Doug Collins: Looking Beyond the Cybersecurity Perimeter

Cybersecurity has become a part of everyday business life. As organizations grow more connected, the challenge is no longer simply protecting systems from attacks. Businesses and their leaders must understand where cyber risks intersect with operations, decision-making, people, and long-term growth. At the same time, the industry itself is being pushed to rethink approaches that were built for an earlier digital era.
With more than 35 years of experience in cybersecurity, Doug Collins, Chief Executive Officer of Quinte Cyber Shield, has built his career around helping organisations make sense of this changing environment. He currently leads EDDITS, a consulting group delivering multifaceted solutions across cybersecurity, property management, and educational software development. Through EDDITS and its subsidiaries, including Quinte Cyber Shield, Doug works with businesses and Boards of Directors to navigate complex cyber risks, offering strategic guidance and tailored solutions designed to strengthen their security posture.
His work, however, extends beyond cybersecurity consulting. Doug is also a published author of fiction and non-fiction, with his writing exploring subjects including emerging technologies, cybersecurity, and mathematics. His interest in education has further led him to develop innovative mathematics software for schools and parents, with the aim of making mathematics more relevant and engaging to teach and learn.
Across these different pursuits runs a common thread: a desire to look beyond conventional thinking. Doug combines his strategic experience with his interests in technology, education, and creative work to contribute to businesses and communities in different ways.
At the heart of this journey is a simple ambition that continues to guide his work: “I wish to inspire a change in thinking.”
From Cybersecurity to Business Leadership
With more than 35 years in cybersecurity, Doug has witnessed the industry evolve from a largely technical function into a critical business concern. His experience has shaped a leadership perspective that looks beyond systems and controls to the wider relationship between cybersecurity, business risk, operational priorities, and revenue.
As Chief Executive Officer of Quinte Cyber Shield, Doug brings this business-focused perspective to organizations navigating an increasingly complex threat environment. His work extends across two cybersecurity platforms, each serving a different need. Quinte Cyber Shield was established to address the operational security requirements of businesses in the Quinte region, while EDDITS Consulting Group focuses on the strategic and directional needs of larger organizations seeking to align cybersecurity with business risk.
Turning Cybersecurity into a Business Decision
Doug believes cybersecurity strategies need to be understood through the language of business. Risk, cost, and revenue should sit at the centre of cybersecurity decision-making.
In his view, cybersecurity has become too expensive and needs to become more streamlined and focused. Many companies have adopted what he describes as a “shotgun approach,” investing across multiple areas without necessarily addressing the right risks. At the same time, security breaches continue to expand, making a more targeted approach increasingly necessary.
Making Smaller Businesses More Proactive
The motivation behind Quinte Cyber Shield came from seeing local companies rely heavily on security by obscurity. Doug believes that approach is becoming increasingly difficult to sustain as supply chain-related attacks continue to grow.
Smaller organizations will need to become more proactive about cybersecurity rather than assuming that limited visibility makes them less attractive targets. His focus through Quinte Cyber Shield is therefore closely connected to helping businesses address their operational security needs before growing threats expose existing weaknesses.
Bringing Cyber Risk into the Boardroom
Cybersecurity is now a boardroom issue, but Doug sees an important gap in how boards interpret cybersecurity information. Many boardrooms do not yet have the expertise required to connect cybersecurity input with wider business risk.
That understanding needs to develop. Until the necessary expertise becomes part of the boardroom itself, Doug believes organizations will continue to need specialist advisors such as EDDITS to help translate cybersecurity concerns into meaningful business decisions.
Preparing for a Rapidly Changing Threat Landscape
The arrival of AI and other emerging technologies is changing the cybersecurity environment at a dramatic pace. Doug believes legacy cybersecurity approaches will struggle to keep pace, particularly as malicious actors adopt AI to accelerate their capabilities.
Quantum computing represents another potential shift, with advancements capable of once again moving faster than cybersecurity responses. In such an environment, Doug sees cybersecurity increasingly becoming a risk in itself rather than simply a control designed to manage risk.
