{"id":134388,"date":"2025-05-15T18:31:19","date_gmt":"2025-05-15T17:31:19","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/?p=134388"},"modified":"2025-06-23T10:01:14","modified_gmt":"2025-06-23T09:01:14","slug":"editors-question-five-leaders-talk-eu-regulations-and-the-cyberthreat-minefield","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2025\/05\/15\/editors-question-five-leaders-talk-eu-regulations-and-the-cyberthreat-minefield\/","title":{"rendered":"Editor\u2019s question: SEVEN leaders talk EU regulations and the cyberthreat minefield"},"content":{"rendered":"\n<p>For Chief Information Officers across Europe, the digital transformation journey presents a complex balancing act. The escalating landscape of cyberthreats, coupled with increasingly stringent EU regulations, demands a robust approach to both compliance and resilience. Yet, the imperative to innovate and drive business value through digital initiatives remains paramount. How can CIOs effectively navigate this intricate environment, ensuring adherence to evolving legal frameworks and bolstering defences against sophisticated attacks, all without stifling the momentum of crucial digital transformation projects?<\/p>\n\n\n\n<p>Our EU CIO Editor puts this critical question to six leading voices in the European technology landscape. Join us as we unpack the key considerations for ensuring compliance, building resilience and fostering innovation as integral components of a successful digital transformation strategy in the European Union.<\/p>\n\n\n\n<p><strong><em>Q: In the context of tightening EU regulations and increasing cyberthreats, how can CIOs ensure compliance, resilience and innovation without slowing down Digital Transformation initiatives?<\/em>&nbsp;<\/strong><\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Martin Schirmer, GVP NEMEA at Cloudera, says: <\/h3>\n\n\n\n<p>CIOs are under growing pressure to accelerate digital transformation while navigating an increasingly complex regulatory and threat landscape. Technologies like AI are unlocking powerful new ways to automate, analyse and innovate, but their deployment comes with high stakes. In this climate, innovation can\u2019t be allowed to outpace governance.<\/p>\n\n\n<div class=\"wp-block-image is-style-rounded\">\n<figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"800\" src=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Martin-Schirmer.jpg\" alt=\"\" class=\"wp-image-134404\" style=\"width:272px;height:auto\" srcset=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Martin-Schirmer.jpg 800w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Martin-Schirmer-300x300.jpg 300w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Martin-Schirmer-150x150.jpg 150w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Martin-Schirmer-768x768.jpg 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure><\/div>\n\n\n<p>With new regulations such as the EU AI Act and DORA coming into effect, the risks extend beyond fines or audits. A single misstep in security or compliance can damage operational resilience, erode customer trust and stall strategic momentum. With the uncertainty surrounding today\u2019s digital economy, trust is everything. That\u2019s why cybersecurity, compliance and governance can\u2019t be treated as afterthoughts. CIO\u2019s must ensure they must be worked into the innovation process from the outset.<\/p>\n\n\n\n<p>The good news for CIOs is that compliance doesn\u2019t have to slow innovation down. In fact, it can be a catalyst for better, more sustainable progress. CIOs who embrace security and governance as core components of their digital strategy set their organisations up for long-term success. This mindset shift can turn regulatory requirements into a booster for innovation, not a roadblock.<\/p>\n\n\n\n<p>One of the biggest challenges CIOs face as a result of these new technologies is the explosion of data across environments. AI relies on vast amounts of data that is created, stored and processed across on-premises systems and multiple cloud platforms. Managing this complex and fragmented landscape securely and consistently is no small feat &#8211; which is why a unified data platform is becoming increasingly essential. By providing a single, secure layer to manage, govern and access data, these platforms help simplify compliance, enable real-time decision-making, and reduce the risk of data silos or policy gaps.<\/p>\n\n\n\n<p>However, the path to resilience and innovation isn\u2019t just technical &#8211; it\u2019s also cultural. The most successful CIOs empower people, as well as platforms. That means fostering openness to change, promoting collaboration between generations and cultivating an environment where data is seen as a shared strategic asset &#8211; not just a technical concern. Unlocking AI\u2019s full potential starts with democratising access to quality, trusted data and embedding a governance mindset across teams.<\/p>\n\n\n\n<p>Ultimately, success comes down to building and maintaining trust. If CIOs ensure security and governance are embedded into every new process and technology rollout, they can remain compliant, confidently push forward with innovation, and continue to transform at speed.