**Navigating the Future of Cybersecurity: A Leader’s Perspective from Andreas Gaetje, CISO of Korber AG**
In the ever-evolving landscape of global technology, certain companies operate behind the scenes yet form the bedrock of modern commerce. Korber AG is one such entity. As the holding company for a diverse German technology and manufacturing organization with approximately 13,000 employees across 100 locations worldwide, Korber facilitates essential services for consumer supply chains. A notable quote from the company encapsulates its pervasive influence: “Take Pharma,” comments CISO Andreas Gaetje. “Probably every vaccine you ever received has been through our machines.”
Despite its scale and significance, Korber remains obscure to the average consumer. Leading this complex security operation is Andreas Gaetje, whose own career path offers a unique blueprint for aspiring cybersecurity professionals. Unlike the stereotypical “tech genius” who grew up coding, Gaetje’s journey into cybersecurity was a pivot born from pragmatic economics and business interests, proving that a deep technical lineage is not the only route to the C-suite.
### The Route to CISO
Gaetje’s career began with a focus on economics and business politics, with aspirations for public service. However, the mid-1990s demanded a different skillset as the internet transformed from an academic tool into a business necessity. “I said to myself, Okay, let’s maybe do something in the computer business,” he recalled, entering the field through a consulting firm. By the early 2000s, he deliberately chose to focus on a single sector: finance, joining an insurance company where he started as an auditor.
It was here that he discovered the symbiosis between business, IT, and security. In an era when cybersecurity was more aligned with audit and compliance than active business defense, Gaetje’s diverse background positioned him perfectly. He was asked to manage the growing information security area, a role that evolved significantly through the era of major attacks like WannaCry and NotPetya. “It was very clear: we weren’t talking about a simple compliance issue anymore. This was a serious business threat,” he noted, marking his transition into a true cybersecurity leader by 2018.
### Leadership Beyond Technical Expertise
Gaetje’s ascent to CISO also illuminates the nature of leadership itself. He rejects the notion of being a “born leader,” instead viewing leadership as the ability to provide direction and vision. “It’s something you can learn,” he insists, emphasizing that personality traits like reliability and trustworthiness are foundational, but the management skills and strategic vision required for the role are honed through training and experience.
This philosophy extends to building his team. The cybersecurity industry faces a significant skills gap, yet Gaetje looks for an intangible quality above all: a desire to learn. “Cybersecurity is something where you must learn something new every day,” he states, explaining that the rapid evolution of threats, particularly those leveraging AI, means his team must be engaged, curious, and proactive. Interestingly, while he values enthusiasm and a “white hat” mentality, he draws a clear line at hiring individuals with a history of malicious “black hat” activity.
### Adapting to the AI Era
A primary concern for Gaetje is the unprecedented speed of technological development. “The pace of new technology is truly hard to manage,” he says, citing AI as a prime example. This technology is a double-edged sword: attackers use it to scale sophisticated attacks, while defenders use it to build new defenses, which in turn can be manipulated. This creates an environment of “shadow AI,” where unauthorized AI tools proliferate within corporate networks.
There is also concern that AI will diminish the need for certain security roles. Gaetje believes the opposite to be true; the role of the CISO will become more critical as AI creates problems that require human oversight to guide other business units, such as product development and software engineering, in securing their innovations. While AI may automate tasks, it also risks creating skill gaps. For instance, coders who rely on AI assistants may miss foundational programming knowledge, and security analysts may lose critical analytical skills if AI handles all tier-1 triaging. “If we just rely on AI, we will lose the ability to see the tricky things in an incident,” he warns.
### Guiding the Team Forward
Ultimately, Gaetje sees adaptation as the key challenge for the entire security team. The CISO’s role is not just to protect existing systems but to lead the cultural and operational shift required to integrate new technologies responsibly. “The job of the security team will change dramatically in the future,” he concludes. “The CISO challenge is to help team members along this road to a new level, where they are able to think out of the box to see what else they can bring to the job.”
—
### FAQ Section
**Q1: What is the primary concern for cybersecurity leaders today according to Andreas Gaetje?**
**A1:** Gaetje’s primary concern is the speed of new technology development, particularly AI. The rapid pace at which new products and techniques are deployed makes it difficult for security teams to learn and understand the technology fast enough to defend against its misuse by attackers.
**Q2: How does Andreas Gaetje view the impact of AI on the security profession?**
**A2:** Gaetje views AI as a double-edged sword. While it empowers attackers with greater speed and sophistication, it also equips defenders. He is not concerned that AI will make the CISO role obsolete; instead, he believes it will make the role more important as security becomes too critical for a single team to handle alone, requiring collaboration with other business units.
**Q3: What advice does Gaetje give for building a cybersecurity team?**
**A3:** He emphasizes that while a wish list of skills is ideal, reality often differs. The one constant requirement across all candidates is a **desire to learn**. Because the threat landscape changes so rapidly, curiosity and a commitment to continuous learning are more essential than specific, static technical skills.
**Q4: What is his advice for ambitious cybersecurity professionals?**
**A4:** His core advice is to **”be curious.”** He stresses that the field is changing too quickly for anyone to believe they know everything. A successful career requires a constant drive to learn and experience new things.
**Q5: Does Andreas Gaetje believe a technical background is necessary to become a CISO?**
**A5:** No. Gaetje’s own path demonstrates that a CISO can emerge from a background in economics, business, and audit. He believes that a deep understanding of business function and IT security is more valuable than being a “deep bit-crawler.”
—
### Conclusion
Andreas Gaetje’s journey from an auditor in the insurance sector to the CISO of a major international manufacturing conglomerate is a testament to the multifaceted nature of modern cybersecurity leadership. His career illustrates that technical prowess is not the sole prerequisite for protecting complex digital environments; a deep-seated understanding of business, paired with an insatiable curiosity, is equally vital. As the industry confronts the challenges of AI and accelerating technological change, Gaetje’s philosophy of continuous learning and adaptive leadership provides a crucial framework for security professionals aiming to guide their organizations through an uncertain future. The role of the CISO is evolving, and as Gaetje suggests, it is the leader who helps the entire team learn to think differently that will ultimately define the security posture of their company.



