{"id":24343,"date":"2026-09-30T08:41:50","date_gmt":"2026-09-30T08:41:50","guid":{"rendered":"https:\/\/www.securitytoday.de\/?p=24343"},"modified":"2026-09-30T08:41:54","modified_gmt":"2026-09-30T08:41:54","slug":"ciso-does-not-take-responsibility-from-leadership","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/09\/30\/ciso-does-not-take-responsibility-from-leadership\/","title":{"rendered":"A CISO does not take responsibility away from company leadership"},"content":{"rendered":"<p style=\"margin:0 0 18px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">Interview ahead of the ECSO CISO Meetup in Berlin<\/p>\n<p><strong>Boards have long known that cyber risk matters. Matthias Muhlert, Group CISO of the Oetker Group and Chair of the ECSO CISO Community, asks a different question ahead of the ECSO CISO Meetup in Berlin: Who remains responsible once the CISO is appointed?<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"color:#69d8ed;text-transform:uppercase;letter-spacing:0.08em;font-size:0.82em;font-weight:700;margin:0 0 16px;\">Key takeaways<\/p>\n<ul style=\"margin:0;padding-left:20px;line-height:1.7;\">\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">Responsibility stays at the top.<\/strong> Whoever decides on suppliers, tolerable downtime or acquisitions also decides on cyber risk. The CISO advises, helps reduce risk and escalates.<\/li>\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">Metrics must support decisions.<\/strong> Muhlert recommends presenting evidence in three parts: what has been demonstrated, which assumptions remain untested and what will be tested next.<\/li>\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">Suppliers matter in a real incident.<\/strong> Access, recovery and reachability need to be clarified and practised. A certificate does not answer these questions for every business relationship.<\/li>\n<li style=\"margin-bottom:0px;\"><strong style=\"color:#69d8ed;\">Delegated authority is the underrated AI risk.<\/strong> Muhlert warns of premise injection and audit debt, meaning automated decisions that nobody can reconstruct any more.<\/li>\n<\/ul>\n<\/div>\n<div data-element=\"expert_card\" style=\"display:flex;gap:18px;align-items:center;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;padding:18px 20px;margin:24px 0 32px;color:#e6e3da;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);\">\n<div style=\"width:96px;height:96px;border-radius:50%;overflow:hidden;border:2px solid rgba(105,216,237,0.35);flex-shrink:0;background:#111210;\"><img loading=\"lazy\" decoding=\"async\" style=\"width:96px;height:96px;object-fit:cover;display:block;\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/09\/ecso-ciso-meetup-interview-matthias-muhlert-portrait-hero.jpg\" alt=\"Matthias Muhlert, Group CISO of the Oetker Group, Chair of the ECSO CISO Community\" width=\"96\" height=\"96\" \/><\/div>\n<div style=\"min-width:0;color:#e6e3da;\">\n<div style=\"font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;margin-bottom:4px;\">In this interview<\/div>\n<div style=\"font-weight:bold;color:#e6e3da;font-size:1.05em;line-height:1.3;\">Matthias Muhlert<\/div>\n<div style=\"color:#a29e91;font-size:0.92em;line-height:1.45;margin-top:4px;\">Group CISO of the Oetker Group, Chair of the ECSO CISO Community<\/div>\n<\/div>\n<\/div>\n<p>On 1 and 2 October, CISOs from across Europe meet at the Estrel Berlin for the ECSO CISO Meetup 2026. It is the fifth edition after Brussels, Florence, Vienna and Valencia. The meetings of the ECSO CISO Community run under the Chatham House Rule. According to its own figures, the community of the European Cyber Security Organisation (ECSO) counts over 700 security leaders from 35 countries.<\/p>\n<p>SecurityToday is media partner of the Meetup. Ahead of the event, the Chair of the ECSO CISO Community answered ten questions in writing. Matthias Muhlert speaks in this interview from his personal professional perspective and not about internal processes of his employer.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Responsibility stays with the board<\/h2>\n<div style=\"margin:36px 0 16px;\">\n<p style=\"margin:0 0 8px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">Question 01<\/p>\n<p style=\"margin:0;font-weight:700;font-size:1.1em;line-height:1.45;color:#e6e3da;\">Boards have heard about cyber risk for a decade. What do most of them still get wrong in 2026, and what would you want every board member to understand?<\/p>\n<\/div>\n<p>Most boards I meet already understand that cyber risk matters. The harder question is who remains responsible after a CISO is appointed. Business decision-making does not suddenly move to the CISO&#8217;s desk. Choosing which suppliers to depend on, deciding how much downtime a production line can tolerate or acquiring a company also means making decisions about cyber risk. Those choices may not look like security decisions at first.