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<h3 class=\"wp-block-heading\">Nick Harris, CISO of&nbsp; Assured, says: <\/h3>\n\n\n\n<p><br>CIOs are stuck in a three-way tug of war. Cyberthreats are more advanced. Regulators are tightening the screws and with different EU countries interpreting DORA differently and the UK&#8217;s Cyber Security and Resilience Bill around the corner, the board still expects digital transformation to move faster than ever. Can the CISO have the answer? Always, security should be the focus; but compliance can be the outcome (not the goal) and unlock these challenges.<\/p>\n\n\n<div class=\"wp-block-image is-style-rounded\">\n<figure class=\"alignleft size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"923\" src=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Nick-J-Harris4194-2-1024x923.jpg\" alt=\"\" class=\"wp-image-134389\" style=\"width:305px;height:auto\" srcset=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Nick-J-Harris4194-2-1024x923.jpg 1024w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Nick-J-Harris4194-2-300x271.jpg 300w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Nick-J-Harris4194-2-768x693.jpg 768w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Nick-J-Harris4194-2-1536x1385.jpg 1536w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Nick-J-Harris4194-2-2048x1847.jpg 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><br><\/figcaption><\/figure><\/div>\n\n\n<p>So how can we do that without causing friction to business?<\/p>\n\n\n\n<p><strong>Assess once, report many<\/strong><br>Use tooling that maps your controls across NIS2, DORA, GDPR the UK Cyber Security and Resilience Bill and whatever lands next. This way you assess a control once and report many times. When a new regulation drops, it can be added to your current control mapping, without needing to start from scratch. Audit fatigue is real and I feel for IT control owners having to share evidence repeatedly. Smart GRC platforms let you prove once, report many times.<\/p>\n\n\n\n<p><strong>Model the real threats<\/strong><br>Threat modelling to determine how best to frame the security is essential and should cover business attractiveness to attackers as well as regulatory risk, operational downtime, reputational damage and third-party exposure. Your model needs to factor brand impact and customer churn to tell the whole story.<\/p>\n\n\n\n<p><strong>Drop the tech. Focus on value<\/strong><br>The board does not care about patch cycles or CVSS scores. They care about how risk affects delivery, growth and reputation. This is your chance to show cybersecurity as a revenue generator as well as loss preventer. Granted its more applicable to B2B but consumers can care about trust in their data and frame the conversation around:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Regulatory fine avoidance (e.g. \u2018This investment helps prevents \u00a317 million in potential GDPR exposure\u2019)<\/li>\n\n\n\n<li>Operational continuity (e.g. \u2018This reduces the risk of supply chain downtime which would delay delivery by two weeks and cause \u00a32 million of lost revenue\u2019)<\/li>\n\n\n\n<li>Revenue protection (e.g. \u2018A breach here risks losing our top five enterprise customers worth \u00a38.5 million annually\u2019)<\/li>\n<\/ul>\n\n\n\n<p><strong>Cut friction, not corners<\/strong><br>Security that slows people down gets bypassed. Prioritise controls that work behind the scenes or enhance user flow. Single sign-on. Windows Hello so you can go passwordless. Device trust. Automated policy enforcement. This gives teams the freedom to move fast without leaving the door open.<\/p>\n\n\n\n<p>Done right, security keeps you safe and the side-effect of compliance shows you&#8217;re consistent, prepared and serious. It makes conversations with the board easier. It strengthens customer confidence. It gives transformation a solid foundation.<\/p>\n\n\n\n<p>The organisations that get this right are not the ones slowing down to tick boxes. They are the ones moving faster because security is part of the engine, not something strapped on the back.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<h3 class=\"wp-block-heading\">Matt Riley, Director for Information Security, Sharp UK\/Europe, says: <\/h3>\n\n\n\n<p>In the context of tightening EU regulations and increasing cyberthreats, CIOs face the challenging task of ensuring compliance, resilience and innovation without slowing down digital transformation initiatives. The key to achieving this balance lies in putting people first. Team members can ultimately be a company\u2019s strongest assets or weakest links. Without their buy-in, ensuring compliance and resilience while encouraging innovation is an impossible task.