For Carlos García Batista, cybersecurity is ultimately about protecting the continuity of essential services. As CISO and Information Security Officer for the Directorate General of Emergencies within the Gobierno de Canarias, he operates at the intersection of critical infrastructure protection, emergency response, operational resilience, and regulatory compliance. His responsibilities include coordinating cybersecurity across technical and operational environments, working with authorities on incident management, and helping ensure that essential services remain secure and available when they are needed most.
That perspective shapes a pragmatic approach to security leadership, one grounded in ownership, accountability, and resilience rather than simply accumulating more tools and controls. From questioning whether a security investment actually reduces operational risk to establishing clear command structures during incidents, García Batista emphasizes the importance of turning cybersecurity into actionable decisions. In this edition of CISO Tips, he shares practical guidance on everything from evaluating vendors and securing privileged access to communicating risk with executives and knowing which security activities are no longer worth the effort.
Complete this sentence: “Before you buy any new security tool, first...”
Before you buy any new security tool, first define the operational risk you are trying to reduce, who will own the tool, who will operate it, and what decision it will help you make.
A tool without ownership becomes another unmanaged asset.
What’s one rule you enforce on your team that other teams would find strict?
No privileged access without a clear purpose, a named owner, traceability, and a review date.
Access should never be granted just because “it may be useful someday.” In security, convenience without control becomes risk very quickly.
What’s a number or ratio that guides how you allocate budget, headcount, or your own time?
I try to keep a practical balance between prevention, detection, response, and resilience.
If most of the effort goes only into buying preventive controls, the organization may look protected but still be unable to detect, respond, or recover properly. For critical services, resilience deserves budget, time, and executive attention.
What’s one line that works when asking the board or CFO for a budget?
“This is not only a cybersecurity investment; it is an operational continuity investment.”
That framing usually works because it connects security to service availability, institutional responsibility, and business or public-service impact.
What should a CISO cut from their program tomorrow with zero regret?
Security activities that generate reports but do not generate decisions.
If a report, meeting, metric, or control does not help reduce risk, improve visibility, assign responsibility, or support a decision, it should be simplified, automated, merged, or removed.
What’s your 60-second test for whether a vendor pitch is worth your time?
I ask three questions:
What specific risk does this reduce?
How will it integrate with what we already have?
Who in my team will operate it on a bad day?
If the answer is vague, the pitch is not mature enough.
What’s one meeting, report, or process you eliminated, and what replaced it?
I try to eliminate meetings that only exist to exchange information that could have been documented beforehand.
They should be replaced by short, evidence-based operational reviews: what changed, what risk increased, what decision is needed, who owns the next action, and by when.
Security governance should create clarity, not ceremony.
In the first 10 minutes of an incident, what’s the one action teams most often skip?
They often skip defining the incident commander and the decision-making channel.
Many teams start investigating immediately, but without clear coordination, roles, and communication discipline. In an incident, technical work matters, but command structure matters just as much.
What’s one question every CISO should ask their team this week?
“What are we currently accepting as normal that is actually a risk?”
That question usually reveals technical debt, informal exceptions, undocumented dependencies, weak ownership, or processes that only work because one person knows how to keep them alive.
What’s a phrase or framing you use to translate a technical risk for executives?
I translate technical risk into operational consequence.
Instead of saying, “We have a vulnerability in this system,” I prefer to say, “If this fails or is compromised, this service may be unavailable, this decision may be delayed, or this operational capability may be affected.”
Executives need to understand impact, not just threat language.
What’s your best tip for surviving the CISO role in exactly five words?
Govern calmly, document, prioritize, breathe.
More tips from the series:


