Scott Applegate, Global Director of Cybersecurity Operations at Dentons

August 25, 2026

In this Sage Spotlight, Scott Applegate, Global Director of Cybersecurity Operations at Dentons, draws on 30 years in the industry to share what enterprise security is missing when it comes to automation. Scott explains how he navigates vendor discovery across 200 offices in 90 countries, and how Sagetap reshaped his discovery process — turning 20 anonymous pitches into four proofs of value and two purchases, including a switch to KnowBe4 for phishing simulation across a multinational environment.

Key Takeaways

  • AI Automation and the Harder Organizational Challenge: Scott is focused on automating simple phishing away while keeping subtler threats in front of trained eyes. Because Dentons is a Swiss Verein of 50 independent law firms, he needs to sell every new solution repeatedly to different leaders.
  • The Tier 1 Analyst Problem the Industry Isn't Considering: Scott says that automating away Tier 1 analysts eliminates the entry-level rung where senior analysts develop pattern recognition and instincts. Without it, the industry faces a 5- to 10-year gap in people qualified to supervise the automation.
  • Dentons Now Finds Vendors It Used to Miss: Before Sagetap, Scott's discovery was limited to analyst scans and peer referrals. Because vendors’ marketing web pages tend to include similar language, he felt he was left wasting time in meetings just to rule solutions out.
  • Sagetap Reshaped the Top of the Funnel: Out of 20 anonymous pitches, Scott has conducted four proofs of value and made two purchases, a result he credits to vendors on Sagetap being pressed to lead with value from the first conversation.
  • Why KnowBe4 Won His Evaluation: Scott replaced his existing phishing simulation vendor with KnowBe4 after running it through his four-question evaluation framework. Robust native language support across 90 countries was the primary deciding factor.

Full Transcript

Scott Applegate: I'm the Global Cybersecurity Operations and Risk Director at Dentons, which is one of the largest multinational law firms in the world.

I currently run global security operations and risk, which means a virtual SOC covering 200 offices in around 90 countries around the world. Plus, I oversee threat intelligence, vulnerability management, threat hunting, and incident response. I'm also the senior security advisor to our Global CIO.

I've been working in the technology and security industry for about 30 years, including running the Army's global security operations center, the Army's red team, and I was a cybersecurity policy advisor for the Joint Chiefs of Staff at the Pentagon. I also teach ethics and cybersecurity at Georgetown University in my spare time.

Meghan Lafferty: What is important to Dentons right now in terms of cybersecurity?

Scott: We are looking at some current projects. We're looking at some AI and automation to reduce the workload on analysts, to surface things that require human attention.

Things like simple phishing, I can automate that away. But there are other phishing and things that come in that are very subtle that do require human eyes and do require someone to run checks. And so that's where we're trying to narrow the gap right now.

What's more important to me right now is organizational, because a law firm isn't a corporation, and Dentons isn't even a single law firm. It's a Swiss Verein that's composed of roughly 50 independent law firms around the world. And so while we do mandate global security policies and standards, we can't mandate technology solutions. 

And so the structure exists for really good commercial and legal reasons, but if I wanna put a new solution in place, I have to sell that solution not just once, but repeatedly to different sets of leaders who are balancing different competing demands, and that's harder than the technical work a lot of times.

Meghan: Have you found the best strategies to do that?

Scott: It's a lot of talking to leaders and trying to understand what their major challenges are, how security can assist them in solving those challenges, and how we can do that at a global scale when dealing with different people, different cultures, different technology bases, things of that nature, so it can be very challenging. 

So there’s a lot of influence involved, and that's really the starting point.

Meghan: What is your process for staying ahead of the curve yourself?

Scott: I pay attention to what's going on in the news. I pay attention to new technologies. I listen to podcasts. I pay attention to people like Gartner. 

Sagetap helps. There's a lot of very innovative and new vendors in your vendor pool. Being exposed to them gives us a lot more information on where the industry is moving, how it's moving, and what new solutions are coming on the market.