<\/p>\n\n\n<div class=\"wp-block-image is-style-rounded\">\n<figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"513\" height=\"513\" src=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Matt-Riley.jpg\" alt=\"\" class=\"wp-image-134390\" style=\"width:333px;height:auto\" srcset=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Matt-Riley.jpg 513w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Matt-Riley-300x300.jpg 300w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Matt-Riley-150x150.jpg 150w\" sizes=\"auto, (max-width: 513px) 100vw, 513px\" \/><\/figure><\/div>\n\n\n<p>People often do what they want to do, not necessarily what they need to do. Therefore, a CIO&#8217;s role is about building a culture where people want to contribute to compliance and resilience. This involves highlighting the importance of processes and procedures and telling relatable stories that resonate with team members. For instance, recent events involving companies like M&amp;S and Co-Op serve as powerful examples of how cyber incidents can impact individuals and their roles. By sharing these stories, CIOs can help build a sense of \u2018want\u2019 rather than just \u2018need\u2019 among team members. Once this culture is in place, people become proactive in their approach, which leads to a speeding up of digital innovation. They understand the reasons behind the necessary steps and can contribute to the success of the initiatives and this proactive mindset is crucial for navigating the complexities of increasing regulations and cyberthreats.<\/p>\n\n\n\n<p>With the growing number of regulations, it is also essential to demonstrate the positives and tell related stories. For example, CIOs can highlight how being early adopters of new regulations can provide a competitive advantage over competitors. This positive approach helps in gaining buy-in for the necessary changes and investments in technology, training, and leveraging cloud solutions.<\/p>\n\n\n\n<p>A practical example of this approach can be seen in our marketing team at Sharp. They engage, are willing to learn &#8211; and take a proactive approach, making innovation quicker and easier while still complying with various pieces of legislation. This demonstrates that with the right culture and mindset, compliance and resilience can go hand in hand with innovation.<\/p>\n\n\n\n<p>Investing in employee training and awareness is another critical step as human error remains one of the leading causes of cybersecurity breaches. In fact, according to Sharp\u2019s own research of over 11,000 employees in Europe, including 1,000 in the UK, almost half (43%) haven\u2019t had any form of cybersecurity training over the past year and 16% have never received any at all, highlighting its importance. To mitigate this risk, CIOs must prioritise employee training and awareness programmes.<\/p>\n\n\n\n<p>Overall, CIOs can ensure compliance, resilience and innovation without slowing down Digital Transformation initiatives by putting people first. Building a culture where team members want to contribute to compliance and resilience, sharing relatable stories, and demonstrating the positives of new regulations are key strategies. With this approach, technology, training, and leveraging cloud solutions can follow, making it easier to gain buy-in and achieve success.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<h3 class=\"wp-block-heading\">Paul Inglis, General Manager of EMEA at Ping Identity, says: <\/h3>\n\n\n\n<p>As cyberattacks grow in frequency and sophistication, and as regulations &#8211; particularly across the EU &#8211; become more demanding, CIOs are under mounting pressure. For organisations in high-risk sectors like financial services, manufacturing and healthcare, achieving compliance while maintaining innovation is no longer optional &#8211; it\u2019s a strategic imperative. The key lies in strengthening digital operational resilience.<\/p>\n\n\n<div class=\"wp-block-image is-style-rounded\">\n<figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1000\" height=\"1017\" src=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Paul-Inglis-GM-EMEA-upscaled-1.jpg\" alt=\"\" class=\"wp-image-134392\" style=\"width:323px;height:auto\" srcset=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Paul-Inglis-GM-EMEA-upscaled-1.jpg 1000w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Paul-Inglis-GM-EMEA-upscaled-1-295x300.jpg 295w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Paul-Inglis-GM-EMEA-upscaled-1-768x781.jpg 768w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure><\/div>\n\n\n<p>Central to this strategy are Identity and Access Management (IAM) and Zero Trust security models. These have evolved from technical solutions into strategic enablers. IAM not only secures access to sensitive systems but also supports compliance through real-time monitoring and incident response. When combined with a Zero Trust approach &#8211; based on the principle of \u2018never trust, always verify\u2019 &#8211; they help organisations adapt to the new threat landscape and regulatory environment.<\/p>\n\n\n\n<p>The increasing reliance on digital systems has amplified both efficiency and risk. In sectors like financial services, even brief downtime can be disastrous &#8211; causing unauthorised access, customer lockouts, or data breaches that erode trust and invite regulatory scrutiny. In this high-stakes context, regulatory frameworks like the EU\u2019s Digital Operational Resilience Act (DORA) are both a challenge and an opportunity: a catalyst for organisations to build resilience, maintain customer confidence and accelerate digital transformation.