Moving Beyond Reactive Security
Doug sees a fundamental mismatch between how cybersecurity architecture has traditionally been designed and the nature of today’s threats. Much of the existing architecture is built around reacting to incidents, while threats are becoming continuous and increasingly sophisticated.
He compares the situation to asking an engine to continuously run in the red zone of a tachometer. Eventually, it will overheat and fail. In the same way, organizations cannot depend indefinitely on a cybersecurity model built around constant reaction. Building genuine resilience requires addressing this mismatch between security architecture and the threat environment.
Credentials That Opened New Doors
Earlier in his career, Doug held CISSP, CISA, and CISM credentials, bringing perspectives across security, auditing, governance, risk management, and leadership to his professional journey.
Reflecting on the value of these qualifications, he keeps his answer straightforward: they have opened doors to opportunities throughout his career. That experience has contributed to the breadth of perspective he now brings to cybersecurity leadership and advisory work.
When Technology Leaves People Carrying the Burden
Technology may sit at the centre of cybersecurity, but people remain deeply involved in keeping systems secure. Doug believes the current cybersecurity architecture places too much responsibility on those people, creating an environment where everyone involved is increasingly facing burnout.
The challenge, in his view, is not simply about asking people to work harder or become more vigilant. It points to a deeper problem within the architecture itself. A security model that depends heavily on people to continually respond, monitor, and manage threats cannot remain sustainable indefinitely.
The Cost of Maintaining the Status Quo
Looking ahead, Doug sees cost becoming one of the biggest cybersecurity concerns for businesses. The current approach requires organizations to maintain perpetual spending across software, people, and the financial consequences of security breaches.
He believes this cycle needs to change. Rather than continuing to build security around detection and response, Doug argues that cybersecurity requires a complete redesign in which prevention becomes prevalent over detection. Such a shift could change not only how organizations protect themselves, but also how they think about the long-term economics of cybersecurity.
Designing Security Around Innovation
Cloud platforms, connected systems, AI, and rapidly evolving digital infrastructure have become fundamental to modern business. Doug believes cybersecurity needs to evolve alongside these developments rather than being added afterward.
His concern is that current cybersecurity design did not adequately account for innovation at its core. As new technologies emerge, organizations have often relied on additional security layers and tools to address them. Doug sees this as an unsustainable pattern and believes cybersecurity itself must be redesigned to accommodate innovation from the beginning.
The Problem Beneath the Add-Ons
Doug’s approach to leadership has been formed by what he sees as a lack of fundamental innovation within cybersecurity. While technologists working at the controls are expected to continually keep pace with new tools and security “add-ons,” the underlying architecture has largely remained unchanged.
That, he believes, is where the real problem lies. The strategic approach to cybersecurity has not fundamentally changed over the years. Instead, organizations have continued to make tactical changes and add layers of technology in response to emerging threats. Doug believes this constant need for tactical change adds to complexity while increasing both financial and human costs, without addressing the strategic foundations of cybersecurity itself.
The industry endures to place new technologies on top of an established foundation without addressing whether that foundation remains appropriate for the threats organizations now face.
Preparing for Q-Day
Among the misconceptions Doug believes businesses need to abandon is the idea that Q-Day remains a distant possibility. He sees it as being on the horizon rather than safely off in the distance.
The implication is clear: organizations should begin considering the potential cybersecurity consequences of quantum computing now, rather than waiting until developments make preparation more urgent.
A Movement Toward Sustainable Cybersecurity
Looking ahead, Doug wants his work through Quinte Cyber Shield to contribute to meaningful change across the cybersecurity landscape. His ambition is not simply to introduce another security solution, but to challenge the way cybersecurity itself is designed and approached.
He wants to see a future where cybersecurity can address emerging threats while remaining sustainable for the businesses that depend on it. Ultimately, Doug hopes to begin a movement, even a revolution, that encourages the industry to rethink its foundations and build a more sustainable model for the future.
