Martin Laberge
Executive Director, Cybersecurity, Governance and IT Services, Énergir

Martin Laberge is Executive Director, Cybersecurity, Governance and IT Services at Énergir in Quebec, where he leads cybersecurity strategy, risk management, OT security, governance, and IT services across the organization and its Canadian and American subsidiaries. Recognized as one of the Top 100 CISOs of 2026, he is a strong advocate for protecting critical infrastructure and advancing operational technology (OT) security. A frequent speaker at industry conferences, Martin is passionate about developing the next generation of cybersecurity leaders and believes that strong teams, resilient organizations, and a people-centered approach are the foundation of long-term success.

Recently, in an exclusive interview with CIO Magazine, Martin shared insights into how a 2003 computer worm shifted him from software QA to cybersecurity, leading to a 23-year career across industries and to his current role at Énergir where security underpins corporate strategy. On AI and emerging threats, he warns boards are underestimating the convergence of AI-accelerated attacks and quantum-era cryptography risk, stressing resilience over single-threat readiness. His advice is to build great people, earn the trust of the business, and lead with adaptability because no CISO succeeds alone. The following excerpts are taken from the interview.

Hi Martin. Your career spans 23 years across retail, finance, government, transport, energy, and utilities, and now as CISO you lead global cybersecurity programs. What was the pivotal project or challenge early in your career that first made you realize cybersecurity was your calling?

Initially, I was not destined to work in cybersecurity. It was one of the first computer worms in 2003 that introduced me to this field. At the time, I was working as a Software Quality Assurance Analyst. The company I worked for had been hit by a computer worm, and most employees were affected except for our small office. Two colleagues and I had searched Yahoo, downloaded the Windows patch that prevented the worm from spreading, burned three CDs, and manually installed the patch on all our workstations. The CIO at the time was impressed by our resourcefulness and promptly “volunteered” us to build the company’s information security team. I did not know much about cybersecurity then, but I was curious and eager to prove myself, so I accepted the challenge. Twelve months later, I was promoted to Team Coordinator.

My first truly defining project came later during my time at RONA, following its acquisition by Lowe’s. We earned the trust of senior leadership in Québec, as well as the support of the U.S.-based CISO at the time, Warren Steytler, who became a mentor to me. My team and I were given the opportunity to design and implement a comprehensive three-year cybersecurity program. That experience solidified my decision to pursue a career as a CISO. Today, I am incredibly fortunate to continue that journey with Énergir, a company that has made cybersecurity a cornerstone of its strategic plan, and where I have had the privilege of building my career for the past six years.

What part of your current role energizes you most every day, and why does it keep you passionate about the work?

What continues to inspire me today is knowing that my team enables the organization to achieve its objectives by reducing operational risk. Knowing that, through our work, the company is able to grow, evolve, and seize new opportunities.

Cybersecurity is such a broad and fascinating field. In the same day, I might have a highly technical discussion with my Director of Operations in the morning, then meet with the CFO to discuss the potential financial impact of a major incident. Later, I might present to the Board of Directors, and finish the day discussing emerging technologies and the integration of artificial intelligence with my colleagues and my boss.

If that’s not motivating, I don’t know what is.

Every day brings new challenges, new perspectives, and new opportunities to make a meaningful impact on the business. That diversity, combined with the ability to influence both technology and corporate strategy, is what makes cybersecurity such a rewarding profession for me.

The threat landscape evolves daily, yet budgets and talent remain finite. Looking ahead five years, what single shift in adversary tactics do you believe boards are still underestimating today? 

I believe boards are still underestimating the convergence of artificial intelligence and quantum computing.

Today, most discussions focus on ransomware and data breaches. Those threats remain real, but they are extensions of risks we already understand. What concerns me more is how emerging technologies will fundamentally change the economics of cyberattacks.

In the near term, artificial intelligence will enable adversaries to automate reconnaissance, vulnerability discovery, social engineering, and even large portions of the attack chain. Attackers will be able to operate at a scale and speed that traditional security organizations cannot easily match.