<\/p>\n\n\n\n<p>Converged IAM solutions are particularly well-suited to this task. By embedding identity and access controls into the core of digital infrastructure, they enhance both security and compliance. For example, DORA mandates timely reporting of IT incidents. IAM systems with behavioural analytics and threat detection can identify suspicious activity &#8211; such as credential misuse or unusual login patterns &#8211; then trigger automated responses, notify internal teams and regulators and generate full audit trails. This proactive posture not only meets compliance requirements but also strengthens operational readiness.<\/p>\n\n\n\n<p>Moreover, IAM and Zero Trust frameworks provide a foundation for scalable, future-proof security architecture. As organisations continue to expand cloud adoption, integrate AI tools, and enable remote workforces, secure identity becomes the linchpin of safe and agile operations. For CIOs, aligning cyber resilience strategies with regulatory obligations is no longer just about protection &#8211; it\u2019s a driver of trust, innovation, and long-term business growth.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<h3 class=\"wp-block-heading\">Tom Ashcroft, CISO of Unit4, says<strong>:<\/strong><\/h3>\n\n\n\n<p>In a world with AI being pushed on all fronts further increasing the rate of change, CIOs across Europe face a multifaceted challenge: driving digital transformation while ensuring compliance with tightening regulations which are all designed to force companies to act on increasing cyberthreats.<\/p>\n\n\n<div class=\"wp-block-image is-style-rounded\">\n<figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"874\" height=\"827\" src=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Tom-Ascroft_CISO_Unit4-cropped.jpg\" alt=\"\" class=\"wp-image-134393\" style=\"width:353px;height:auto\" srcset=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Tom-Ascroft_CISO_Unit4-cropped.jpg 874w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Tom-Ascroft_CISO_Unit4-cropped-300x284.jpg 300w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Tom-Ascroft_CISO_Unit4-cropped-768x727.jpg 768w\" sizes=\"auto, (max-width: 874px) 100vw, 874px\" \/><\/figure><\/div>\n\n\n<p><strong>Work as a cohesive collective across your entire organisation to embed compliance into transformation from the start<\/strong><\/p>\n\n\n\n<p>Legal teams must be scanning the horizon and understand what is coming next. CIOs need to form tight alliances across all departments to ensure that information is converted into actionable items. Compliance should never be treated as a check-box exercise or an afterthought. It must be integrated into every stage of digital initiatives.<\/p>\n\n\n\n<p><strong>Embrace Secure-by-Design architectures<\/strong><\/p>\n\n\n\n<p>To counter rising cyberthreats while maintaining transformation speed, CIOs must modernise infrastructure, understand their unique attack chains and apply tailored security principles. There is no universal solution &#8211; each environment has its own weaknesses. Strong foundations remain key: know your estate and manage assets to ensure clear roles, responsibilities and ownership. A business-aligned risk management process provides direction.<\/p>\n\n\n\n<p><strong>Leverage automation and AI for risk and compliance &#8211; but make sure the brakes work before going too fast<\/strong><\/p>\n\n\n\n<p>Automation is a CIO\u2019s ally in managing complexity. AI-driven governance, risk and compliance (GRC) platforms can continuously monitor for regulatory changes and detect early signs of non-compliance or threat exposure. Automated controls validation, data mapping and policy enforcement reduce manual overheads while improving accuracy and audit readiness. However, with AI it is paramount to ensure the basics are in place first with correct Access Control, Data Labeling, Data Loss Prevention and overarching Governance to ensure that no sensitive data is exposed.<\/p>\n\n\n\n<p><strong>Drive innovation through controlled experimentation<\/strong><\/p>\n\n\n\n<p>Digital transformation need not be stifled by regulation; if anything, smart governance can be a catalyst. CIOs should foster a culture of innovation within \u2018safe zones\u2019 such as sandboxes, digital twins, or isolated cloud environments. These controlled environments allow rapid experimentation without introducing undue risk. Innovations can be iteratively hardened and scaled once they meet compliance and security thresholds.<\/p>\n\n\n\n<p><strong>Build Cyber Resilience as a strategic capability<\/strong><\/p>\n\n\n\n<p>Cyber-resilience is no longer a defensive posture but a business enabler. CIOs must invest in adaptive capabilities like cyberthreat intelligence, incident simulation and cross-functional crisis playbooks. It is important resilience capabilities get as much attention as Defence-as-Breaches need to be considered a when, rather than an if.