Career profile
Matt Kimpel
Chief Information Security Officer, Magna5
- Current role, per sources checked 7 October 2026
- 1 January 2025
Matt Kimpel is the Chief Information Security Officer of Magna5, appointed effective January 1, 2025.
Career path
Kimpel's time at Magna5 began as a NOC Engineer at NetServe365, a company Magna5 acquired in 2017.
He advanced through engineering and cybersecurity roles at Magna5 before becoming Director of Cybersecurity and Engineering.
In March 2022, while serving as Director of Cybersecurity and Engineering and after 15 years with the company, he earned the CISSP certification.
Magna5 promoted him to Chief Information Security Officer effective January 1, 2025, a role in which he leads the company's cybersecurity strategy, threat protection and compliance efforts for clients across industries.
He holds a degree in Network Security & Computer Forensics from Pittsburgh Technical College and is certified as a CISSP and CISM, along with multiple Cisco certifications.
Remit and public commentary
As CISO, Kimpel is responsible for Magna5's cybersecurity initiatives, protection against the latest threats, and facilitating regulatory compliance for clients in education, healthcare, government, financial services, manufacturing and other sectors.
Commenting on a data-theft incident at Novo Nordisk, Kimpel said that if claims of months-long attacker dwell time hold up, "the real story is dwell time," and that extortion and intellectual property theft are now often combined in such incidents.
He said pharmaceutical security programs should keep emphasizing identity hardening, vendor risk and monitoring of privileged research environments rather than relying only on perimeter defense.
Discussing the same breach for Dark Reading, Kimpel said developers and development environments have become high-value targets because they hold standing access to source code, build and deployment pipelines, and the credentials those systems use.
He described access to a code repository as comparable to an attacker obtaining a building's architectural plans rather than merely opening a file cabinet.
He said AI-assisted development is increasing the volume and speed of code creation while creating new opportunities for sensitive data and secrets to leak through unsanctioned tools.
Kimpel recommended that organizations start by inventorying their non-human identities, then eliminate long-lived secrets, scope access aggressively, and rotate credentials on a real cadence rather than on a calendar schedule.