CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG

Korber AG is the holding company of a diverse German technology and manufacturing organization with around 13,000 employees in 100 locations around the world. 

“Take Pharma,” comments Andreas Gaetje. “Probably every vaccine you ever received has been through our machines.” Korber services companies that supply consumers. So, despite its size and importance, it is rarely known to or recognized by the eventual consumer.

Gaetje is the CISO at Korber AG.

The route to CISO

“I never planned to make a career in cybersecurity,” he said. “When I started my career, I was more focused on economics and business politics, and more likely and expectant of finding a job in public services.” 

But the reality of life often reshapes expectations. He was young and needed money now, rather than from future expectations. It was the mid-1990s, when the internet had newly transitioned from an elite playground to a fundamental tool for business and people. Email became the de facto method of communication.

“I said to myself, Okay, let’s maybe do something in the computer business,” he continued. This entry route is unlike many of today’s leading CISOs, who started by being gifted an early PC and teaching themselves how to use it and the internet and get free online gaming time. But that didn’t matter too much to Gaetje. “I’m not the deepest bit-crawler – that’s just not who I am,” he said.

Advertisement. Scroll to continue reading.

He looked for a profession where he could combine his initial interest in economics and the politics of business with information technology. So, he joined a consulting firm.

But by the early 2000s, he decided that if he really wanted to focus on business inside of IT, he would need to focus on just one industry sector. “The best industry at this point in time, where IT was really crucial,” he recalled, “was the finance industry. I joined an insurance company.”

He started as an auditor, learned about the business and figured out how business and IT can work together. At that time, cybersecurity hadn’t become the major occupation it is today. “ITsec and audit had a natural affinity. ITsec was primarily about compliance – it wasn’t yet the business threat it has since become. My knowledge of business, information technology and audit put me in a good place when cybersecurity began to kick off. At that point, I was asked if I wanted to manage the growing information security area.”

Andreas Gaetje, CISO, Körber AG

It was in the 2010s that, in his own words, “The fun started.” This was the era of new large-scale cyberattacks, including WannaCry and NotPetya. “It was very clear: we weren’t talking about a simple compliance issue anymore. This was a serious business threat. Cybersecurity had become a hot topic. It was complex, innovative, and really interesting to work in.”

By 2018, Gaetje had become CISO at Korber IT Solutions. In 2019, he became CISO at Korber AG. The inexorable rise of someone starting with an interest in economics and business politics to the chief of cybersecurity in a major international group proves one thing: you can be a security leader without ever being ‘a deep bit-crawler’ provided you have a deep understanding of business and the function of IT and security.

What good career advice did Andreas Gaetje receive on his career path?

“Much,” he said, “but the most recent was what brought me to Korber. It was this: if you really want to understand security, don’t stay too long in a single company or a single industry sector.”

It was good advice, he continued. Different companies and different sectors have different risk profiles – and if you stay too long in one place, your mind may get stuck in a rut. Without wider experience, you may not be able to change how you think as fast as the attackers change how they attack.

“It’s what made me move from the insurance industry into manufacturing and machine building. I wanted to learn something else, to experience something new, and do something different.”

Becoming a leader

Working in a profession is different than leading in that profession. Leadership skills go beyond pure subject knowledge – and considering what makes a leader is a lesson in how to be a leader. Are leaders born, tutored, or self-taught?

“I’m not a born leader. I would never consider that,” said Gaetje. “But I have a clear understanding about leadership and what it is. My view is that a leader is someone who provides direction to others, or a vision of what and how something can be achieved.”

That’s an interesting idea. It suggests that a leader is fundamentally the person with the dominant personality. Whenever a group of more than one person is involved, one person emerges as the de facto leader. As the group expands, pure dominance must be enhanced with additional characteristics to justify that dominance.

“It’s something you can learn. It’s not something that comes out of the blue. I learned and enhanced that learning with training courses. But of course, your personality is also important. You need to be reliable – you need to be a person that people trust, otherwise it just doesn’t work.”

It’s basically a strong personality that engenders trust from others. “The rest,” he said, “is something you can learn – and I had to learn it.”

Becoming a leader is something most people can achieve, provided they have the intent and personality and training to do so. But achieving leadership needn’t be a formal management position. The function is not in the title. “You’re a leader, even if it’s a thought leader driving and directing other people in a specific direction.”

The leader’s team

Leaders typically emerge from within a team as their careers progress. That relationship changes when you reach C-level leadership – now you largely get to choose and shape your own team. But building that team is not necessarily simple: the ‘skills gap’ in cybersecurity in 2025 was estimated to be between 2.8 million and 4.8 million. 