Looking further ahead, quantum computing has the potential to disrupt one of the foundations of modern cybersecurity: cryptography. While large-scale quantum attacks may still be years away, the risk is already present because adversaries can steal sensitive information today and decrypt it in the future once quantum capabilities mature. Many boards are still treating quantum as a research problem rather than a business risk.

The real challenge is that organizations are preparing for individual threats when they should be preparing for a future where AI accelerates attacks and quantum computing weakens some of the trust mechanisms that underpin our digital economy.

The question boards should be asking is not simply whether they are protected from today’s threats. It is whether their organization is becoming resilient enough to adapt to technologies that will fundamentally reshape both attack and defence.

Talent in the AI era needs new fluency. Beyond technical upskilling, what human capability do you believe leaders must cultivate so their teams thrive alongside AI, not fear it? 

Beyond technical upskilling, the most important capability leaders need to cultivate is adaptability.

Every major technology shift creates uncertainty, and uncertainty often leads to fear. AI is no different. The organizations that will thrive won’t necessarily be those with the most advanced AI tools, they will be the ones with people who are willing and able to continuously learn, unlearn, and reinvent how they work.

Throughout history, technology has repeatedly changed jobs, but it has rarely eliminated the need for human judgment, creativity, empathy, and leadership. What changes is how we apply those uniquely human strengths.

As leaders, our role is not simply to teach employees how to use AI. It’s to create an environment where experimentation is encouraged, learning is continuous, and failure is viewed as part of the adaptation process.

In cybersecurity, we’ve been adapting to constant change for decades. AI is simply the next evolution. The individuals who will excel are not those who know all the answers, but those who remain curious, flexible, and willing to evolve alongside the technology.

Ultimately, I don’t think the future belongs to AI. I think it belongs to people who know how to work with AI.

Most recently, you were recognized as one of the Top 100 CISOs, 2026. Our readers would love to know the secret mantra behind your success.

To be honest, I don’t believe there is a secret mantra for success as a CISO. If there is one lesson I’ve learned throughout my career, it’s that no CISO succeeds alone.

Any recognition I receive is really a reflection of the incredible people I have the privilege to work with every day. Success in cybersecurity requires a strong, multidisciplinary team made up of people with different skills, perspectives, and experiences. You need technical experts, risk professionals, architects, communicators, and problem-solvers who share the same purpose and passion.

Equally important is the support of the organization. Cybersecurity cannot succeed in isolation. It requires executive sponsorship, engaged business leaders, and a culture that understands that security is an enabler of growth, resilience, and trust.

Personally, I have always believed that passion is contagious. I am passionate about what I do, and I think leaders who genuinely care about their mission have a unique ability to inspire others and bring people along on the journey. Building a high-performing team is not just about hiring talented people, it’s about creating an environment where they can grow, innovate, and challenge one another.

Another lesson I’ve learned is that a successful CISO cannot view the role as purely technological. Technology is important, but cybersecurity is fundamentally a business discipline. It is about understanding risk, enabling strategic objectives, protecting critical operations, and helping organizations innovate with confidence.

The most effective CISOs are those who can move comfortably between the technical and business worlds, discussing threats and architecture with engineers in the morning, risk exposure with the CFO at lunch, and strategic priorities with the Board of Directors in the afternoon.

If I had to summarize my philosophy in one sentence, it would be this: build great people, earn the trust of the business, and never lose sight of the fact that cybersecurity exists to help the organization succeed.

Leaders are shaped as much by life outside the office as within it. What’s a book, not about security or business, that fundamentally changed how you think about risk or people? 

The book that had the greatest impact on me was Awaken the Giant Within by Tony Robbins.

At first glance, it may seem far removed from cybersecurity, but many of the lessons I learned from it have shaped both my leadership philosophy and my approach to risk management.

One of the book’s central messages is that our results are largely driven by our beliefs, decisions, and actions. As leaders, we cannot control every challenge, crisis, or threat that comes our way, but we can control how we respond to them. That mindset has been invaluable throughout my career in cybersecurity, where uncertainty and constant change are part of the job.

