise capable of hiring a floor of analysts. It was the business with an IT generalist, a stack of security products and nobody whose Tuesday-night duty included interpreting an alarm.

The partnership joined two careers shaped by large, consequential networks. Bond had spent nearly thirty-two years in the Navy. Steenland had moved through defense and a multinational technology company. They did not pretend a neighborhood company had Fujitsu's budget or the Navy's command structure. They asked which disciplines could survive the translation: layers of defense, continuous attention, clear authority and a practiced response when something unusual appeared.

Jonathan Steenland speaking during a Discover Mercer County Business interview
OFF THE DASHBOARD: Steenland discusses cybersecurity and the Pennsylvania Cybersecurity Center. The bright studio is considerably friendlier than a 2 a.m. incident queue.

The company's proposition is a managed security operation: layered technology, continuous monitoring and people who can investigate and respond. ForceNow compares conventional antivirus to a smoke detector. A monitored service is closer to a fire department. The analogy is useful because it restores the verb. Detection informs you that something may be burning. Response is the work that keeps a suspicious spark from becoming the quarterly report nobody wanted to write.

“If we protect those businesses, we protect our communities.”Jonathan Steenland

That line explains why the smaller customer is not merely a market segment. Local manufacturers, professional offices and family businesses hold payrolls, records and trust. They also have tighter budgets and fewer specialists. A global company can spread security costs across 170,000 employees. An eight-person provider serving a small practice must make every alert, escalation and subscription intelligible. The technical standard does not shrink. The operating model has to.

The operating loop

01Map assets, risks and gaps
02Deploy layered controls
03Watch signals continuously
04Investigate, contain, learn

This is where Steenland's enterprise years become more than biography. The reusable lesson is that security is a system of decisions, not a cupboard of tools. The point of automation is speed and coverage. The point of human oversight is context, judgment and accountability. Remove either half and the customer gets an incomplete service: a vigilant person who cannot see enough, or a tireless machine that cannot own the consequence.

One hand, then ten

Steenland's second ForceNow brief begins far from the operations center. He has described visiting high-school classrooms and asking how many students have considered a cybersecurity career. Sometimes one hand rises. After he talks about the work and the opportunities, he asks again and can see more than ten. It is a modest anecdote with an uncomfortable diagnosis: part of the talent shortage is a failure of imagination, and adults have neglected to supply the pictures.

Cybersecurity is broad enough to be forbidding. Its entry routes are poorly marked, its language is dense, and the popular image of a lone hacker in a dark room has done little for career guidance. Steenland has argued for earlier exposure, including elementary school, followed by industry-aligned credentials, college credit and work-based learning. ForceNow has worked with rural Colorado schools including Peyton and Calhan on curriculum, internships and routes toward apprenticeships.

The ambition is not limited to filling vacancies. Steenland describes cyber work as a route to well-paid employment joined to a cause that touches every organization and person using connected systems. That pairing matters in a classroom. Salary makes a path plausible; purpose makes it memorable. His membership in the professional security community stretches back at least to 2005, but his education work is aimed at reducing the amount of wandering required before a newcomer can find that community.

The romance ends where the calendar begins. In testimony supporting Colorado work-based-learning incentives, Steenland listed the practical snags employers face: Who manages the interns? How should staff be trained to work with young people? How do schedules and transport work? These are not objections to the idea. They are the bolts that keep the bridge upright. A talent pipeline made entirely of conference panels will transport no one.

“We believe it is essential for communities and business to be a part of the education model.”Jonathan Steenland

The same pattern appears in both sides of his work. A security product needs an operator who turns a signal into a decision. A classroom needs an employer who turns an abstract profession into a believable next step. In each case, the missing piece is a human handoff. Steenland's interest is not simply in explaining sophisticated systems. It is in making them traversable.

Freedom to move

More recently, his public conversations have widened to AI, blockchain and automotive cybersecurity. At Georgia Tech's Scheller College of Business, he spoke about AI's movement from automation toward autonomous agents and framed adaptability as “freedom of movement.” The phrase suits a career that has crossed military service, global enterprise, consulting, nonprofit leadership and startups without abandoning the central problem of trustworthy systems.

It also keeps AI security from becoming a purely technical argument. Steenland urged students to treat AI as a strategic partner, attend to ethical use and develop hybrid skills. In the automotive sector, he has warned that industries with uneven preparation are attractive targets. He announced a NADA fireside discussion with U.S. National Cyber Director Harry Coker on the threats facing auto businesses. The context changes; the operating question remains: can an organization adapt before circumstances make the decision for it?

There is an appealing lack of theatre in this view of cybersecurity. The useful work is repetitive: assess, deploy, watch, investigate, teach, repeat. It happens in boardrooms, classrooms and quiet operations centers. Success may look like an incident contained, an owner who understands the next decision, or eleven teenagers now able to imagine themselves in a field that had seemed sealed off.

Steenland's career began with large systems and has become increasingly interested in access. Access for a small organization to defense it could not staff alone. Access for a student to a profession whose doorway was hidden. Access for leaders to new technology without surrendering judgment to it. The work joins scale to intimacy. One side counts countries and endpoints. The other asks who, exactly, will answer when the alarm rings.