<\/p>\n\n\n\n<p><strong>Prioritise data governance and ethics<\/strong><\/p>\n\n\n\n<p>As transformation initiatives become increasingly data-driven, CIOs must address ethical data use and privacy. A well-governed data architecture with clear ownership, lineage, and purpose limitations supports compliance while enabling trusted analytics and AI.<\/p>\n\n\n\n<p>CIOs who proactively align transformation with regulation and resilience will gain competitive advantage. By embedding compliance, embracing security, and empowering innovation, they can lead their organisations with confidence through the twin challenges of tightening EU oversight and a relentless cyber threat landscape.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<h3 class=\"wp-block-heading\">Richard Ford, Chief Technology Officer at Integrity360, says:<\/h3>\n\n\n\n<p>CIOs face the challenge of maintaining compliance and resilience without slowing digital transformation. It comes amid rising regulatory pressure and an evolving cyber threat landscape. The solution lies in reframing cybersecurity as a core enabler of innovation and not an obstacle.<\/p>\n\n\n<div class=\"wp-block-image is-style-rounded\">\n<figure class=\"alignleft size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1022\" height=\"1024\" src=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Richard-pic-cropped-2-1-1022x1024.jpg\" alt=\"\" class=\"wp-image-134400\" style=\"width:356px;height:auto\" srcset=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Richard-pic-cropped-2-1-1022x1024.jpg 1022w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Richard-pic-cropped-2-1-300x300.jpg 300w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Richard-pic-cropped-2-1-150x150.jpg 150w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Richard-pic-cropped-2-1-768x769.jpg 768w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Richard-pic-cropped-2-1-1534x1536.jpg 1534w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/Richard-pic-cropped-2-1.jpg 1843w\" sizes=\"auto, (max-width: 1022px) 100vw, 1022px\" \/><\/figure><\/div>\n\n\n<p>Regulatory compliance has long been one of the key drivers in cybersecurity, in many cases shaping cybersecurity programmes in order to gain and maintain compliance. Sometimes treated as a box ticking exercise, compliance frameworks should form the minimum standard of what we do. Regulatory frameworks, such as DORA and NIS2, have been put in place to harmonise the approach to cyber security across the EU and ensure a healthy level of security maturity and build resilience to attack.<\/p>\n\n\n\n<p>Alongside compliance demands, organisations face relentless cyberthreats. High-profile attacks; particularly in sectors like retail &#8211; highlight the scale and impact of breaches. Cyber-resilience must be built into the business from the start, not bolted on later. That means embedding controls early in the design process and ensuring they evolve as the organisation and its technology stack grows.<\/p>\n\n\n\n<p>The key is implementing controls as frictionlessly as possible. Not just to enable digital transformation efforts but also to discourage users circumventing them and introducing risk. CIOs and security leaders need to encourage working together with stakeholders to understand what they need to achieve, their outcomes, rather than security being siloed and blindly enforced. Security must be the enabler for organisations to help deliver on these outcomes, not a blocker. That is what frictionless security means.<\/p>\n\n\n\n<p>Everyone needs to understand their accountability. Secure-by-design must be the cornerstone of any initiative building cyber resilience into the solution from the ground up. The retrofitting of security controls is a sure-fire way to add friction and either slow or impede efforts to transform.<\/p>\n\n\n\n<p>With the availability of cloud platforms, and the ease of implementing them, the threat of shadow IT and supply chain risks is on the rise. This puts not only data at risk, as it walks out of the organisation into third party platforms, but also the risk of compromise. Third party platforms and integrations are one of the top risks we should be concerned about. Third parties need to be managed, assessed and their risk mitigated.<\/p>\n\n\n\n<p>AI represents a similar dilemma. It offers significant productivity benefits but also presents new security concerns. Tools like ChatGPT can help users and IT teams alike, but if misused, they can expose sensitive data. Too often, users don\u2019t realise that uploading internal information can put it in the public domain. Organisations must provide clear guidance, training and security controls that enable the secure use of AI while protecting corporate data.<\/p>\n\n\n\n<p>CIOs can maintain momentum in digital transformation by embedding compliance and resilience into the fabric of their strategies. By leveraging automation, aligning with business goals and fostering a security-first culture, they can turn regulatory pressure and rising threats into opportunities for sustainable, secure innovation.