The book also reinforced an important lesson about people: individuals are capable of far more than they often believe. As a leader, I see one of my primary responsibilities as helping people recognize their potential, develop confidence, and grow beyond what they thought possible.

Building high-performing teams is not just about technical skills. It’s about inspiring people, creating a sense of purpose, and fostering an environment where they can continue to learn and evolve. Those lessons have influenced me as much as any cybersecurity framework or technical certification.

Ultimately, the book taught me that success starts with mindset. Technology changes, threats evolve, and industries transform, but the ability to adapt, grow, and bring out the best in people remains a timeless leadership skill.

If you weren’t in cybersecurity, the curiosity and discipline you have could translate to many fields. What’s one profession you secretly think you’d have loved to pursue? 

If I weren’t in cybersecurity, I think I would have loved to be an actor.

I did a great deal of theatre in my youth and even appeared as an extra in a few television productions and web series. I was fascinated by the idea of stepping into another person’s shoes and bringing emotions to life for an audience.

Ironically, I still get to do a little of that today. I spend a lot of time speaking at conferences, telling stories, and helping people see cybersecurity from a different perspective.

The setting may have changed, but the goal is similar: connect with people, inspire them, and leave a lasting impression. I suppose cybersecurity became my stage.

What is your biggest goal? Where do you see yourself in 5 years from now?

Five years from now, I hope to continue evolving alongside a team and an organization that are as talented, innovative, and human-centered as the ones I have the privilege to work with today at Énergir.

Earlier in my career, I was driven primarily by technology and the excitement of solving complex security challenges. Over time, however, I discovered that one of the most rewarding aspects of leadership is watching others grow and succeed. Seeing team members develop new skills, take on bigger responsibilities, and achieve goals they once thought were beyond their reach has become even more fulfilling than deploying the latest technology.

One of my personal goals is to help develop the next generation of cybersecurity leaders. If, in five years, some of the people I have had the opportunity to mentor are serving as CISOs, security executives, or influential voices in our industry, I would consider that one of my greatest accomplishments.

Beyond my organization, I have become increasingly passionate about operational technology (OT) security and the protection of critical infrastructure. Over the past few years, I have made it one of my personal missions to raise awareness of the risks facing critical assets and the importance of investing in their protection.

I hope to continue working with industry leaders, government officials, and operators of critical infrastructure to help strengthen our collective resilience. The consequences of a cyberattack against critical services extend far beyond technology.  They can impact public safety, economic stability, and the daily lives of citizens.

Ultimately, my goal is not just to build secure systems. It is to help build stronger people, stronger organizations, and more resilient critical infrastructure for the next generation.

If an aspiring professional could only take one lesson from your journey, what truth about building a career in security would you want them to remember on their hardest day?

If there is one lesson, I would want aspiring professionals to remember on their hardest day, it is that people are far more resilient than they think.

At some point in your career, you will face a major incident, a crisis, or a situation that seems overwhelming. In cybersecurity, it is not a question of if, it is a question of when. The organizations and professionals who succeed are not the ones who avoid every crisis. They are the ones who are prepared to respond when adversity arrives.

One of the biggest lessons I have learned is that there is almost always a solution. Sometimes it requires thinking outside the box. Sometimes it requires challenging assumptions. And very often, the answer is sitting somewhere within your team, waiting to be discovered through collaboration and open dialogue.

No one succeeds alone in this profession. When things go wrong, ego becomes the enemy. The ability to listen, ask for help, and leverage the collective intelligence of your colleagues is often what makes the difference between failure and success.

Throughout my career, I have always encouraged my teams to adopt this mindset: stay calm, stay curious, and focus on solutions. Every crisis presents an opportunity to learn, improve, and emerge stronger than before.

The true measure of maturity, both for a cybersecurity professional and for an organization, is not whether they can prevent every incident. It is how effectively they respond, adapt, and recover when the inevitable happens.

Content Disclaimer

Related Articles