Writing index
INTERVIEW — 23 Apr 2024

CISO Interview Series

A conversation with the Swiss Cyber Institute on becoming a CISO by accident, what the role really demands, and the workforce shortage seen from the inside.

Swiss Cyber Institute
Published in
Swiss Cyber Institute
Role
Interviewee

The career started at Telenor Montenegro on an IT helpdesk, with a chance assignment alongside the company's information security manager. That manager argued from day one that InfoSec was a necessary and genuinely interesting path, and the switch to information security engineer followed quickly. From 2G to 5G it was an education in how data moves and how the security around it evolves — and it set a lasting habit of mentoring as many potential InfoSec professionals as possible, in return.

What followed was a deliberate sequence of harder environments: building an information security management system from the ground up at Air Serbia, moving to the software company DevTech to stay close to the newest technology and modern practice, then to Germany leading a security team in the online travel industry and protecting the data of millions of travellers, and finally into healthcare as CISO of Kaia Health — the first role carrying responsibility for highly sensitive health data across two continents, with an ISMS built from an entirely new perspective covering incident management, GRC, data privacy, physical security, awareness and secure product development.

On the role itself: what sustains a CISO is a cold head in hot situations, never trading security away for operational efficiency but making both work through compensating controls, acting as an enabler rather than the person who says no, being the voice of reason and a strong communicator, and never stopping learning. The specific challenge at a company like Kaia is raising security and privacy posture to corporate level inside a startup culture — solved through adaptation, education and communication. On the global shortage, the honest answer is that it was never felt personally, but the calls asking for good candidate recommendations never stop: if every current InfoSec professional brought just one person into the field, the compound effect would be enormous.

Key findings

  • 01Entered InfoSec by chance from an IT helpdesk role at Telenor Montenegro, convinced by the company's information security manager.
  • 02Built an ISMS from the ground up at Air Serbia, then moved through DevTech and an online-travel security team in Germany protecting millions of travellers' data.
  • 03As CISO of Kaia Health, responsible for highly sensitive health data across two continents: incident management, GRC, data privacy, awareness and secure SDLC.
  • 04CISO success factors: a cold head under pressure, no security-for-efficiency trades, being an enabler rather than a blocker, strong communication, continuous learning.
  • 05The hardest startup challenge is raising security and privacy posture to corporate level — through adaptation, education and communication.
  • 06Awareness is not keeping pace with the growing internet user base, and national programmes differ wildly between regions.
  • 07On the workforce shortage: if every current InfoSec professional brought one person into the field, the collective impact would be enormous.
More interviews & press