Ultra Clean Technology (UCT) is a business experiencing major change. It’s a developer and supplier of leading subsystems, parts, and services for the semiconductor industry – an industry which is experiencing enormous growth. This is primarily due to the AI boom.
Any organisation navigating such a level of accelerated change needs good, strong cybersecurity on its side. Mandy Huth, UCT’s CISO, has forged a path to cybersecurity that she describes as non-traditional and non-linear. While she started her further education in poli-sci and psychology, she quickly learned that those topics didn’t suit her own sense of authenticity. So, she ended up with Spanish as her major at Xavier University in Cincinnati, following encouragement from her high school Spanish teacher.
After graduating, Huth started her career at Procter & Gamble within the HR centre. While this was entirely separate from the technology side, it did involve a lot of investigating and rewriting processes, and improving efficiencies across global sites. While she was there, the company introduced its intranet – one of the first organisations to have such a thing. This meant Huth’s team moving all of the benefit manuals to an online portal. That was her first purview into computer science.
“They taught us to write HTML code, and then we started writing code for our portal,” she explains. “I learned java script, I learned reader variables – all this computer stuff. I quickly discovered I was pretty good at it.”
As a result, Huth was moved to a new position after that project. “We had over 16,000 pieces of content and I had to make it usable and navigable,” she says. Later, Procter & Gamble outsourced its IT to HP. So, Huth followed and spent a decade with the company.

The path to cybersecurity
Huth later shifted to a smaller organisation called Tripwire, which makes security software. When the CIO left, she asked if she could take over security. This new role gave her ownership of the strategy for security and product security, which was fascinating to Huth. This is where she fell in love.
“I love that security is ever-evolving and ever-changing,” she explains. “When I look back on this non-traditional path, it actually all makes sense. After my Spanish major, I lived in Germany for two years and learned the language there. I learned some Japanese. Then I learned HTML, then JavaScript, and then Python, all of which are also languages. On reflection, my path makes total sense because I have a clear predilection for language. That’s how I landed here.”

Preparing for ‘not if, but when’
Huth’s first six months at UCT were about discovering the business and grading it, before introducing a new security structure which will always be a work-in-progress. There are also a lot of operational things she needed to make sure UCT was doing well. Again, these are foundational elements because Huth is passionate about back-to-basics security from the ground-up.
“It’s a cliche, but in cybersecurity, we always say ‘it’s not if, but when’,” she explains. “Getting hit by an adversary is an eventuality. It’s about how you respond to that. Is there a strong response plan? Who is the definitive authoritative source for making decisions? How are we going to continue running while we deal with it? It’s hard to remember things when your hair is on fire, so having that plan is key.”
In an era where organisations have a habit of putting the horse before the cart because they want to adopt the latest technology as fast as they can, Huth believes focusing on business outcomes with strong process within UCT is a better approach. A lot of people will have the technology they want picked out before really examining the issues that need addressing.