Stefano Pasotti, CISO and ICT Manager at DN Automotive Italy, brings a pragmatic perspective to cybersecurity shaped by years of experience across software development, IT leadership, manufacturing, and logistics. In his role, he oversees cybersecurity, infrastructure, and digitalization initiatives across European operations, where technologies ranging from WMS and production planning to EDI and IoT must work securely and reliably.
For Pasotti, effective security is ultimately about making better business decisions. His approach emphasizes measurable risk reduction over flashy tools, practical incident readiness over compliance theater, and clear communication that translates technical risk into business consequences such as production downtime. In this edition of CISO Tips, he shares his principles for evaluating security investments, preparing teams for incidents, working with vendors, and leading security programs with discipline and reflection.
Complete this sentence: “Before you buy any new security tool, first...”
...I ask myself how much it actually reduces our risk percentage, how much it really makes us safer. Is it a necessary move, or just a ‘cool tool’?
What’s one rule you enforce on your team that other teams would find strict?
Document everything. An experience that isn’t written down is an experience lost.
What’s a number or ratio that guides how you allocate budget, headcount, or your own time?
Training before tools, always. It only takes one wrong click to waste a thousand technology solutions.
What’s one line that works when asking the board or CFO for a budget?
I put risk on the table, not the tool. How much risk is the company willing to take? How much downtime can we afford, and how likely is it to actually happen?
What should a CISO cut from their program tomorrow with zero regret?
Some certifications that only exist for the plaque on the wall. If they change nothing in practice, they’re just time spent — not security.
What’s your 60-second test for whether a vendor pitch is worth your time?
“If they throw around technical jargon at random, or bombard me with overly detailed questions that make no sense at this stage, I know right away they haven’t listened. Same if they show no interest in understanding who we are and what we do before pitching us something: they’re not selling a solution, they’re selling a script.”
What’s one meeting, report, or process you eliminated, and what replaced it?
I rarely eliminate; I prefer to rebuild. The latest case: incident response policies and runbooks that only existed on paper — I rewrote them to be truly operational, not just a compliance exercise.
In the first 10 minutes of an incident, what’s the one action teams most often skip?
Stopping to think. Speed is critical, so the temptation is to act immediately — but acting without a moment’s reflection can cause more damage than the incident itself.
What’s one question every CISO should ask their team this week?
If it happened right now, would we actually know what to do, or would we be improvising?”
What’s a phrase or framing you use to translate a technical risk for executives?
I translate everything into production downtime. Once the risk is clear to everyone, then we talk solutions.
What’s your best tip for surviving the CISO role in exactly five words?
Stop, reflect, then take action.


