Security without the memory test Cleveland to Los Angeles to the UK Recovery taught the case for prevention Security without the memory test Cleveland to Los Angeles to the UK Recovery taught the case for prevention

Profile / Cybersecurity / Cleveland

Sergey Gulyayev Is Trying to Make Security Boring

His argument is disarmingly practical: protection works best when people have fewer chances to forget it. At SecureData, that idea has traveled from recovery labs to encrypted drives, remote controls and the chief executive's desk.

The reassuring fantasy of data recovery begins with a small miracle. A laptop fails, a drive clicks, a folder vanishes, and somewhere a patient technician restores the photographs, contracts or accounts that seemed to have disappeared. Sergey Gulyayev works in the business that receives those panicked calls. His less comforting contribution is to say, plainly, that miracles have terms and conditions. “Sometimes there is no way to recover data if it has been obliterated,” he said in 2018. For an executive in the recovery trade, it was almost impolite candor. It was also the beginning of a useful philosophy: the elegant rescue matters less than arranging things so that nobody needs one.

Gulyayev is now chief executive of SecureData, the company that began as Secure Data Recovery in West Hollywood in 2007. The company lists its headquarters in Los Angeles; his own professional profile places him in Cleveland. Those two cities describe the business rather well. One is the corporate address. The other became home to a 30,000-square-foot recovery facility with an ISO-4 Class 10 cleanroom, built for work where a speck of dust can become a villain. Between them sits a company that expanded from damaged disks into digital forensics, repair software, encrypted drives, backup and managed IT.

Sergey Gulyayev in a suit and glasses during his time as SecureData COO
The earlier uniform: Gulyayev during his COO years, when the public brief was encrypted drives and fewer opportunities for error.

There is very little celebrity machinery around Gulyayev. No grand founder mythology circulates under his name. His visible record is made of company roles, a college listing, regulatory paperwork, an interview and a bylined trade essay. Even his social presence is quieter than SecureData's own accounts. This absence of theater fits the subject. Backups are rarely invited to the launch party. Encryption is appreciated most when a device is sitting in the wrong taxi. The work earns attention at precisely the moment everyone wishes it had been done yesterday.

The afterthought economy

In July 2018, when he was SecureData's chief operating officer, Gulyayev explained why small businesses postpone backups. Defensive work competes badly with revenue work. A new customer feels immediate; a backup test feels like an appointment with a hypothetical. Hardware, software and regular checks also cost time. So protection becomes, in his phrase, “an afterthought - if thought of at all.” It is hard to find a more concise description of the afterthought economy, that vast market of tasks everyone values and nobody schedules.

“Backing up is more defensive and a small business is more focused on revenue generation, so it becomes an afterthought.”Sergey Gulyayev, 2018

His telling example was not a spectacular cyberattack. It was onboarding. When a new employee arrives, the IT team makes sure the person has a computer, permissions and the applications needed to begin. Where files should be stored, whether those locations are protected, and when restoration was last tested can get lost in the shuffle. The failure begins amid competence. Everyone completes the visible job. The invisible job waits.

That observation reveals Gulyayev's preferred unit of analysis: not the heroic individual, but the ordinary process. If security needs every employee to remember every rule every time, it has been designed around optimism. People get distracted. Organizations accumulate platforms. Devices travel. The answer, in his public comments, is to move more responsibility into the product and more control into the hands of administrators.

The uncomfortable ceiling
10 tries

SecureData's keypad products were designed to erase credentials and data after ten consecutive wrong password attempts. The device, not a nervous user, enforces the limit.

A lock that does not need a lecture

The products SecureData introduced around that period made the philosophy physical. SecureDrive KP put a keypad on an encrypted external drive. SecureDrive BT used a phone application and Bluetooth for authentication. The premise was that strong encryption could arrive through gestures people already understood: enter a PIN, use a familiar device, unlock what is yours. In September 2018, the keypad model received FIPS 140-2 Level 3 validation. The federal certificate named Gulyayev as SecureData's vendor contact.

The technical details are formidable: AES encryption, authentication controls, tamper resistance and firmware versions with names suited to a filing cabinet. Gulyayev's explanation was happily unromantic. The user “really doesn't need to know how it works, it just works.” There is wit hiding in that sentence. Security companies often want customers to admire the lock. Customers would prefer to open the door, then get on with their day.

