Maurizio Imperadore, Head of the Cybersecurity Team at Connect S.p.A., brings a network engineering background to the CISO role, with experience spanning telecommunications, network design, Cisco and HP systems, and Session Initiation Protocol (SIP). His approach to cybersecurity is grounded in operational resilience: making the most of existing security investments, maintaining strong identity controls, and ensuring security decisions are tied to business continuity.
In this edition of CISO Tips, Imperadore shares practical lessons on where security teams should focus their time and resources. From enforcing zero exceptions on MFA to replacing lengthy risk reports with a single-page executive dashboard, his advice centers on reducing noise, communicating risk in financial terms, and building a security program that protects the operations the business depends on most.
Before you buy any new security tool, first…
Ensure you are fully utilizing the native security capabilities of your existing stack.
What’s one rule you enforce on your team that other teams would find strict?
Zero exceptions on MFA and identity verification, even for emergency admin actions.
What’s a number or ratio that guides how you allocate budget, headcount, or your own time?
The 80/20 rule: 80% on core operational resilience and visibility, 20% on new security innovation.
What’s one line that works when asking the board or CFO for a budget?
“This isn’t an operational expense; it’s the cost of keeping our core revenue streams online.”
What should a CISO cut from their program tomorrow with zero regret?
Outdated annual compliance training that tick boxes without changing user behavior.
What’s your 60-second test for whether a vendor pitch is worth your time?
If they can’t clearly articulate the specific problem they solve without using buzzwords in the first minute.
What’s one meeting, report, or process you eliminated, and what replaced it?
Eliminated lengthy monthly risk slide decks and replaced them with a dynamic single-page executive dashboard.
In the first 10 minutes of an incident, what’s the one action teams most often skip?
Pausing to establish clear incident roles and dedicated communication channels before touching systems.
What’s one question every CISO should ask their team this week?
“Which alert or process is generating the most noise and wasting your time?”
What’s a phrase or framing you use to translate a technical risk for executives?
Translating technical vulnerabilities directly into financial downtime: “If X fails, core operations stop for Y hours at a cost of $Z.”
What’s your best tip for surviving the CISO role in exactly five words?
Prioritize relentlessly, delegate, rest daily.
More tips from the series:
CISO Tips: Jigar Shah on Buying Fewer Tools, Building More Trust
CISO Tips: Andy Curtis on Turning Cybersecurity Into Business Risk Decisions
CISO Tips: Carlos García Batista on Turning Cybersecurity Into Operational Resilience
CISO Tips: Sergey Tairyan on Thinking Like an Attacker and Leading Through Cyber Risk
CISO Tips: Kristin Lowery on Turning Security Activity Into Measurable Risk Reduction