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<h3 class=\"wp-block-heading\">Ellen Benaim, CISO of Templafy, says:<\/h3>\n\n\n\n<p>Culture is at the heart of any successful digital transformation. When CIOs build a culture where security, innovation, and compliance are seen as partners rather than obstacles, everything moves faster, and more securely. Embedding security from the start gives product and engineering teams the freedom to innovate with confidence. It&#8217;s not about saying &#8216;no&#8217; to new ideas, but about creating the conditions for those ideas to scale safely. One of the most effective ways to do this is by embedding security champions within delivery teams and fostering open, cross-functional collaboration between IT, privacy, legal and business leaders.<\/p>\n\n\n<div class=\"wp-block-image is-style-rounded\">\n<figure class=\"alignleft size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"600\" height=\"600\" src=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/newsletter-Ellen-edited.jpg\" alt=\"\" class=\"wp-image-134443\" style=\"width:352px;height:auto\" srcset=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/newsletter-Ellen-edited.jpg 600w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/newsletter-Ellen-edited-300x300.jpg 300w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/newsletter-Ellen-edited-150x150.jpg 150w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/figure><\/div>\n\n\n<p>With EU regulations like NIS2 and DORA raising expectations, compliance can\u2019t just be a checkbox exercise anymore. It has to be continuous, embedded, and visible. That\u2019s where automation plays a vital role. Automating compliance reporting, KPIs and audit evidence gives leaders real-time insight and helps teams stay focused on what matters: building and delivering value. Whether it\u2019s automating DPIAs or incident response workflows, the right tooling can make compliance a background process, not a blocker.<\/p>\n\n\n\n<p>At the same time, we have to be clear-eyed about the threat landscape. AI-powered attacks are making credential theft, phishing and lateral movement faster and harder to spot. It\u2019s not a matter of if you\u2019ll be targeted &#8211; it\u2019s when. That\u2019s why resilience needs to be baked in from the beginning. An &#8216;assume breach&#8217; mindset means your recovery plans need to be tested, your playbooks rehearsed and your executive teams looped in. Incidents aren\u2019t edge cases anymore &#8211; they\u2019re part of the business reality. Being ready to respond is as important as trying to prevent them.<\/p>\n\n\n\n<p>We also need to ensure that any regulation and security measures supports growth to allow for innovation and development for digital translation initiatives. Cybersecurity should be integrated seamlessly into the business growth strategy, enabling secure innovation throughout the development process. By embedding security into the design and development of new technologies early on, adopting scalable cloud-based protections and fostering a culture of security awareness across all departments can mitigate risks without stifling progress. Close collaboration between IT and the business department is essential to ensure that security frameworks support, rather than obstruct, the deployment of new digital tools, platforms, and processes.<\/p>\n\n\n\n<p>As organisations modernise, security has to scale with them. That means embracing identity-first strategies like Conditional Access, zero-trust architecture and zero-touch provisioning. Done right, these approaches don\u2019t slow teams down, they actually improve the user experience and reduce complexity. People want to get their work done securely, from wherever they are. Our job is to make that seamless.<\/p>\n\n\n\n<p>In the end, getting this right isn\u2019t about choosing between compliance, resilience, or innovation &#8211; it\u2019s about making sure they move forward together. The companies that will thrive in this new era are the ones that treat trust as a product feature, not just a policy. When you build a culture of security, automate the right things and plan for disruption, you can move fast and stay safe.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Ian Price, Director of Corporate IT at HR, payroll and finance provider, at MHR, says: <\/strong><\/h3>\n\n\n\n<p>Compliance, security and resilience, alongside skills and innovation are the pillars of company growth. An organisation is unable to safely scale without embedding policies that support compliance, ensuring that security and data protection awareness is in place, especially when adopting new technologies.<\/p>\n\n\n<div class=\"wp-block-image is-style-rounded\">\n<figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"880\" height=\"867\" src=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/IMG_9404-web.jpg\" alt=\"\" class=\"wp-image-143343\" style=\"width:344px;height:auto\" srcset=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/IMG_9404-web.jpg 880w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/IMG_9404-web-300x296.jpg 300w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2025\/05\/IMG_9404-web-768x757.jpg 768w\" sizes=\"auto, (max-width: 880px) 100vw, 880px\" \/><\/figure><\/div>\n\n\n<p>Achieving compliance whilst continuing to innovate and grow the business is the perennial tension within a modern organisation. The answer to this lies in a successful CIO \/ CISO relationship. They must work together to position security and compliance not as a blocker, but rather an enabler.