<\/p>\n<p>The CISO advises, helps reduce risk and has a responsibility to escalate. The CISO remains accountable for that advice and for the work within the role&#8217;s remit. Responsibility for business decisions stays with the people authorised to make them.<\/p>\n<p>I would connect this more closely to strategy. A list of ten critical risks gives a board little direction. Explaining that two of them threaten this year&#8217;s growth plan gives it a concrete reason to weigh the options and allocate resources.<\/p>\n<figure data-element=\"pull_quote\" style=\"margin:32px 0;padding:22px 0;border-top:1px solid rgba(217,200,145,0.4);border-bottom:1px solid rgba(217,200,145,0.4);\">\n<blockquote style=\"margin:0;font-size:1.22em;line-height:1.5;color:#e6e3da;font-style:italic;\"><p>A metric a board cannot act on is decoration.<\/blockquote><figcaption style=\"margin-top:14px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.74em;letter-spacing:0.08em;text-transform:uppercase;color:#69d8ed;\">Matthias Muhlert, Chair of the ECSO CISO Community<\/figcaption><\/figure>\n<div style=\"margin:36px 0 16px;\">\n<p style=\"margin:0 0 8px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">Question 02<\/p>\n<p style=\"margin:0;font-weight:700;font-size:1.1em;line-height:1.45;color:#e6e3da;\">When you brief a board, which three numbers or statements do you bring, and which ones do you deliberately leave out?<\/p>\n<\/div>\n<p>I can&#8217;t go into the Oetker Group&#8217;s internal reporting. Speaking generally, I would present evidence in three parts, covering what has been demonstrated and under which conditions, which assumptions remain untested, and what will be tested next, with a date and an owner.<\/p>\n<p>A result without its test conditions tells only half the story. \u201cA compromised account cannot reach production administration\u201d is a claim. \u201cIn test X on date Y, the account reached layer Z and no further\u201d is a concrete finding with clearly visible limits.<\/p>\n<p>Each measure should help frame a decision or identify a question worth asking. I would leave out activity counts that do neither. On their own, millions of blocked attacks tell us more about the weather than the roof. A metric a board cannot act on is decoration.<\/p>\n<div data-element=\"checklist\" style=\"background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;padding:22px 24px;margin:32px 0;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);\">\n<p style=\"margin:0 0 12px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">A proposal for the board briefing: evidence in three parts<\/p>\n<ul style=\"margin:0;padding-left:0;list-style:none;\">\n<li style=\"margin:0 0 10px;padding-left:26px;position:relative;color:#e6e3da;line-height:1.5;\"><span style=\"position:absolute;left:0;color:#69d8ed;\">&#10003;<\/span>What has been demonstrated and under which conditions<\/li>\n<li style=\"margin:0 0 10px;padding-left:26px;position:relative;color:#e6e3da;line-height:1.5;\"><span style=\"position:absolute;left:0;color:#69d8ed;\">&#10003;<\/span>Which assumptions remain untested<\/li>\n<li style=\"margin:0 0 10px;padding-left:26px;position:relative;color:#e6e3da;line-height:1.5;\"><span style=\"position:absolute;left:0;color:#69d8ed;\">&#10003;<\/span>What will be tested next, with a date and an owner<\/li>\n<\/ul>\n<\/div>\n<div style=\"margin:36px 0 16px;\">\n<p style=\"margin:0 0 8px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">Question 03<\/p>\n<p style=\"margin:0;font-weight:700;font-size:1.1em;line-height:1.45;color:#e6e3da;\">Budget round 2027: many boards are cutting IT budgets. How do you argue for security spend in a year like this?<\/p>\n<\/div>\n<p>The Oetker Group&#8217;s budget is not something I can discuss here. In that kind of debate, I would generally explain the consequences of a reduction and how certain I am about the assessment. Fear alone is a weak defence of a total. An honest answer also identifies work that no longer justifies its cost. That might be reporting nobody uses or duplicated activity. With tools, the expected security benefit has to justify the operating and support burden.<\/p>\n<p>For a made-up example, take a business selling perishable goods. An interruption can cause losses that later production cannot recover. That business consequence belongs in the discussion alongside the cost of protection. It is a more useful starting point than automatically defending every existing security expense.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What NIS2 and the CRA change in a real incident<\/h2>\n<div style=\"margin:36px 0 16px;\">\n<p style=\"margin:0 0 8px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">Question 04<\/p>\n<p style=\"margin:0;font-weight:700;font-size:1.1em;line-height:1.45;color:#e6e3da;\">Germany&#8217;s NIS2 implementing act has been in force since 6 December 2025, and the Cyber Resilience Act&#8217;s manufacturer reporting obligations began on 11 September 2026. Where do these rules make your organisation safer, and where do they add paperwork without security?