Cybersecurity leadership is rarely about having the most tools or the most elaborate security program. For Jörg Scheiblhofer, Chief Information Security Officer at ORF, effective security starts with understanding the organization’s requirements, processes, and actual risk before deciding which technologies or controls are needed. His approach emphasizes analytical thinking, consistency, and a clear understanding of the potential impact of security decisions.
In this edition of CISO Tips, Scheiblhofer shares his perspective on making better decisions under pressure, communicating cyber risk to executives through relatable analogies, and avoiding assumptions during critical incidents. From assessing the real situation in the first minutes of an attack to tailoring risk discussions for the board, his advice reflects a practical philosophy: strong cybersecurity requires sound analysis, clear communication, and a human approach.
Complete this sentence: “Before you buy any new security tool, first…”
…you have to think about process and your requirements “
What’s one rule you enforce on your team that other teams would find strict?
There are no exceptions on suspicion without an analytical basis and certainly no general exceptions.
What’s one line that works when asking the board or CFO for a budget?
It is not a single sentence; rather, it is a presentation, tailored to the target audience, of the risks that exist or may arise if measures are not implemented.
What’s your 60-second test for whether a vendor pitch is worth your time?
Has he dealt with his potential customer?
What’s one meeting, report, or process you eliminated, and what replaced it? -
In the first 10 minutes of an incident, what’s the one action teams most often skip?
Accurately assessing the actual situation. In the heat of the moment, this is often overlooked. What’s one question every CISO should ask their team this week?
What’s a phrase or framing you use to translate a technical risk for executives?
I like to use the creation of analogies from everyday life. In a way, a language in pictures, so that management can imagine something better.
What’s your best tip for surviving the CISO role in exactly five words?
1.) remain consistent 2.) adopt an analytical approach 3.) tailor communication to the target audience 4.) assess the risk and potential damage 5.) remain human
More tips from the series:
CISO Tips: Maurizio Imperadore on Resilience, Identity and Cutting Security Noise
CISO Tips: Jigar Shah on Buying Fewer Tools, Building More Trust
CISO Tips: Andy Curtis on Turning Cybersecurity Into Business Risk Decisions
CISO Tips: Carlos García Batista on Turning Cybersecurity Into Operational Resilience
CISO Tips: Sergey Tairyan on Thinking Like an Attacker and Leading Through Cyber Risk


