
[Masayuki Matsuhisa, CISO and Group Executive Officer at Money Forward]
Masayuki Matsuhisa joined Hewlett-Packard Japan in 1997 and was responsible for system development, primarily for city banks. In 2011, he was transferred to the company’s Singapore office, where he served as the Project Director and led IT projects in Asia. In 2016, he returned to Japan and joined Amazon Web Services. He served as the General Manager of the Financial Solutions Division and played an instrumental role in introducing cloud technologies to the financial services industry. In 2023, he joined Money Forward as the CISO.
For the past seven years, I have been the Technical Director of the Financial Sector at AWS Japan.
The public cloud was something of a rarity in the financial services industry back in 2016. We had worked hard to help traditional financial institutions understand and take advantage of it.
In my previous career at HP Enterprise, I also experienced integrating systems for the financial services industry. I have been in this field since the early days of Internet banking in Japan for over 20 years.
There was no security framework in place at that time.
I didn’t think finance or security would be my career when I started out, but once I got involved and learned more about these industries, I was hooked.

I have lived in Singapore for five years since 2011 while working for HP Enterprise, which allowed me to be in a global environment.
The reason why I ended up going to Singapore was really a matter of chance.
In one of the executive training programs I was in at the time, we were tasked with setting up an offshore center in India, and I was there for about two months. On my way back home, I made a stop in Singapore because I was asked by a large financial institution to help them with the integration of their data centers in Asia, and I stayed there just like that.
I was not expecting this at all, but I decided to take the chance.
Actually, I could not speak English until I moved to Singapore.
Having said that, I studied English because I thought that, in my 30s, working for a foreign company, English would be an asset to my career, and I got a high score on TOEIC. Of course, a high score on TOEIC is by no means a guarantee of my ability to speak English, but it allowed me to go abroad on business and gain management experience in Singapore. Including those experiences, I’m sure my English skills have led me to where I am now.
The challenges Money Forward is facing now are what I have experienced over the last 10 years.
I’ve had an exciting seven years at AWS Japan.
It was fun managing a team of about 50 talented solution architects.
On the other hand, cloud service providers like AWS can offer great technology, but they cannot build products from it. Their job is to acquire skills in a particular technology and pass on that know-how to engineers at companies like Money Forward.
That is fun, of course, but technology is something we want to play with once we know how it works.
And I have always wanted to use technology to run a real business.

It is common for people who work for big tech companies to get offers from others, and as a result, employees often move from one tech giant to another.
I decided to accept the offer to join Money Forward because I’ve always wanted to challenge myself and take my skills to a whole new level, instead of working in the same big tech environment and following the same career path.
In terms of security, which is my area of expertise, my impression was that Money Forward ensured it where needed, even though the company has a diverse business portfolio.

There is no end to the work of ensuring security. It is impossible to completely eliminate all threats, and even if a countermeasure is taken, new threats will continue to emerge.
That is why we need someone to set the boundaries to define which risks we are taking action against and which we will tolerate.
Ichikawa-san has been in this position since the establishment of Money Forward.
It is extremely difficult to maintain so many large-scale services on a limited budget.
Of course, when we look at the whole picture, we can also identify areas where measures are inadequate. However, as I mentioned earlier, there is always “what not to do” in security measures.
Therefore, I’m trying to understand the current situation and come up with an idea of what kind of additional services we can offer as a money platform rather than trying to figure out where we are lacking.
In the future, as Money Forward becomes a global company, its portfolio will further expand. I have formulated a three-year plan based on what needs to be done to grow in Fintech x SaaS.
There are three cornerstones.
① Product Security
We offer a wide range of SaaS services. Protecting user data and enhancing security is one of the cornerstones.
② Corporate Security
We constantly update employees’ PC environments and login procedures and take the necessary steps to create an efficient work environment while ensuring protection from behind the scenes.
③ Governance
We are establishing common information security across all locations as the number of our overseas offices, such as Vietnam and India, increases. Training and workshops will be offered to help understand the definition of secure programming.

