CISO Spotlight: Dimitris Georgiou on Building Security that Serves People First
None
<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/dgeorgiou/" rel="noreferrer noopener">Dimitris Georgiou</a> has been a self-professed computer geek since the early 80s. At university, he studied the convergence of educational technology with computer science as part of his psychology MA – finding, to his disbelief, that systems were perilously insecure. </p><p class="wp-block-paragraph">Since then, he’s always worked in and around cybersecurity. He’s had roles as a computer science teacher, a technology manager, and a cybersecurity consultant, before finally landing in his current role: Chief Security Officer at <a href="https://www.alphabit.gr/" rel="noreferrer noopener">Alphabit Cybersecurity</a>, member of the <a href="http://www.softweb.gr/" rel="noreferrer noopener">Softweb Adaptive I.T. Solutions</a> Group of Companies. But he’s never forgotten about his humanities background.</p><p class="wp-block-paragraph">In this edition of CISO Spotlight, Dimitris explores the importance of CISOs speaking both technical and business language, his concerns around <a href="https://www.wallarm.com/solutions/s-protect-agentic-ai" rel="noreferrer noopener">AI</a> and <a href="https://www.wallarm.com/" rel="noreferrer noopener">API security</a>, and the CISO’s role in the boardroom. </p><h1 class="wp-block-heading">Emphasizing the Human Factor</h1><p class="wp-block-paragraph">For Dimitris, the human factor is the pinnacle of everything cybersecurity professionals do. “Cybersecurity is not just a tradecraft,” he said, “it’s more than that. It has a human impact. Everything we do is to keep our resources out of the hands of cybercriminals. And digital transformation has resulted in the greatest transfer of resources in history.”</p><p class="wp-block-paragraph">Dimitris argues that security awareness only works when it starts with people’s real lives, not just corporate policy. Teaching employees how to protect their children, savings, or elderly relatives creates a mindset that naturally carries back into the workplace. </p><p class="wp-block-paragraph">“If you start with the business, it doesn’t land,” he explained. “But if people see how cybersecurity protects <em>them</em>, you create that all-important human firewall.”</p><h1 class="wp-block-heading">The Changing Role of the CISO</h1><p class="wp-block-paragraph">Early in his career, Dimitris’s primary challenge was simply convincing organizations to invest in even the most basic cybersecurity. “Back then” he recalls, “you had to convince people to spend twenty or thirty dollars per user – and even to stop using cracked versions of antivirus.”</p><p class="wp-block-paragraph">That experience shaped how he thinks about security leadership today. Rather than trying to scare executives into action, he focuses on aligning cybersecurity with growth and resilience. The CISO, he insists, must operate fluently in both technical and business worlds.</p><p class="wp-block-paragraph">“We must translate security imperatives into business continuity and business flourishing mandates. From there, we must create a dogma within the business establishment – not the security establishment – that cybersecurity can and will be a business enabler if you treat it as such.” </p><p class="wp-block-paragraph">Dimitris’s mindset reflects a broader change across modern security leadership. Time and time again in this series, we’ve seen leaders drive home one simple truth: CISOs can no longer just be enforcers, they must be enablers that bridge technical risk with business outcomes. </p><h1 class="wp-block-heading">Speaking the Language of the Boardroom</h1><p class="wp-block-paragraph">This shift towards business-focused CISOs influences how Dimitris thinks about the boardroom. Over the next few years, he expects CISOs to become routine participants in executive decision-making, sitting alongside CFOs and CEOs to discuss risk ownership, resilience, and operational continuity. </p><p class="wp-block-paragraph">“Cybersecurity is just one risk among many. Boards have to consider financial risk, operational risk, market risk, employee churn, effectiveness – everything,” he said. </p><p class="wp-block-paragraph">CISOs must frame cybersecurity within that narrative, convincing the board to align strategic goals with cybersecurity for resilience, operational effectiveness, and development across the organization.</p><p class="wp-block-paragraph">Achieving this requires a rare combination of skills. Technical expertise still matters – Dimitris stresses that leaders should understand the pain and complexity security teams face – but CISOs don’t necessarily need to be the most technically brilliant person in the room. Soft skills like communication and narrative-building are just as important.</p><p class="wp-block-paragraph">“Organizations don’t exist to be secure,” says Dimitris, “they have a mission. The CISO’s job is to help them achieve that mission safely.” </p><h1 class="wp-block-heading">Preparing for Breaches and Dealing with the Aftermath</h1><p class="wp-block-paragraph">Preparation for incidents, Dimitris argues, starts with awareness. Breaches will happen. Perfection isn’t the goal, readiness is. That means building teams that can respond without panic and leaders understanding what resilience really means. </p><p class="wp-block-paragraph">But Dimitris is quick to emphasize the emotional toll breaches can take. Morale often collapses after an incident, especially when security teams are underfunded or unsupported beforehand. In those moments, governance and executive involvement become essential. “You can’t just throw security at a problem and expect miracles,” he said. </p><p class="wp-block-paragraph">From past incidents, he’s learned that many disasters result from poor budget decisions – purchasing cheap, ineffective controls when the cost of more expensive tools pales in comparison to what an incident can cost in reputation, damages, and morale. </p><h1 class="wp-block-heading">Handling AI Uncertainty</h1><p class="wp-block-paragraph">Although Dimitris recognizes the productivity gains <a href="https://www.wallarm.com/company" rel="noreferrer noopener">AI</a> brings, he worries about the lack of transparency and governance surrounding its use and its impact on organizations’ security posture. “We’re engaging with black boxes doing magical and fantastic things,” he said. “But we don’t understand their inner workings.”