Humberto Comellas, President & CEO, Ulltium Consulting

Humberto Comellas, President & CEO, Ulltium ConsultingIn an interview with Invest:, Humberto Comellas, president and CEO of Ulltium Consulting, discussed how companies can better align technology with business strategy, reduce cybersecurity exposure, and prepare for emerging shifts in AI, cloud, and quantum computing. “Cybersecurity is no longer an afterthought. It has to be part of the day-to-day operation,” Comellas said.

How does Ulltium Consulting help organizations ensure technology investments deliver measurable business outcomes?

I am a technologist by trade, but I look at the business requirements. When I meet with a prospect or client, I always lead with the idea that technology is one of the four pillars. It cannot be considered an afterthought. Just like a good banker, a good accountant, and a good attorney, you need a good technology partner, whether that is internal or outsourced.

Technology needs to be part of the organization by being invited into the boardroom. What is the business strategy? Where are you going? That allows us to make sure technology is aligned with those requirements and that the company is making sound financial investments.

It is not about simply replacing hardware or adding tools that may or may not deliver a return on investment. It is about putting solutions in place that help the business become more effective, more efficient, and better positioned for growth.

What are the most common cybersecurity vulnerabilities you see among midsized organizations?

Part of our core services, besides managed services, is cybersecurity. Throughout my career, I have managed tens of thousands of endpoints and have been responsible for hundreds of sites. I have never had a successful cyber breach, although there have been many attempts.

However, I always tell clients and prospects that if the bad guys want to get into your data badly enough, inevitably, it is going to happen. There is very little that any company can guarantee when it comes to never being breached. The key is to make it as difficult as possible for any bad actor to gain access.

You also need proper security and recovery measures. If you are down for an hour, that is one thing. If you are down for a day, that is another. But if you are down for a week or two, especially in the SMB space, the likelihood that you will ever reopen your doors starts to diminish day after day.

The number No. 1 risk factor, in my opinion and professional experience, continues to be between the person and the mouse. Where people go, what they click on, and what files they open remain critical vulnerabilities. Education is paramount, along with proper protocols and employee training.

I have turned away business because some organizations do not value having those security measures in place. I am willing to take on that risk only when I have a strategic partner that recognizes that cybersecurity is no longer an afterthought. It has to be part of the day-to-day operation.

How should companies approach cloud adoption, AI, and digital transformation without creating more disruption?

I recently picked up a client that had migrated from an on-premise environment to the cloud, but the migration was not properly planned. The result was latency, disconnects, and disruption to the business.

I truly believe that cloud is the way to go for a number of reasons, including resilience and redundancy, especially because we live in Hurricane Alley. Having systems in the cloud creates a level of protection and accessibility that many organizations would not otherwise have.

However, companies need to make sure everything is properly designed and configured. It is not simply a matter of moving systems from one environment to another.

Another important point is security. Moving to the cloud or adopting a SaaS solution does not eliminate the potential for downtime, data loss, or compromise. None of the cybersecurity requirements go away. Many clients do not understand that, so it falls on the managed security service provider to have those conversations and make sure expectations are realistic.

What separates companies that successfully use technology for competitive advantage from those that fall behind?

This is where I think AI can be a big game changer. Years ago, the focus was on CRM systems and understanding your customer. Having access to information that creates a differentiator between you and your competitors remains important.

However, there is an old adage: junk in, junk out.

If you are not properly sorting, categorizing, and leveraging your data, then you are still chasing information instead of using it. You are asking where the data is, how to use it, and whether it is accurate.

I believe AI, embraced cautiously, can help companies organize that information and access it in a way that better serves both the organization and its clients.

Are organizations becoming more proactive with compliance, or are they still treating it as a checkbox exercise?

I would like to think they are becoming more proactive, but unfortunately, I think it is still more of a checkbox exercise. 

I spent close to 20 years as CIO for two large banks, and in that industry, security, compliance, and regulatory requirements are non-negotiable. That experience has enabled me to have frank conversations with prospects and clients about the importance of compliance.

Whether it is HIPAA compliance in healthcare, PCI compliance for financial information, or SOC requirements for cloud environments, these standards exist not only to protect data but also to protect businesses and their clients.

When you are a small business and do not have the resources to respond to a major incident, minimizing exposure becomes critical. Having the proper security protocols and compliance measures in place helps protect both the business and its reputation.

What technologies or trends do you believe will have the greatest impact on your clients over the next five years?

In nearly 45 years in the industry, I have seen technology evolve dramatically. The pace of growth over the last decade has been remarkable, and that acceleration is only going to continue with AI and other emerging technologies.

The biggest challenge, as well as the biggest opportunity, may be quantum computing. Quantum computing is going to take everything to another level because of the sheer speed at which it can process information.

I have read statistics suggesting that quantum computing could potentially breach even highly complex security structures in extremely short periods of time. Imagine what that means for companies that are trying to detect, protect, and safeguard critical systems and information.

There are a lot of changes coming that will create both opportunities and challenges. If you are in the technology world, you will never have a dull moment in the next five years.

What message would you give to small and midsized businesses about cybersecurity?

There is still a misconception that cybersecurity is only relevant to large organizations. That is completely false. Small and midsized businesses are also being targeted, and many of them do not have the resources or financial capacity to recover from a major incident.

If something does happen, you need to be able to recover.

It is no longer a Fortune 500 issue. SMBs and smaller companies are being targeted.

Unfortunately, many business owners still do not have a vested interest in technology. As long as everything is working, they do not think about it. It is like a car. You turn it on and it runs, so you do not pay much attention to it until it stops working.

That is why having these conversations is so important. Business owners need to make sure their IT partner is doing what they say they are doing.