From a global perspective, there are no differences in information security between countries. The reason for this is that we have a global standard for information security, and the frameworks often overlap with each other.
However, Japan and other countries may have different requirements for what information must be protected. In Japan, we have Personal Information Protection Act. In the same way, other countries also have different legal perspectives. Therefore, we work with the Legal Division closely.
The CISO office is a so-called “safety net” for the company.
CISOs from around the world refer to a tool called the “CISO Mind Map,” published by a working group of distinguished individuals from major global technology companies. The CISO Mind Map is designed to to define CISOs’ role comprehensively. It is also important for us to eliminate the “what not to do” from the vast amount of tasks and identify the “what to do” for Money Forward.
Money Forward is in the midst of globalizing. And in my opinion, a common language is key to being a global company.
When I say "common language," I do not mean English, but a "common way of thinking".
There is a cybersecurity framework created by the National Institute of Standards and Technology (NIST). I suggested that Money Forward use this framework because it is used by many global companies.
This framework is accessible worldwide, so whether we are based in Japan or Vietnam, we can start from the exact same step.
Without this global framework, we may end up trying to impose Japanese practices on our overseas offices.

Nakade-san, the company’s CTO, has been saying that we are going to become a big tech company.
As I understand his message, he’s not saying that we should be a clone of the existing tech giants. It would be perfect for us to be a global company in our original way, borrowing from the tech giants.
Working at AWS Japan has allowed me to experience both the good and the bad. Now, it’s time for me to share my knowledge and experience to help transform Money Forward into a global company keeping what makes it unique and special.
The challenging security specialist job is among the most difficult jobs in the engineering sector.
Security specialists need a comprehensive understanding of how a developed service runs in the cloud, not to mention the language and frameworks used.
We are expected to have a broad range of knowledge because we need to see things from the same perspective as cyber attackers and identify where vulnerabilities exist.
This makes the job very demanding but also very rewarding when you are able to meet expectations.

However, I don’t think that every security specialist needs to have this knowledge from the start. Instead, I think they can learn it in the course of their daily work.
Specialists of the CISO Office help and learn from each other, making the most of their areas of expertise.
In this sense, I expect those who join Money Forward as security specialists to have the ability to enjoy an environment that requires them to absorb a wide range of knowledge and deal with unknown threats that are a byproduct of new technology.
It literally represents our culture of “Fun”.
In my opinion, you don’t have to be able to do everything when you join the company, because technical skills can be cultivated through training.
If you have expertise in a particular area, you can use that. Outside of this, you can work with and learn from others to build a better future together.
One of the most exciting aspects of working at Money Forward is the speed with which we tackle various challenges.
For enterprise-sized organizations, things usually slow down to some degree.
If I may put it bluntly, some people believe that it doesn’t matter if security measures are taken as long as there are no problems. Security measures will not be executed unless the company believes the threats directly impact its business, even if they are proposed from a CISO’s perspective.
However, at Money Forward, the CISO reports directly to the CEO. The process is very fast because Tsuji-san values speed in decision making.
Even if he decides “not to take this action at this time”, the decision is quick, so we can move forward.
I think that is one of the great appeals of this company.

The CISO Office must go global as Money Forward goes global.
My plan is to hire non-Japanese speakers and have English as the official language of the team.
This can be a big change for those who do not speak English. However, I improved my English skills in my 30s, which has opened up a new world for me.
So I hope everybody sees this challenge as a positive opportunity.
As I mentioned earlier, being a security engineer is a very tough job. This is because we have to decide what to do and what not to do.
CISOs across the country find it difficult to draw the line between the two.
So what I’m trying to do is create a kind of template that they can refer to when they have to make a decision.
Your budget will be wasted if you don’t understand which risks you are trying to minimize with the investment.
It is not easy to decide not to take action because we want to do something when there is a risk in front of us.
My goal is to make Money Forward a reference for other CISOs if they have doubts about their decisions. To achieve this, we must ensure that our security is robust and consistent.
As a member of Money Forward, I will strive for that future.

Interview, text and pictures by Hiroyuki Nitta (Recruiting PR Division, Money Forward)
English Translation by Yuki Momma (Globalization & Communication Partners)