THANK YOU FOR SUBSCRIBING

Strengthening Security Leadership for a New Digital Era


In an interview with Enterprise Security Magazine Europe, Victor Pettersson, Chief Information Security Officer at Sokigo, reflects on the evolving demands of cybersecurity leadership, the organization’s transformation journey, and the strategic role of security in building resilient, future-ready digital services.
With a foundation in IT security engineering and extensive experience across managed security services, network operations, and enterprise compliance, Pettersson has shaped Sokigo’s modern security function, guiding the organization through ISO 27001 certification, AI-driven security enhancements, and the development of a company-wide security culture. His approach centers on education, accessibility, and continuous improvement, ensuring security is embedded not as a barrier but as an enabler of innovation.
The Journey That Shaped My Path To Ciso
My journey in cybersecurity began when I chose to study IT security in Stockholm, drawn to its ever-evolving nature and the constant opportunity to learn, adapt, and explore new challenges.
After graduating, I joined GlobalConnect, an ISP operating across the Nordics, where I worked in B2B support. This role provided me with a deep foundation in understanding complex national and multinational networks. It shaped my appreciation for the fundamentals of network architecture, operating system security, and the broader ecosystem of network defense, knowledge that continues to inform my leadership today.
My next chapter took me to Orange Cyberdefense, one of Europe’s largest MSSPs. I began as a SIEM specialist and eventually became the technical lead for the Microsoft Sentinel managed security service. Leading this initiative strengthened my ability to translate stakeholder needs into scalable technical solutions and taught me how to operationalize security across large environments. It also grounded me in project management and helped me refine the strategic lens that now guides my work at the executive level.
Joining Sokigo marked a significant shift. I started as an Information Security Officer with a clear mandate to strengthen our security capabilities and prepare for accelerated regulatory and threat-driven change. It soon became evident that the organization needed a dedicated CISO to shape this agenda. Stepping into that role allowed me to influence not only our technical roadmap but also our culture, decision-making, and long-term readiness as a provider of essential digital services.
Strategic Programs That Delivered Measurable Organizational Value
One of the most impactful programs I have led at Sokigo is our ISO 27001 certification journey. We achieved certification last year, and it has significantly strengthened both our security posture and our operational maturity.
The process introduced greater structure across the organization and created meaningful feedback loops that allow us to identify improvement areas early and address them consistently. More importantly, it enhanced the quality and reliability of our deliveries, ensuring our customers benefit from a more predictable, transparent, and secure operating model.
ISO 27001 also improved cross-functional collaboration, helping teams speak a shared language around risk, documentation, and accountability. It moved us from isolated security practices to a more cohesive, organization-wide commitment to improvement.
Building High-Performing Security Teams Through Education And Engagement
I have always viewed the CISO role as part strategist and part educator. No organization can depend on a single person to manage security. It must be embedded into the daily decisions of developers, project managers, product teams, and operational staff. My focus has been on helping people understand why security matters and how it directly contributes to delivering better products, stronger customer trust, and improved organizational outcomes.
When employees understand the threat landscape and recognize their influence on security, they become active participants rather than passive recipients of policy. That cultural shift of building awareness, fostering engagement, and empowering teams has been central to strengthening our resilience.
Why Sokigo Invested In A Dedicated Ciso
The decision to invest in a dedicated CISO role emerged from the convergence of two realities: a rapidly escalating threat landscape and an increasingly complex European regulatory environment. Emerging AI-powered threats were reducing the time required to create and deploy sophisticated malware, making it clear that proactive leadership was needed to stay ahead. At the same time, major EU regulations such as the NIS2 Directive, the CER Directive, the Cyber Resilience Act, and the AI Act introduced new compliance expectations that required dedicated oversight.
More fundamentally, the role was created to ensure that the digital solutions we deliver remain secure, stable, and reliable for our customers. Security is not an isolated function at Sokigo. It is central to maintaining the trust we have earned as a provider of critical public-sector solutions. Establishing a CISO was a strategic commitment to strengthening that trust for the future.
Leveraging AI to Enhance Security While Preserving Human Oversight
AI has introduced powerful opportunities to improve the efficiency and quality of security operations, but only when deployed responsibly. My philosophy is that secure tools should also be the easiest tools to use. When secure solutions are more accessible than unapproved alternatives, people naturally gravitate toward them. At Sokigo, we have introduced approved AI systems that are simple, intuitive, and governed by strict contractual and technical safeguards. This ensures that data is handled responsibly, remains within the EU, and is never used to train external models.
We take the same approach when exploring internal LLM deployments. Ease of use and strong security controls must coexist. By keeping humans at the center of critical decisions, we ensure that AI enhances our capabilities rather than replacing judgment.
Advice for Security Leaders Driving Transformation
For any leader aiming to create lasting impact, my advice is that security must become an organizational habit rather than an isolated function. It should be reflected in how code is written, how projects are structured, how tools are selected, and how decisions are made every day. Education, accessibility, and continuous improvement are essential to making this possible.
When teams understand their role in security and are empowered with the right practices and tools, meaningful change happens organically. Security becomes not a mandate but a shared value, and that is where true transformation begins.