<\/p>\n<\/div>\n<p>I can&#8217;t comment on the effects within the Oetker Group. The German law took effect on St Nicholas Day, when children in Germany traditionally find presents in their boots. Not every organisation welcomed this particular gift.<\/p>\n<p>The rules themselves are, of course, open for discussion. What interests me is what they change during an incident. NIS2 uses reporting in stages. The early warning quickly alerts the relevant authorities and can help an organisation seek assistance. An early warning is not yet a final root-cause analysis. Later reports add detail. It remains important what was uncertain at first and what was corrected later.<\/p>\n<p>Then comes the question of what happened to that information. I&#8217;d want to trace who used the information and which decision changed as a result. Test results would then help establish whether response or recovery actually worked better.<\/p>\n<p>The effort of preparing the reports belongs in that assessment too. It needs to be weighed against the benefit, rather than treated as proof that reporting was pointless. Documentation can help protect an organisation. A completed form alone still cannot tell me whether anything works better when it matters.<\/p>\n<div data-element=\"timeline\" style=\"background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;padding:22px 24px 12px;margin:32px 0;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);\">\n<p style=\"margin:0 0 14px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">The key dates at a glance<\/p>\n<div style=\"display:flex;flex-wrap:wrap;gap:2px 16px;margin:0 0 14px;color:#e6e3da;\">\n<div style=\"flex:0 0 136px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.78em;color:#69d8ed;padding-top:3px;\">6 Dec 2025<\/div>\n<div style=\"flex:1 1 240px;min-width:0;color:#e6e3da;line-height:1.55;\">Germany&#8217;s NIS2 implementation act enters into force.<\/div>\n<\/div>\n<div style=\"display:flex;flex-wrap:wrap;gap:2px 16px;margin:0 0 14px;color:#e6e3da;\">\n<div style=\"flex:0 0 136px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.78em;color:#69d8ed;padding-top:3px;\">11 Sep 2026<\/div>\n<div style=\"flex:1 1 240px;min-width:0;color:#e6e3da;line-height:1.55;\">The manufacturer reporting obligations under the Cyber Resilience Act apply.<\/div>\n<\/div>\n<div style=\"display:flex;flex-wrap:wrap;gap:2px 16px;margin:0 0 14px;color:#e6e3da;\">\n<div style=\"flex:0 0 136px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.78em;color:#69d8ed;padding-top:3px;\">1 Oct 2026<\/div>\n<div style=\"flex:1 1 240px;min-width:0;color:#e6e3da;line-height:1.55;\">The ECSO CISO Meetup opens at the Estrel Berlin.<\/div>\n<\/div>\n<\/div>\n<div style=\"margin:36px 0 16px;\">\n<p style=\"margin:0 0 8px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">Question 05<\/p>\n<p style=\"margin:0;font-weight:700;font-size:1.1em;line-height:1.45;color:#e6e3da;\">What should European policymakers hear from CISOs before the next regulatory round?<\/p>\n<\/div>\n<p>I&#8217;d like to show them what implementation actually looks like. That includes what the team knew at each reporting stage and which statements it had to correct later. It also matters where the information was used and how much work went into preparing it. The same account can reveal operational benefits and administrative effort. The circumstances matter too. A small organisation and a multinational may face very different constraints while meeting the same obligation.<\/p>\n<p>Results from exercises and experience from incidents can show which decisions changed and which capabilities were actually demonstrated. They cannot, by themselves, establish that a legal requirement caused an improvement. I would talk to policymakers about observed effects, costs and the questions still open. Sweeping verdicts that regulation either solves security or merely creates paperwork won&#8217;t help us much. Berlin gives practitioners and public institutions an opportunity to discuss those experiences together and understand what the results can tell us.<\/p>\n<figure data-element=\"pull_quote\" style=\"margin:32px 0;padding:22px 0;border-top:1px solid rgba(217,200,145,0.4);border-bottom:1px solid rgba(217,200,145,0.4);\">\n<blockquote style=\"margin:0;font-size:1.22em;line-height:1.5;color:#e6e3da;font-style:italic;\"><p>At three in the morning, the certificate will not answer the phone.