Hello and welcome to The CISO Perspective. I'm Berthold Kerl, CEO of KuppingerCole, a leading analyst firm based in Europe and focused on identity and cybersecurity. In this series, we speak with leading security executives about how they think, how they lead, and how they deal with the decisions that shape cybersecurity today. For this very first episode, let me briefly explain why we created this format. Cybersecurity clearly is a leadership topic. The most useful insights do not come from university or books. They come from the people who carry real responsibility.
With the CISO Perspective, we want to make these insights accessible to a broader audience, from young professionals and students to experienced practitioners or business leaders, basically everyone who's interested. We also want to highlight the KuppingerCole Cyber Council because many of its members bring exactly the practical perspective this series is meant to share. For our very first episode, I'm very pleased to welcome Heinrich Voelker, Chief Security Officer of Deutsche Boers Group.
Heinrich, it's great to have you here and thank you for joining me for this very first episode of The CISO Perspective. Yeah, thank you for having me.
So, it's a pleasure and an honor to be the first one. Yeah.
Heinrich, you and I, we worked together many years ago at Deutsche Bank. At that time, Deutsche Bank was one of the first large organizations, certainly in Germany, that had to build information security and access governance in a much more structured way than before. Not always voluntarily, more because of strong pressure from regulators on banks across the globe. I'm sure many of our viewers would like to understand your personal journey a bit better.
So, looking back, how did you get into security in the first place? Yeah, thanks, Bertolt. Absolutely, when I entered my IT career, that was not a natural choice. It was actually pretty much not known. I had the opportunity to build large-scale organizations as a CIO and CTO function. I remember very clearly, it was just right after the big hit of the financial crisis where the board member at the time for IT, Vera Visionary, said, Heinrich, do something for information security. This is going to go big.
And it, as you rightfully say, it didn't exist at the time pretty much. And so, what pulled me really in was, one, that vision, and second, it was a complete empty field, meaning building something really from scratch. That was quite appealing. And I think there were a few role models, certainly not in Germany, perhaps in the US, they were a little bit further advanced. What did that time teach you and which lessons from that period still matter today?
Yeah, it still matters very, very big. And you mentioned that before. Security is multifaceted. It's driven by, first of all, securing companies, absolutely. Permanently proven by adversaries, whether you do your job right. And thirdly, by regulation. And I think that is some sort of the permanent balance. You would need to get right. And you need to stay vigilant against what really matters. There's no mercy on security. And for that reason, I think that is key. Let's stick to today's role of a security leader, which is much broader than it used to be.
Many think of a technology savvy person first, when they think of a security leader. Do you have to be a nerd or perhaps even a former hacker to be qualified for this role? It might help a bit, but you need to make sure that you elevate at the right point in your career. And what is really key is to have the capability to get a really good understanding of technology and security matters, while be able to translate this on board, supervisory board level, into something that resonates with them. Yeah.
So, yeah. Can you elaborate a little bit? What does a good security leader or good security leadership look like today in practice?
So, in practice is, of course, a people business, as many. But what makes a big difference to the IT, for instance, in general, is really, you get your success feedback pretty much directly.
Because, as I mentioned before, there is no mercy. If something is not really covered, it's really, you will be proven that you have an issue very, very quickly. And for that, you need to have the right team with the right skill sets, with the right deep knowledge, and as well, the ones who can aggregate up so that you get the buy-in from the business, from the boards, that you create the common understanding around the importance of security. Yeah.
So, we touched on the early days back, or whatever, 10, 15 years at Deutsche Bank. Today, many CISOs are under pressure from very different angles now. I think we've seen growing dependency on external providers, that even combined now with the geopolitical challenges, but also growing complexity inside their own security environment.
So, I think we were all used to look at the obvious adversaries, China, Russia, North Korea. But today, the world is even more complex. And we could observe that at the recent Munich Cyber Security Conference, that the CISOs are now looking more and more to Europe, promoting technological sovereignty. A recent survey amongst your peer members in the Cyber Council showed that 90% are moderately or significantly concerned about dependency.
Now, the question, against that background, what does digital or technological sovereignty mean in practice for you as a CISO here in Europe, located in Europe? Yeah, definitely, an upcoming topic. I think we had dependencies all along. I think we both created, as well, some sort of, along our career, really, a global economy. We always pick best solutions from wherever they come. There were here and there, of course, a little bit of background, where the technology is originating from, and all this. But it was really the question of who's leading in terms of the protection.
