Mark Hendry
Partner, Ashurst Perkins Coie

Mark Hendry is a Partner in Ashurst Perkins Coie’s Risk Advisory practice with almost 20 years’ experience in cyber security, digital risk, operational resilience and regulatory compliance. Before joining the firm, Mark was Equity Partner and Head of Digital Services at S&W, having previously held senior leadership positions at DWF, Deloitte and PwC. He advises organisations on cyber security strategy, incident response, governance, risk and compliance, technology transformation and digital regulation. Mark is recognised for helping clients navigate complex risk environments, build resilient operating models and implement technology-enabled solutions that support business growth, compliance and operational effectiveness.

Recently, in an exclusive interview with CIO Magazine, Mark shared insights into how his career in risk leadership began with a pivotal transformation review that showed him the power of resilience to turn around failing strategy. On AI, Mark notes enterprises often don’t know what AI is doing on their behalf yet remain accountable, making governance and evidence-based trust the biggest challenge ahead. His advice to future leaders is to stay curious, stay authentic, master the basics, take ownership, and build resilience one day at a time. The following excerpts are taken from the interview.

Hi Mark. You’ve held senior in-house roles as CISO, Head of Technology Risk & Audit, and Head of Enterprise Resilience. What was the first moment you realized risk leadership was where you wanted to build your career?

Around 2010-11, I was tasked with leading a review into a series of strategic changes at a global company. It became apparent that the intent behind the strategy was good, and the choices made were defensible as they fit the organisation’s established ways of working. But the strategic intent was to break those old ways of working and reshape the business for the digital age. So the initiatives were failing, costing huge sums of money and causing significant disruption, and actually taking the company further from where it wanted to go.

That fascinated me. How could such intelligent, well-intentioned, hard-working people collectively mis-steer a household name, and where would that take the company? I was also struck, at a fairly junior stage of my career, that my opinions weren’t just valued, they had the power to help turn the ship around. That’s when I realised risk and resilience could give me a genuinely interesting career with real impact.

You describe yourself as someone who loves delivering strategic initiatives. What part of leading large-scale change energizes you the most right now?

I think we’re living through a genuinely unprecedented period of technical, geopolitical, and social change. It’s not one single thing happening, each shift is the next inflection point in a lineage of prior ones. Some of my clients tell me that 90% of their AI adoption comes through SaaS vendors quietly enabling AI features, sometimes without even asking permission. We couldn’t have arrived there without the dot-com boom first, then cloud transformation, before AI came along. What energises me most is the ongoing novelty of these changes and the complexity that comes with them.

Regulated industries are moving faster than regulations can keep up. What do you believe will be the biggest regulatory challenge for enterprises in the next 5 years?

That’s true, but it’s always been true. It’s probably just truer now than ever, given the pace and scale of technology change.

One of the biggest regulatory challenges, not just for enterprises but for regulators too, is governing the actions of AI. It already feels ubiquitous, and it’s only going to become more so over that timeframe. Right now, we’re in a position where enterprises don’t always know or understand what AI is doing on their behalf, yet they will be held accountable for actions taken by AI that is ostensibly under their control. The challenge is making sure they have that control and that understanding and can account for it. In other words, taking real accountability.

Trust is becoming a competitive advantage. How can organizations measure and build trust as a core part of their risk strategy?

Trust used to be something organisations earned once and then took for granted. Now you need to be able to measure trust and sentiment properly, across a range of topics, we hear a lot about concern over “greenwashing,” for instance. As organisations adopt AI, trust relies on being able to answer questions like: Can you show who or what took an action? Can you verify the data behind a decision? Can you evidence the controls around your AI systems the same way you would any other critical process?

Organisations that can do this and show the evidence will be the ones clients and regulators trust most. The competitive advantage isn’t making a claim about trustworthiness, it’s being able to prove it.

The role of a risk leader is shifting from control to enablement. What does great leadership look like when teams and AI agents are co-managing risk?

Traditional risk management assumes a relatively static picture: experts assess, then control, with handoffs across teams and an evergreen cycle to work through. But business, technology, supply chains,  and therefore risk, are far more dynamic now. From a cyber security standpoint, we need to think about the environment as being tested, and contested, at all times. There’s an adversary actively working against your controls, and now AI agents on both sides of that contest.

So great leadership isn’t about the risk leader holding the controls. Truthfully, they’ve never been able to control everything, even if they valiantly tried for a long time. The great risk leaders now are the ones who step away without losing oversight. They set the risk and control conditions so that teams and AI agents can operate with good judgement inside clear boundaries, and they know when to step in. That’s harder than it sounds.

Strategic change requires clarity and stamina. What is one book, thinker, or mentor that fundamentally shaped how you lead?

It does require those qualities. It also requires bravery and the fortitude to see things through, as well as patience and open-mindedness. Marcus Aurelius’ Meditations are an excellent point of reference for any leader.

You host and moderate industry panels. Which question do you love asking other leaders because it always sparks a great answer?

It varies depending on the situation, but I think history is a great educator and hindsight is a great motivator. I like to ask about something they wish they had done differently, or an opportunity they wished they’d taken, and how that affects their approach to the topic under discussion. I tend to find that leads to more honest, unpractised answers that audiences are genuinely interested to hear.

What is your biggest goal? Where do you see yourself in 5 years from now?

Firstly, the aim is to stay happy, healthy, and enjoying life. I mention that because, as a risk and crisis leader, I help clients through some of the most stressful situations they’ll face in their careers and things go wrong when people burn themselves into the ground through overwork, including when facing crisis. If you start from the mindset that you matter, individually, to the friends, family, colleagues, and clients who rely on you, you can operate in a way that lets you achieve your goals regardless of the pressures you face. Company resilience is built on personal and team resilience.

To that end, the goal is for my practice at Ashurst Perkins Coie to be recognised as the leading choice for all clients seeking high-quality, multidisciplinary cyber resilience expertise.

If you could leave one sentence of advice on the desk of every graduate entering risk, tech, or audit today, what would it be?

Be curious, be yourself, and make your bed. (Look up the speech by US Navy Admiral William McRaven.)

Content Disclaimer

Related Articles