This was not an argument against sophistication. It was an argument about where sophistication belongs. It belongs inside the object, behind the interface, in validation labs and administrative controls. It should not sit on the user's desk as homework. When a drive is lost or stolen, its encryption remains. When a malicious person guesses repeatedly, the device can defend itself. With managed models, an administrator can restrict access by place or time, reset credentials or issue a remote wipe.

Recovery looks backward. Resilience looks around.

By 2021, Gulyayev had arranged the company's approach into three layers. First, keep protected backups and portable storage offline, beyond ransomware's easiest reach. Second, manage drives remotely, including where and when they can open. Third, control the USB endpoints that connect portable devices to a network. A lost drive, an infected stick and an exposed backup are different problems. Treating them as one dramatic cloud called “cybersecurity” makes for a handsome slide and a poor defense.

The sequence also reflects SecureData's unusual view from both sides of a failure. Recovery looks backward. It asks what happened to the platter, the controller, the file system or the person holding the coffee. Prevention looks around. It asks where copies live, who can reach them, which device may connect, and what happens when a password is guessed for the eleventh time. Gulyayev's career joins those questions inside one operating company.

SecureData's own timeline shows the widening circle. The first recovery lab opened in Los Angeles in 2008. The cleanroom achieved its Class 10 certification in 2009. The SecureData security-products brand arrived in 2013, backup in 2014, dozens of recovery and repair software titles by 2016, and an expanded digital-forensics offering in 2017. The encrypted-drive validation followed in 2018. The Cleveland facility arrived in 2020. Managed IT came in 2021, ransomware recovery in 2022, and UK operations in 2024.

2018
Gulyayev speaks as COO; SecureDrive KP receives FIPS 140-2 Level 3 validation.
2021
He publishes the three-part case for offline storage, remote drive control and endpoint protection.
2024
He becomes a director of Secure Data Recovery UK Ltd as the company opens in Britain.
Now
SecureData lists him as CEO, with a management brief spanning recovery, products and services.

A corporate timeline cannot establish who made every decision, and it should not be mistaken for a private diary. It does show the institution Gulyayev came to lead: a specialist recovery operation that kept adding earlier points of intervention. Each new layer moves the company a little farther from the desperate final phone call. That is commercially clever, of course. It is also a coherent answer to what the recovery bench teaches.

The promotion of an operator

The documented arc of Gulyayev's own career is simpler. He was publicly identified as COO in 2018 and again in 2021. In November 2024, British corporate records named Sergey Mikhaylovich Gulyayev an active director of Secure Data Recovery UK Ltd, alongside United Secure Data Technologies, LLC. The filing records his nationality as American and his residence as the United States. SecureData's current management page places him at the top as CEO.

The move from operations chief to chief executive makes sense without requiring a parable. SecureData's work is operations all the way down. A recovery lab must preserve chain of custody. A cleanroom must stay clean. A backup must run on schedule. An encrypted drive must refuse the wrong person with admirable consistency. Sales may promise reassurance, but processes have to deliver it.

Gulyayev's public vocabulary reflects this. He talks about plans, compatibility, testing, onboarding and controls. Even when discussing ransomware or regulation, he returns to implementation. The danger is not merely that an organization lacks a policy. It is that the policy asks a busy person to remember something at exactly the wrong moment. A fine may sharpen attention, but it does not produce an out-of-box solution. A frightening headline may inspire a meeting, but it does not test last night's backup.

“The user really doesn't need to know how it works, it just works.”Sergey Gulyayev on hardware encryption

The elegance of nothing happening

There is a peculiar modesty to prevention. Recovery can end with an emotional reunion between a person and a folder of photographs. Prevention ends with Wednesday. The payroll file opens. The lost drive remains unreadable. The backup is present and dull. No technician becomes a magician because no magician is required.

That is the quiet ambition running through Gulyayev's record. Security should survive distraction. Encryption should not demand a seminar. Backups should exist in more than one place and be protected there. Devices should carry rules with them. Administrators should retain some control after hardware has left the building. None of these ideas is theatrical. Together they remove several opportunities for regret.

The cybersecurity business is filled with apocalyptic nouns. Breach. Attack. Disaster. Gulyayev's more interesting words are verbs of maintenance: store, test, protect, restrict, recover. They are not exciting, which may be the point. The executive who knows what an obliterated drive looks like has little reason to romanticize the ending. Better to design the uneventful middle, where the system remembers what the person forgot and everybody goes home without a story.