<\/blockquote><figcaption style=\"margin-top:14px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.74em;letter-spacing:0.08em;text-transform:uppercase;color:#69d8ed;\">Matthias Muhlert, Chair of the ECSO CISO Community<\/figcaption><\/figure>\n<div style=\"margin:36px 0 16px;\">\n<p style=\"margin:0 0 8px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">Question 06<\/p>\n<p style=\"margin:0;font-weight:700;font-size:1.1em;line-height:1.45;color:#e6e3da;\">Supply chain: what do you require from vendors today that you did not require three years ago?<\/p>\n<\/div>\n<p>I don&#8217;t speak publicly about the Oetker Group&#8217;s specific supplier requirements. For the wider professional discussion, my measure would be whether cooperation holds up when something fails. I&#8217;d first establish what the supplier can access in a customer&#8217;s environment. That includes how the customer could restrict that access during an incident at the supplier. How quickly can affected services be restored, and when was that last tested?<\/p>\n<p>I&#8217;d also want to know how soon the customer will be informed, through which channel and who will answer. Who else expects access to the same recovery capacity belongs in that conversation too.<\/p>\n<p>A certificate tells you something about the area it covers. It won&#8217;t settle every question about this particular relationship. Cooperation needs to be exercised by agreement. Surprise calls are the wrong way to do that. At three in the morning, the certificate will not answer the phone.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What the community should achieve in Berlin<\/h2>\n<div style=\"margin:36px 0 16px;\">\n<p style=\"margin:0 0 8px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">Question 07<\/p>\n<p style=\"margin:0;font-weight:700;font-size:1.1em;line-height:1.45;color:#e6e3da;\">The ECSO CISO Community works under the Chatham House Rule. What kind of exchange becomes possible there that does not happen at conferences?<\/p>\n<\/div>\n<p>After someone says \u201cthis worked for us\u201d, we can ask the next question. Why do we think it worked? That also means looking at what else changed along the way. Would the same approach hold up in a different organisation and under different pressure?<\/p>\n<p>Confidentiality protects the person telling the story. Whether the explanation is right remains an open question. That setting lets us be generous with each other while still asking demanding questions.<\/p>\n<p>In Berlin, I want to hear unfinished stories and understand why something that looked sensible failed anyway. What we still don&#8217;t know belongs in the conversation too. We have to be able to disagree. Otherwise we become a highly qualified group of yes-men who only agree with each other.<\/p>\n<figure data-element=\"pull_quote\" style=\"margin:32px 0;padding:22px 0;border-top:1px solid rgba(217,200,145,0.4);border-bottom:1px solid rgba(217,200,145,0.4);\">\n<blockquote style=\"margin:0;font-size:1.22em;line-height:1.5;color:#e6e3da;font-style:italic;\"><p>Before calling something a recovery capability, I want to know whether it still works when the hero is on holiday.<\/blockquote><figcaption style=\"margin-top:14px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.74em;letter-spacing:0.08em;text-transform:uppercase;color:#69d8ed;\">Matthias Muhlert, Chair of the ECSO CISO Community<\/figcaption><\/figure>\n<div style=\"margin:36px 0 16px;\">\n<p style=\"margin:0 0 8px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">Question 08<\/p>\n<p style=\"margin:0;font-weight:700;font-size:1.1em;line-height:1.45;color:#e6e3da;\">Ransomware case studies are a fixed part of the Meetup. What is the one lesson from real incidents that rarely makes it into official guidance?<\/p>\n<\/div>\n<p>I&#8217;m interested in whether a successful response can be repeated next time. An undocumented workaround or one person&#8217;s judgement may have made the difference during an incident. That deserves recognition. Expertise and improvisation still matter. The organisation also needs to understand what it can reliably do next time without depending on that particular person&#8217;s memory and availability.<\/p>\n<p>In a controlled exercise, make the usual decision-maker unavailable for one phase. The exercise can reveal whether the person covering for them is able to act and has the authority and information they need. Where do they hesitate? That helps reveal what the organisation can really depend on. Before calling something a recovery capability, I want to know whether it still works when the hero is on holiday.<\/p>\n<div style=\"margin:36px 0 16px;border-top:1px solid rgba(230,227,218,0.12);padding-top:26px;\">\n<p style=\"margin:0 0 8px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">Question 09<\/p>\n<p style=\"margin:0;font-weight:700;font-size:1.1em;line-height:1.45;color:#e6e3da;\">AI: which AI risk is overrated in board conversations right now, and which one is underrated?