Meghan: Is there a challenge out there that you think deserves more attention than it's getting right now?

Scott: I would say there's a growing Tier 1 analyst problem, because right now we're automating away the Tier 1. Everybody's celebrating that. It's a great thing. It's real efficiency. What nobody's discussing is that Tier 1 is where senior analysts come from. 

We don't just pop out senior analysts with those skill sets. They learn that by being junior analysts and by learning pattern recognition and building the instinct to look at something and see when something feels wrong.

And if we delete that entry-level rung, we get a 5- to 10-year gap where no one's qualified to supervise the automation or manage escalation out of these systems that have eliminated Tier 1.

And I don't think the industry's got a plan for that, and I don't think vendors are thinking about that right now.

Meghan: Before you were on Sagetap, what did your typical vendor research and discovery process look like?

Scott: Our process before Sagetap was traditional. It still is to a certain extent. 

We build requirements documents. We get a clear understanding of what the problem is. We do market research to identify vendors. We set up meetings. We narrow it down to two or three vendors that meet the requirements we're looking for, and we run proofs of concept, proofs of value. That's when we make the acquisition decision.

I think the biggest friction point that we run across in the traditional process is vendor selection because, quite honestly, if that vendor isn't in my analyst scans or in my peer network, then it doesn't exist to me because I don't know about it.

You can go look at marketing web pages for these things, and they all say about the same thing. And so you end up going through several meetings a lot of times just to narrow down the field to figure out that this product isn't a fit.

Meghan: So you decided to get on Sagetap, hopefully to solve some of those issues. How has your Sagetap experience been?

Scott: I think it's been a good experience. What changed is the top of the funnel. 

I've done roughly 20 anonymized pitches through Sagetap. I've done proofs of value with four of those. We've gone to acquisition with two of them. And so obviously that has been successful for us. 

And the mechanic that makes that work is actually the 30-minute meeting cap. That really forces a vendor to get straight to the value proposition and the important details. And if they can't get that to you in 30 minutes, it's a clean cut. You don't have a relationship to manage. You can move on. You can go look at a different vendor.

I think that's really valuable and worth something.

Meghan: Let's talk about the ones that have been successful. Tell me about the vendors that you’ve found and what your experience has been like with them.

Scott: The main one I would talk about is KnowBe4, which is a phishing simulation and security awareness company. 

We did have a vendor in-house that we were already using, but we wanted to go out and evaluate some different products because of some of the shortcomings that vendor had.

As I said, we work in 90 different countries around the world, so you have to try to do these things in native language because that changes their perception, that changes their awareness. 

And so that made a big difference for us, and that's why we eventually went with KnowBe4, because of that robust language support they had. And some other customizations and features they had on the platforms. And so from my perspective, that made a huge difference.

For me, when I evaluate vendors, I look at it from four questions. First, does it close a gap that I'm actually concerned about and that has been identified to me through some real means.

Second is can the project actually integrate into my environment, because I'm in a very weird, complex environment.

My third question is usually does it add or reduce workload for my SOC, because we have a very small team.

And then finally, do I have the resources to deploy, integrate, and manage that in a reasonable timeframe.

For KnowBe4, it was a combination of ease of integration, compatibility with our environment, and the language support that really sold it for us.

Meghan: If there is another leader who is like you, but they're not on Sagetap yet, what would you tell them?

Scott: I would tell you it's worth trying because you're gonna get exposed to a lot of different vendors.

The way Sagetap works is you can essentially put up what your current initiatives are, and then you can filter the vendors that are on the platform for the ones that actually are focused on that.

But on the other side of the coin, sometimes vendors will see your initiative and will reach out to you and ask you to come to their pitch session too, so that's always nice. In at least one of those cases, we did go to a POV with that vendor.

It's put vendors in front of me that I wasn't gonna find on my own, and that cuts the cost of finding out whether those vendors actually matter to me, and that is definitely worth something.

Continue Reading
Access the entire report with exclusive data and actionable insights from your peers.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Get Started

Join over 4,000+ startups already growing with Sagetap.