On the other side now, over the recent years, sovereignty comes in as one of the topics which are important for us, the confidentiality, integrity, availability. So you can probably count this in. And it gets elevated through the cloudification of pretty much all of IT, because, yeah, we had database systems always from the US, but now it's really a little bit of different level. For that reason, the CISOs become one element, but not the only one.
It's really a strategy question for IT overall, for compliance, for IT governance, and for CISOs in combination to find the right path forward, and to see what kind of concentration risk a company has with all the technology dependency. It's new on the agenda, absolutely. But at the moment, we need to admit that technology leadership is, and has always been, very clearly distributed across the world. Yeah. And I think, obviously, all organizations carry a certain history with them. So they have now implemented over years, many tools from providers across the globe, right?
And I think it's not possible to exchange them all at once, right? And against what? That is as well the question.
Europe is, US is, obviously, and has always been in IT, very dominant, and most solutions coming from there, and they're driven by the market. So by the need of the companies, combined with some competition on the price levels, a typical market ingredients of value against price, Europe now coming up and stepping up would need to compete on exactly that level. And what we see is more regulation in order to control the environment. But we all know, market is typically rather the better measure to respond than purely by regulation.
Where do you currently see the top hurdles which hinder people, hinder CISOs to go for newer European vendors, startups, etc.? So what, I mean, because what I'm seeing is, everybody says, oh, yes, we need to become much more independent and much more sovereign, etc. But then in practice, I'm seeing quite little adoption.
Yeah, it's all around the capabilities. So obviously, the big incumbents have invested enormous amount of money, enormous funds, into very, very sophisticated capabilities for now. And any company that want to compete here would need to do some equal investments. And I think these are big hurdles. And until the capabilities are not really on a same level, it's going to be hard for someone who picks out of the choices of the global market to simply say, you know what, I'd rather go now for a half mature European solution, because I think that would be difficult.
And that feeds back to what I earlier said, an individual subject like security would never do this. I think we have IFP processes, and we obviously run for the best solution that fits to the problem. And then it requires wider considerations from other disciplines and across a company if someone want to go for other solutions simply to promote, like as well, European technology. But it's fair to absolutely include startups and newcomers into the market and all this and really have a close eye on them in order to support.
One key requirement I remember people saying would be to, as a recommendation to the startups, that they must be able to integrate with the bigger platforms. Yeah, that is typically valid, at least for highly regulated companies like financial institutions. You need to have always from highly dependent technologies, an exit strategy, a plan B, so to speak. And that automatically brings you into an architecture, overall architecture, where you have multiple choices, where you can support multiple platforms and all this.
So overall, pretty much for everybody in the market, multi-cloud, multi-platform is definitely the way to go. Propriety doesn't help here a lot, because then the exit strategy and a stressed exit or something like this would be pretty much too expensive and too long to execute.
Yeah, I think the other aspect of that is that many large organizations have built up security over many years. We already mentioned that. And they ended up with a ton of tools, overlapping functions and a lot of integration work, which of course causes complexity, causes effort, costs. What's your view on that?
Yeah, you are 100% right. I think over the past years, we have seen a market of the security tooling, which typically operates in quite niches. And because a company could have been extremely successful solving a single security problem, bring it to the market. And it was then on us to stitch all this together and get a quite big, we call it security tool metrics ramped up. I think this is now somehow at the tipping point, because on the other hand, we see over the past years, a lot of cloudification and security had two major efforts over the past years.
One is to, of course, secure as well cloud footprints equally good. But second, cloudify as well the security. Because what we see in the market is that more and more pure on prem toolings and all this are being sunset right now and not being supported and further developed as we see that with others. So we had exactly these double efforts of moving security in the cloud, even supporting on prem here, and then on in a multi cloud environment.
And what we have seen over the past very few years is that more large platform providers are coming up and strong players over certain capability are now building up as well complete platform. So there's a wider variety of larger platforms available right now versus the individual kind of best of breed situation that the race is not complete yet. I think we're exactly at the point where this comes up. There are large benefits out of out of the platforms, because typically they integrate quite nice.
You need less integration efforts and have, as an example, if you take all of your protection tools and if detection response want to investigate something, they have pretty much all the information from all the protection tools from your ideally automated penetration testing, reteaming, and all this at their fingertips and have them all information available in one platform. I think this is quite strong and I could see quite a number of benefits.