<\/p>\n<\/div>\n<p>For me, the overrated risk is the cinematic scenario of an AI deciding to turn on its owners. The underrated one is delegated authority and the premises it runs on. An AI system does not need to be malicious to cause damage. It can follow a permitted workflow while starting from something false. A procurement assistant might, for example, accept a fabricated claim that new supplier bank details have already been verified.<\/p>\n<p>That is what I call premise injection, manipulating the propositions an agent treats as grounds for reasoning and action. Every delegation that no person can account for also adds to what I call audit debt. I mean the growing inability to reconstruct the actions and authority behind automated decisions.<\/p>\n<p>The useful board questions are dull. What can this system change? What evidence supports the facts it relies on? Can a wrong action be stopped and reversed?<\/p>\n<div data-element=\"definition_box\" style=\"background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;padding:20px 24px 10px;margin:32px 0;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);\">\n<p style=\"margin:0 0 12px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">Two terms from the interview<\/p>\n<p style=\"margin:0 0 10px;color:#e6e3da;line-height:1.6;\"><strong style=\"color:#69d8ed;\">Premise Injection:<\/strong> manipulating the propositions an agent treats as grounds for reasoning and action<\/p>\n<p style=\"margin:0 0 10px;color:#e6e3da;line-height:1.6;\"><strong style=\"color:#69d8ed;\">Audit Debt:<\/strong> the growing inability to reconstruct the actions and authority behind automated decisions<\/p>\n<\/div>\n<div style=\"margin:36px 0 16px;\">\n<p style=\"margin:0 0 8px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">Question 10<\/p>\n<p style=\"margin:0;font-weight:700;font-size:1.1em;line-height:1.45;color:#e6e3da;\">What should a CISO take home from Berlin on 2 October?<\/p>\n<\/div>\n<p>I&#8217;d like each participant to leave with an assumption they are willing to have challenged and a test they intend to run safely in their own organisation. They should also have a peer to tell what the test revealed. That should be someone who challenges an assumption in October and asks in November what happened.<\/p>\n<p>Perhaps this second conversation a month later is especially important. It gives a good intention a real follow-up, and both people can discuss a result that failed to confirm the original lesson.<\/p>\n<p>Berlin is where those conversations can begin. Their value becomes clearer when we see what people actually do afterwards.<\/p>\n<div style=\"background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;padding:24px 24px 20px;margin:48px 0 40px;color:#e6e3da;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);\">\n<p style=\"margin:0 0 6px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">ECSO CISO Meetup 2026<\/p>\n<p style=\"margin:0 0 18px;font-size:1.3em;font-weight:700;line-height:1.3;color:#e6e3da;\">1 and 2 October 2026 \u00b7 Estrel Berlin<\/p>\n<p style=\"margin:0 0 16px;color:#e6e3da;line-height:1.6;\">The Meetup of the European Cyber Security Organisation (ECSO) takes place on 1 and 2 October 2026 at the Estrel Berlin.<\/p>\n<div style=\"display:flex;flex-wrap:wrap;gap:12px;margin:0 0 20px;color:#e6e3da;\">\n<div style=\"color:#e6e3da;flex:1 1 240px;min-width:0;background:rgba(0,51,64,0.55);border:1px solid rgba(105,216,237,0.18);border-radius:8px;padding:14px 16px;box-sizing:border-box;\">\n<p style=\"margin:0 0 6px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">Who it is for<\/p>\n<p style=\"margin:0;color:#e6e3da;line-height:1.55;font-size:0.95em;\">It is aimed primarily at CISOs, Deputy CISOs and their teams.<\/p>\n<\/div>\n<div style=\"color:#e6e3da;flex:1 1 240px;min-width:0;background:rgba(0,51,64,0.55);border:1px solid rgba(105,216,237,0.18);border-radius:8px;padding:14px 16px;box-sizing:border-box;\">\n<p style=\"margin:0 0 6px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">Participation<\/p>\n<p style=\"margin:0;color:#e6e3da;line-height:1.55;font-size:0.95em;\">Participation is subject to approval of the registration. It is free of charge. Travel and accommodation are at the participants&#8217; own expense.<\/p>\n<\/div>\n<\/div>\n<p style=\"margin:0 0 14px;color:#e6e3da;\"><a href=\"https:\/\/www.b2match.com\/e\/ecso-ciso-meetup-2026-berlin\/components\/65652\/info\" target=\"_blank\" rel=\"noopener\" style=\"display:inline-block;background:#003340;border:1px solid #69d8ed;color:#e6e3da;font-weight:700;text-decoration:none;padding:11px 20px;border-radius:6px;\">Programme and registration at ECSO<\/a><\/p>\n<p style=\"margin:0;color:#a29e91;font-size:0.85em;\">SecurityToday is media partner of the ECSO CISO Meetup 2026.<\/p>\n<\/div>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>When and where does the ECSO CISO Meetup 2026 take place?