Morgan Street Holdings is a holding company and private investment group with a growth mindset, owning a portfolio of operating companies and brands – HAVI, tms, Stanley 1913, and Continental – offering best-in-class sourcing and supply chain capabilities, brand-defining marketing and promotion services, innovative and award-winning consumer products, and convenience and vending solutions. Together, these companies have over 10,000 employees operating in more than 50 countries around the world.

For Douglas Darden, Business Information Security Officer at Morgan Street Holdings, cybersecurity leadership is not simply about controls, frameworks or risk registers. It is about enabling a diverse and growing enterprise to move with confidence.
“I use the analogy of the organisation as a sports car, and security as the brakes,” he says. “You’re not going to get into a sports car and go full throttle if you know you can’t stop, or at least slow down.”
As Head of Technology Governance, Risk and Compliance, Douglas leads a compact but influential GRC team across Morgan Street Holdings and its operating companies and brands. The main holding company has around 130 people, with a security team of roughly 20, but its reach extends across four operating companies and brands – HAVI, tms, Stanley 1913 and Continental – each with its own business model, risk profile and objectives.
The breadth of Douglas’ role reflects the complexity of Morgan Street Holdings’ structure. He reports directly to the CISO, but his team’s responsibilities extend beyond the holding company itself. The challenge is to align governance, security standards, and legal and regulatory requirements across the full portfolio.
“Every day presents a new challenge,” he says. “That’s the world that I thrive in, where no day is the same twice. We’re a small but mighty team.”
Cyber Leadership Through Influence
Douglas’ five years at Morgan Street Holdings have coincided with significant organisational change. When he joined, the security team was much smaller, with around five full-time employees and one contractor. Since then, the team has achieved ISO 27001 certification with multiple scopes, absorbed new operating companies and brands including Continental and Stanley 1913, and evolved into Morgan Street Holdings.
Being close to the CISO has been central to his ability to drive change. “Reporting directly to the CISO gives me greater influence within the organisation to get things done,” Douglas says. “It also gets me in front of my CISO’s leadership and his peers.”
That access has helped him build Morgan Street Holdings’ data protection program, working directly with finance, HR, treasury, the CIO and the PMO. For Douglas, governance is not an abstract exercise. It is built through relationships, shared priorities and practical execution.
“I’ve been putting together my strategic plan and now I’m in execution mode,” he notes. “Part of that is defining the governance and putting in the tools that will support it.”
From Compliance to Enablement
When Douglas joined Morgan Street Holdings, the company was operating under a different structure and had fewer operating companies and brands. Security policies were already in place, and ISO certification became a major milestone, driven in part by customer requirements.
But certification was not the end state. “For security awareness training, we set a target of 80% initially,” he says. “Once we got the certification, we said: how do we mature the organisation? So, we raised that standard to 90%.”
Since then, Morgan Street Holdings has rewritten a number of policies, standards and guidelines to reflect the needs of a holding company with diverse operating businesses. The work requires a bespoke approach.
“It’s a nuanced conversation around securing different entities that have different business models and objectives,” Douglas says. “That really is us getting in front of those executives and understanding what’s important to them.”
This is particularly important during M&A. When Continental was onboarded, Morgan Street Holdings assessed where the business was in its security journey, what tools it had and what its risk profile looked like. The same approach applied to Stanley 1913 and to Morgan Street Holdings itself as it evolved.
“We’ve created a security assurance function where we baseline all of the operating companies and brands on where they are in their security journey,” he says. “That allows them to roadmap areas where they want to invest more into their maturity levels.”