“In recruiting your team, you have a wish list, and then you have reality – and unfortunately, they don’t always fit together,” he explained. “But there is one requirement that is constant across all candidates of whatever experience: I need people who want to learn.”

The cybersecurity world, he said, is evolving rapidly in both attacks and attack paths. “It’s incredible how fast things change. So, what I always need are people who are engaged, can think out of the box, and want to go the extra mile to understand what’s going on.”

This is not a nine-to-five job with predefined procedures. “Cybersecurity is something where you must learn something new every day, and I need people with a desire to learn.” Training and career advice he can and does provide; but that initial personality spark of curiosity and enthusiasm he cannot. “So, whether I’m looking for an engineer, an analyst or some junior position, experience is good, but enthusiasm to learn is necessary.”

Would he employ a hacker?

“That depends,” he answered. “The hacker mentality comes with that built-in curiosity coupled with an ability to worry at a problem until it is solved. But there are two flavors of hacker – what we might call black and white.”

He simply isn’t comfortable employing someone with a history of malicious activity in Korber. “So, white hackers I would employ; blackhats, no.”

What career advice would Andreas Gaetje give ambitious members of his team?

“Be curious. Things are really changing. If you think you know everything about anything, you’re wrong. That’s never true. There’s always something new coming for you to learn and experience.”

Biggest concerns today

His primary concern today is simply the speed of new technology development.

“Just think about the many things you’ve learned in the last few weeks, about new developments, new products and new techniques that have been deployed to the public. AI is an example – we learn new things about the potential of generative AI and agentic AI every week. What used to occur over a period of two years or more now happens in a couple of weeks.”

AI is particularly challenging, because it is used by both attackers and defenders. Attackers are using AI to increase the speed, scale and sophistication of attacks. Defenders are using their own AI to defend against adversarial AI, while those very defenses can be manipulated by attackers in different attacks. Shadow AI (AI systems installed but unknown to the IT and security departments) is proliferating.

“The pace of new technology is truly hard to manage. For each new technology you must find time to learn and understand it – but that’s on top of everything else you’re already doing. And it’s not just you – everyone on your team must find time to understand the new technology, and you must personally motivate them to do so when they are already fully occupied.”

AI is expected to reduce staff requirements. Will it have any effect on the role of the CISO?

“I think not. I think the role of cybersecurity, and even my own role will be much more important in the future than it is today. But it may change. AI is growing throughout the business and creating problems too widespread for the security team to handle alone. So, we will have to bring other parts of the business into play. Our product development team, our software developers, they all need to be in play with security to protect our own innovations going forward.”

Is increased use of AI affecting skill levels generally?

“It’s not a new question – it’s common with all new technologies. I remember we worried the arrival of Excel would cause people to lose the ability to do math for themselves.” That never really happened. “But this may be a bit different with AI,” he continued. “Consider our coders. AI coding assistants require prompt engineers and architects above programmers – and that can be a problem. How do you bring people from this level to the next level if they are not able to program on their own?” (There are separate problems about the security of code generated by AI assistants.)

Gaetje doesn’t believe this problem is limited to programmers – there will be a similar issue for analysts in the SOC. The standard belief is that AI will collapse the SOC tier hierarchy. There will be no need for traditional tier 1 analysts to perform triaging because that will now be done by AI systems.

“If the security analyst job can be done via an agentic AI tool, then how will analysts learn how to analyze an event? Maybe in the future, if we just rely on AI, we will lose the ability to see the tricky things in the incident, like what could happen here, and what does it mean? This may happen.”

He has thought about the consequences of AI on security people, but he is not concerned for the future of security itself. “I’m pretty sure we will find different ways to handle the changes. And honestly, there’s so much out there that I’m not really concerned that we will lose anything.” 

It’s the security team that must adapt to new processes rather than security itself failing. Guiding this process will be another requirement on the CISO.

“The job of the security team will change dramatically in the future. That’s my strong belief. The CISO challenge is to help team members along this road to a new level, where they are able to think out of the box to see what else they can bring to the job.”

Related: CISO Conversations: Aimee Cardwell

Related: CISO Conversations: Timothy Youngblood; 4x Fortune 500 CISO/CSO

Related: CISO Conversations: Keith McCammon, CSO and Co-founder at Red Canary

Related: CISO Conversations: John ‘Four’ Flynn, VP of Security and Privacy at Google DeepMind

https://www.securityweek.com/ciso-conversations-andreas-gaetje-from-economics-to-ciso-at-korber-ag/