</p><p class="wp-block-paragraph">Putting on his “digital forensic investigator hat,” Dimitris argues that it would be very difficult to investigate an incident involving an AI model. One can’t just plug an interface into a model and collect the data necessary for an investigation. And that’s a problem at the moment. </p><p class="wp-block-paragraph">For Dimitris, we need to have a serious conversation about governance. Organizations are too focused on outcomes and overlook factors like digital sovereignty. He’s not at all anti-innovation, but he calls for a “marriage of innovation and governance.”</p><h1 class="wp-block-heading">Why API Security Deserves Attention</h1><p class="wp-block-paragraph">If AI is the big conversation, API security is the immediate battlefield. Dimitris believes that APIs will dominate security agendas going forward. But it’s going to be a challenge.</p><p class="wp-block-paragraph">“Everybody is creating sockets for everybody to connect,” he said, pointing to the explosion of integrations and automated workflows across modern software ecosystems.</p><p class="wp-block-paragraph">APIs, he argues, are fundamentally different from traditional web applications. Treating them the same – assuming a <a href="https://www.wallarm.com/what/waf-meaning" rel="noreferrer noopener">web application firewall (WAF)</a> alone is sufficient, for example – is a dangerous misconception. APIs often operate with high-privilege machine accounts, meaning a single weakness can grant attackers deep access to systems. </p><p class="wp-block-paragraph">His advice starts with fundamental: <a href="https://www.wallarm.com/what/what-is-threat-modeling" rel="noreferrer noopener">threat modeling</a>, <a href="https://www.wallarm.com/what/secure-coding" rel="noreferrer noopener">secure coding</a>, segmentation of privileged system accounts, continuous monitoring, and relentless assessment. In his words, we can’t simply bolt API security on; we must build it into the API itself from the beginning. </p><h1 class="wp-block-heading">A Human-Centred Future</h1><p class="wp-block-paragraph">Despite tackling complex technical issues, Dimitris always returns to one idea: cybersecurity is about people. Whether discussing AI, governance, or executive strategy, his focus remains on the human impact. </p><p class="wp-block-paragraph">Outside work, he’s sharpening his management skills through <em>Harvard Business Review</em> lessons, listening to lounge music to unwind, and following financial and cybersecurity podcasts to stay informed.</p><p class="wp-block-paragraph">If he had the time, he’d head to Japan – he’s drawn to the balance between deep cultural roots and relentless technological innovation. That same curiosity defines his approach to security leadership. </p><p class="wp-block-paragraph">And to reiterate: for Dimitris, the modern CISO is more than a technical guardian. The role is about translating risk into business language, aligning people and technology, and helping organizations move forward with confidence. </p><p>The post <a href="https://lab.wallarm.com/ciso-spotlight-dimitris-georgiou-security-serves-people-first/">CISO Spotlight: Dimitris Georgiou on Building Security that Serves People First</a> appeared first on <a href="https://lab.wallarm.com/">Wallarm</a>.</p><div class="spu-placeholder" style="display:none"></div><div class="addtoany_share_save_container addtoany_content addtoany_content_bottom"><div class="a2a_kit a2a_kit_size_20 addtoany_list" data-a2a-url="https://securityboulevard.com/2026/03/ciso-spotlight-dimitris-georgiou-on-building-security-that-serves-people-first/" data-a2a-title="CISO Spotlight: Dimitris Georgiou on Building Security that Serves People First"><a class="a2a_button_twitter" href="https://www.addtoany.com/add_to/twitter?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F03%2Fciso-spotlight-dimitris-georgiou-on-building-security-that-serves-people-first%2F&linkname=CISO%20Spotlight%3A%20Dimitris%20Georgiou%20on%20Building%20Security%20that%20Serves%20People%20First" title="Twitter" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_linkedin" href="https://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F03%2Fciso-spotlight-dimitris-georgiou-on-building-security-that-serves-people-first%2F&linkname=CISO%20Spotlight%3A%20Dimitris%20Georgiou%20on%20Building%20Security%20that%20Serves%20People%20First" title="LinkedIn" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_facebook" href="https://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F03%2Fciso-spotlight-dimitris-georgiou-on-building-security-that-serves-people-first%2F&linkname=CISO%20Spotlight%3A%20Dimitris%20Georgiou%20on%20Building%20Security%20that%20Serves%20People%20First" title="Facebook" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_reddit" href="https://www.addtoany.com/add_to/reddit?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F03%2Fciso-spotlight-dimitris-georgiou-on-building-security-that-serves-people-first%2F&linkname=CISO%20Spotlight%3A%20Dimitris%20Georgiou%20on%20Building%20Security%20that%20Serves%20People%20First" title="Reddit" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_email" href="https://www.addtoany.com/add_to/email?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F03%2Fciso-spotlight-dimitris-georgiou-on-building-security-that-serves-people-first%2F&linkname=CISO%20Spotlight%3A%20Dimitris%20Georgiou%20on%20Building%20Security%20that%20Serves%20People%20First" title="Email" rel="nofollow noopener" target="_blank"></a><a class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share"></a></div></div><p class="syndicated-attribution">*** This is a Security Bloggers Network syndicated blog from <a href="https://lab.wallarm.com/">Wallarm</a> authored by <a href="https://securityboulevard.com/author/0/" title="Read other posts by Tim Erlin">Tim Erlin</a>. Read the original post at: <a href="https://lab.wallarm.com/ciso-spotlight-dimitris-georgiou-security-serves-people-first/">https://lab.wallarm.com/ciso-spotlight-dimitris-georgiou-security-serves-people-first/</a> </p>