# From Ransomware to Resilience: How TransLink’s CISO Learned to Prove Security ROI to the Board
In the high-stakes world of public infrastructure cybersecurity, proving that your security program actually works can be harder than implementing it. Biying He, Director of Cybersecurity, Resilience, and Information Management at TransLink—the transportation authority serving Metro Vancouver—has cracked that code. As one of two finalists for the 2026 CanadianCIO CISO of the Year Award, He reveals her unconventional approach: moving beyond technical jargon to deliver operational metrics that boards actually understand, all while rebuilding a security team decimated by a devastating ransomware attack.
For cybersecurity professionals, the eternal struggle isn't just fighting threats—it's convincing executives that the millions spent on defensive measures are worth it. Too often, security leaders speak in abstractions like "risk mitigation" and "threat intelligence," which translate poorly in boardrooms governed by spreadsheets and ROI calculations. Biying He, the quiet force behind TransLink's cyber resilience, believes she's found the answer through a surprising blend of accounting discipline and operational transparency.
## The Road to TransLink: An Unconventional Path to Cybersecurity
He never aspired to the spotlight. "I never wanted to be in the spotlight, to be honest," she admits. "I just want to quietly get the things done." Yet her journey to becoming a CISO finalist began in an unlikely place: accounting. Working as an accountant in China, He was unexpectedly assigned as the project manager for an Enterprise Resource Planning (ERP) system installation—before she had any formal project management credentials.
That baptism by fire led to running a factory with 150 employees and eventually a startup focused on identity and asset management. When she moved to Canada and joined KPMG as a senior consultant, He found herself frustrated by a recurring pattern: she could offer clients the best recommendations available, but if they didn't act on them, she'd return three years later finding identical vulnerabilities. "That's why I transitioned into a practitioner," says He. "I want to make things happen."
A formative early boss taught her a crucial lesson about organizational readiness: "Before you can run, you have to crawl first. We all know that. But sometimes we kind of forget that and it takes time."
## Rebuilding After a Major Data Breach and Malware Attack
When He joined TransLink in 2023, she walked into an organization still reeling from a significant security incident. In December 2020, a ransomware attack knocked out card payments at vending machines and fare gates for three days. TransLink was forced to shut down key IT systems while transit service continued running. Employees received advance pay with overtime and pay stubs missing—a logistical nightmare compounded by the security breach itself.
The executive team had been asking since the attack whether the organization was truly serious about cybersecurity or merely treating it as a buzzword. He saw this as a golden opportunity rather than a burden. "I think it's a great opportunity to rebuild, restructure and make it better," she says. The attack left her with something every security leader craves: executive support.
Her first move was aggressive hiring. She expanded her team from approximately 11 people to 29 over two years, spanning cybersecurity, IT resiliency, and information management. He deliberately prioritized people over process and technology, arguing that the latter two collapse without skilled, motivated humans driving them. "Technology is always the easy part," she notes.
The journey hasn't been smooth. "We have lots of friction, I can tell you," He says. "Sometimes it's like you feel that you cannot move that mountain." But the teams that weathered that friction emerged trusting each other and moving faster.
## Speaking the Board's Language: Operational Metrics Over Fear
He's background in accounting and operations manifests directly in how she reports to TransLink's executives and board. Rather than drowning them in technical vulnerability assessments, she delivers what they understand: operational numbers. How many employees finished their training? How long does a critical vulnerability sit open? How long does it take the organization to recover a critical system?
This data-driven approach transforms cybersecurity from a nebulous cost center into a measurable operational function. The board sees progress in concrete terms, not abstract risk models. For a public infrastructure authority with approximately 10,000 employees, this transparency is essential—the risk profile includes everything from fare payment systems to operational technology that keeps trains moving.
## The Training Program That Succeeded Beyond Expectations
One of He's most striking successes came from setting a security awareness training target—and having her CEO dramatically raise it. Originally, He calculated that a 45% completion rate was realistic for roughly 10,000 employees and 4,500 computer users. Her CEO responded, "Why not, let's set it at 90 percent."
"I was so happy about it," says He. Most security leaders spend careers fighting to raise executive expectations; He found herself with a CEO who doubled her own ambition.
The initial completion rate stood at 30 to 40%. Within a year, it hit 80%. He rebuilt the program to run monthly instead of annually, with simulated phishing tests three times per year. A "Cyber Smart" program now names one or two employees annually based on how much phishing they report and how much training they complete. Crucially, completion and click rates go to executives and the board, broken down so each leader sees their own staff's performance. "As long as you can create that clarity on what support you need from them, they will be able to support you," He explains.
## Real Numbers: Vulnerability Remediation Time Drops Dramatically
The results speak volumes. He reports that vulnerability remediation time on zero-day exploits dropped from weeks and months to hours. "Nowadays we are talking about hours," she says. Response typically takes two to four hours, with some cases extending to 24 hours or a few days depending on where the vulnerability sits and which systems it touches.
For other vulnerabilities, time to remediation plummeted from 90 days to 30. But He adds a crucial caveat: "30 days can slip back to 60 if the process behind it isn't maintained." This honesty with the board is part of her strategy. She doesn't just present numbers—she educates executives on what those numbers mean and why they fluctuated.
TransLink runs more than 500 applications. He's team ranked them to identify the ones the business can't operate without. For the top tiers, she tracks whether recovery instructions have been updated within the last year, whether recovery has been tested within the last year, and how long each system actually takes to restore. Her mantra? "If you say you're doing well, show me how well you're doing."
## AI: The Double-Edged Sword in Modern Cybersecurity
When asked about artificial intelligence, He gives a measured but cautionary response: "If you're applying AI immediately in your organization without having solid data management or information management, you're accelerating your data exposure."
This is the voice of experience speaking. AI has made phishing more effective, so her training now draws on real phishing cases from around the world. When an employee clicks a live phishing email that the security layer already stripped of its malicious link, a training module opens on the spot—turning a potential malware infection into a teachable moment.
He's team automates much of the patching process and is beginning to use AI to help prioritize what needs fixing first. This helps combat a growing threat: attackers stringing together several medium-severity vulnerabilities to gain deeper access into systems.
## Real-World Testing: Surviving a DoS Attack
TransLink faced a series of denial-of-service (DoS) attacks in August—a scenario where attackers flood a system with junk traffic until it stops answering legitimate users. Fortunately, He's team had run a tabletop exercise on that exact scenario three months earlier. "The response held because each person already knew their part," she says. It's a powerful demonstration of why preparation matters, not just having the right technology in place.
## The Community Builder's Philosophy
Beyond her role at TransLink, He serves on the executive committee of the CIO Association of Canada's CISO division, where she and her peers share lessons learned. "If I go first, I will share my experience with them, what went well and what didn't, so that they can avoid making the same mistake as we do," she says.
This commitment to community explains why a self-described low-key person agreed to be in the public spotlight as a CISO of the Year finalist. Someone has to step up. "I want to build that strong community in Canada and contribute where I can," says He.
## Conclusion: Security Success Is About Communication and Persistence
Biying He's approach offers a blueprint for cybersecurity leaders struggling to demonstrate value to skeptical boards. By bridging the gap between technical complexity and operational practicality, she's shown that security success isn't just about having the best tools—it's about communicating progress in language executives understand, building teams that can adapt quickly, and never forgetting that before you can run, you have to crawl. For those wondering why their vulnerability metrics aren't improving or their security awareness training rates have plateaued, He's story offers a compelling lesson: sometimes the most effective security strategy is translating your success into numbers your board can't ignore.