&nbsp;<\/p>\n\n\n\n<p>Organisations need to help employees appreciate how the right protections will support their work and ensure they meet their goals. However, security measures must be aligned with operational requirements. This is where CIOs, CISOs and DPOs (data protection officers) must work together to implement effective measures that don\u2019t stifle creativity. The wrong approach can alienate employees and discourage them from innovating at all.<\/p>\n\n\n\n<p>Some organisations approach cybersecurity training as a box-ticking exercise, resulting in limited engagement. The focus should be on changing mindsets and encouraging proactive behaviours rather than an annual training course or exam. Moving beyond compliance-driven training and creating a culture of shared responsibility is the aim.<\/p>\n\n\n\n<p>Understanding risk can be the key to staff understanding the importance of compliance with security and data protection principles. Presenting case studies and educating the workforce on the anatomy of an attack or breach and subsequent consequences are extremely effective tools.<\/p>\n\n\n\n<p>A perfect current example is AI. The use of AI can be transformative for business, but it introduces many risks. Once again, the place to start is policy. Setting clear guidelines for the organisation, highlighting preferred tools, and calling out things to avoid is a straight-forward and sensible place to start. This then informs training and compliance activities.<\/p>\n\n\n\n<p>Ask yourself, has my organisation got an AI policy?<\/p>\n\n\n\n<p>The final part of the equation is upskilling within the workforce. The more informed your teams, the lower the risk of security or data compromise. It is vital to upskill business leaders and employees to understand how to embrace AI securely, establishing strategies and policies to govern its use. This includes conducting due diligence on AI tools, monitoring outputs, and training employees to recognise AI-driven threats.&nbsp;&nbsp;<\/p>\n\n\n\n<p>Companies should also consider compliance in supply chain, such as sanctions compliance to avoid reputational damage of its supply chain being owned by a sanctioned state actor or organisation. This is avoided through effective supplier management.<\/p>\n\n\n\n<p>In a world of hybrid working, physical security can sometimes be forgotten, however companies that deal with sensitive customer data must still comply with security standards such as cyber essentials and ISO 27001.<\/p>\n\n\n\n<p>At the core of all activities to protect your organisation from threats is policy. Good policy, well implemented and tested, will allow your organisation to thrive by providing the guardrails for the business to achieve its goals at the same time as protecting it. CIOs should view compliance, resilience, and regulation as a catalyst for improvement, rather than a barrier to innovation.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>For Chief Information Officers across Europe, the digital transformation journey presents a complex balancing act. The escalating landscape of cyberthreats, coupled with increasingly stringent EU regulations, demands a robust approach to both compliance and resilience. Yet, the imperative to innovate and drive business value through digital initiatives remains paramount. How can CIOs effectively navigate this [&hellip;]<\/p>\n","protected":false},"author":4017,"featured_media":134395,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[21064,21857,17482,218,18793,20673,22074,7359,21754,93,23],"tags":[158,25,564,76,3763,8],"class_list":["post-134388","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai","category-analytics","category-cybersecurity","category-editors-choice","category-europe","category-expert-opinion","category-hot-topic","category-industry-expert","category-technology-ciso","category-top-stories","category-united-kingdom","tag-ai","tag-cloud","tag-cybersecurity","tag-digital-transformation","tag-eu-regulation","tag-europe"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/134388","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/4017"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=134388"}],"version-history":[{"count":9,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/134388\/revisions"}],"predecessor-version":[{"id":143344,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/134388\/revisions\/143344"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/134395"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=134388"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=134388"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=134388"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}