Of course, always need to keep in mind, don't put all eggs into one basket, because then again the dependency that this one platform is going to cover all your security needs is extremely important. So it's a balance and the race is not over. I think when you look ahead over the next few years, what do you think will matter more for the CSOs? More control over dependencies, less complexity, better alignment with business goals or perhaps all together or something else?
Yeah, it's as well that not only in cloud platforms where we have the principle of shared responsibility, this now enters as well the space of security. So it's much more shared responsibility with two big platform providers and the CSO. So it needs to be not only a trust, it's not only a question of trust, it's as well a question of rock-solid capability. And I think that is what I see is being the near challenge, where to draw the line, how to build up the shared responsibility as well on a security level. Thank you for your insights so far.
Before we close, I'd like to do a short quickfire round. Yeah. So I will ask you three short questions and I would prefer your answers to be brief and spontaneous. Okay. So first question.
Actually, it's two questions. What is the one topic in cybersecurity that gets more attention than it deserves today? And one area that deserves more attention than it gets? So very clear answer is we tend to have too much focus on pure regulation. I think that is overrated, that regulation and fulfillment and compliance regulation will actually make us more secure.
We would need to probably have a little bit of influence as well that this doesn't go overboard because then the focus of the real, what really matters to first and foremost, fight as well adversaries and detect vulnerabilities on our end gets out of sight. What is the area that deserves more attention? More attention is practical testing. We have a lot of controls in place and we pile one control over the other, but it is the overall architecture, how it's being configured, how it's being implemented, the IT.
We need to have this more actually tested in order to find the right potential and vulnerability. Yeah. Thank you. Thank you for that. So the next question goes more into the direction of management, the board. I'm sure you had now over the past couple of years enough time to educate your existing board members, but let's assume you get someone completely new. If you had one minute with that person that perhaps does not fully understand cybersecurity yet, what is the one thing they absolutely need to get right? Yeah. First of all, thanks.
Happy I have and had boards which have a really great understanding. So that's great. And what we all do as CISOs is to tell how terrible the world is. So to imagine you don't invest, look around you, what happens in the industry and how dependent you are from IT. So it's all around risk and reward. That would it be. But of course, the reward piece needs to be big as well. We cannot only working through fear. Yeah. Thank you. Last question. And of course, you and I, we are quite seasoned in the meanwhile. So what would your advice be to someone at the beginning of a cybersecurity career?
So what capabilities does someone need? What should they start working on now? Okay. First of all, congratulate you made the right choice. Security is here to stay and it's going to continue to develop fast and stays interesting. So keep up the interest and keep up to date is definitely absolutely key. Building up a career would be really come out of really a technology niche without some technology background, solid technology background. I think until now, it's still a little bit difficult. So stay interested in all this in technology and then keep up with the developments.
And in order to do so, stay connected in the market. When we work in large corporates, for instance, there's always a tendency that there's so many demand internally and all this, you sometimes miss to raise the view and look across and connect with others and exchange experience. So stay hungry in terms of your knowledge. And then last but not least, and that connects nicely what we discussed. Always look in how can you transport what we want to achieve, not necessarily the technical details to the businesses, to the boards, to the other decision makers in the corporate.
I think that's, in my opinion, often underestimated that it's very obvious that the security leaders need to be tech savvy, but they also need to be business people. They need to be able to talk business language and understand their objectives and balance everything. And I think that is often underestimated, I believe. By the way, is there, does there one difficult decision come to your mind, which you had to take that taught you an important lesson? Can you think of one? It's really, it sounds probably a little bit easy, but it's really risk decisions.
These are typically fired with, oh, here we have a risk. And risk has a problem that once people are tabling it and put it up, it's extremely difficult to ignore it. So you either need to say, but formally you take the risk or you put a measure in against this. So that is, that's key. What kind of risks are you ready to take and take them? Because if you want to address every risk, which we have in cybersecurity through another measure, it will explode. The cost will explode. People will not follow. Yes. Please be prepared and be ready to take risks, which you are ready to take. That's key.
Henry, thank you very much. What I take from this conversation is better understanding how close the leadership, the leadership technology management are now linked also together in cybersecurity.
And yeah, I think that's a very unique challenge. And as you said, it is a future playing field, which will not go away anytime, anytime soon. Thank you very much for being the very first guest on the CISO Perspective. So I'm very glad for that and also for helping us launch this series. It was a great pleasure. And all of you, thank you very much for watching. We'll be back soon with the next episode where we continue our conversations with leading security experts on how they think, decide and lead. Until next time. Thank you for joining us. Thanks. Bye.