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">On 1 and 2 October 2026 at the Estrel Berlin. It is the fifth edition after Brussels, Florence, Vienna and Valencia. It is aimed primarily at CISOs, Deputy CISOs and their teams. Participation is subject to approval of the registration. It is free of charge, and participants cover travel and accommodation themselves.<\/p>\n<\/details>\n<details>\n<summary><strong>What does Matthias Muhlert mean by premise injection?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The manipulation of the propositions an AI agent treats as grounds for reasoning and action. A procurement assistant might, for example, accept a fabricated claim that new supplier bank details have already been verified.<\/p>\n<\/details>\n<details>\n<summary><strong>Which metrics belong in a board briefing according to Muhlert?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Only those that help frame a decision or identify a question worth asking. He would leave out pure activity figures. To him, millions of blocked attacks tell us more about the weather than the roof.<\/p>\n<\/details>\n<p><!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">Editor&#8217;s Picks<\/h3>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/27\/supervisory-board-reporting-key-figures\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/ciso-board-reporting-kennzahlen-aufsichtsrat-cover-hero-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Five Metrics the Supervisory Board Actually Understands<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/07\/08\/concentration-risk-fourth-party-supply-chain\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/konzentrationsrisiko-vierte-partei-lieferkette-cover-hero-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">The concentration risk no supplier audit sees<\/span><\/span><\/a><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.digital-chiefs.de\/en\/nis2-liability-for-management-boards-applies-despite-registration\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/09\/net-nis2-organhaftung-nachweis-registrierung-50596877-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#e8828d;margin-bottom:5px;\">Digital Chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">NIS2 liability for management boards applies despite registration<\/span><\/span><\/a><a href=\"https:\/\/mybusinessfuture.com\/en\/manufacturers-report-cra-incidents-to-enisa-before-the-csirt\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/09\/net-enisa-gibt-die-cra-meldung-ohne-csirt-pr-89978765-250x141.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#aa8ac2;margin-bottom:5px;\">MyBusinessFuture<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Manufacturers Report CRA Incidents to ENISA Ahead of the CSIRT<\/span><\/span><\/a><!--\/ST-LOWER-CARDS--><\/p>\n<p style=\"font-style:italic;text-align:right;font-size:0.85em;margin-top:8px;\">Image source: AI-generated (September 2026). Portrait in this article: Matthias Muhlert \/ ECSO (press photo).<\/p>\n","protected":false},"excerpt":{"rendered":"Matthias Muhlert, Chair of the ECSO CISO Community, ahead of the ECSO CISO Meetup 2026 in Berlin on board responsibility, metrics, suppliers and AI risks.","protected":false},"author":50,"featured_media":24339,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"ECSO CISO Meetup","_yoast_wpseo_title":"A CISO does not take responsibility away from leadership","_yoast_wpseo_metadesc":"Matthias Muhlert, Chair of the ECSO CISO Community, ahead of the ECSO CISO Meetup in Berlin on board responsibility, metrics, suppliers and AI risks.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/09\/ecso-ciso-meetup-interview-matthias-muhlert-cover-hero.jpg","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/09\/ecso-ciso-meetup-interview-matthias-muhlert-cover-hero.jpg","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_pin_until":1790978340,"evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"en","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[259],"tags":[],"class_list":["post-24343","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-strategie-governance-en"],"evm_reading_time_minutes":14,"wpml_language":"en","wpml_translation_of":24322,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/24343","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=24343"}],"version-history":[{"count":2,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/24343\/revisions"}],"predecessor-version":[{"id":24346,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/24343\/revisions\/24346"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/24339"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=24343"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=24343"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=24343"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}