THANK YOU FOR SUBSCRIBING
Kim Larsen is the Group Chief Information Security Officer (CISO) at Keepit, with more than 20 years of leadership experience in IT and cybersecurity across government and the private sector. He specializes in business-driven security, aligning corporate, digital, and security strategies with risk management and threat mitigation appropriate for managing risk in line with real business priorities. As a seasoned keynote speaker, negotiator, and board advisor, Kim has worked with organizations including NATO, EU institutions, Verizon, Systematic, and multiple industry security boards, operating at the intersection of geopolitics, technology, and executive decision-making. Could You Talk About Your Professional Journey And Current Responsibilities As The Ciso At Keepit? I have built my career in environments where trust, resilience, and operational discipline are not optional. That includes time in the police and military, as well as international institutions and global technology companies. Those environments teach you very quickly how to separate signal from noise, how to prioritize under pressure, and how to reduce risk in ways that hold up in the real world, not just in policy documents. Working across international contexts also teaches you that security has to function across cultures, regulatory systems, and complex supply chains. If it cannot operate consistently across those realities, it does not scale. For me, that means building frameworks that are clear, measurable, and practical so teams can apply them consistently rather than simply understand them in theory. During my time supporting large global networks, including at Verizon, I learned a lesson that still guides me. Security cannot be added at the end. It has to be engineered into systems, processes, and decisions from the beginning. “Alignment happens when leadership can clearly see the trade-offs. They need to understand what we are protecting, why it matters, and what good actually looks like.” At Keepit, my responsibility is to protect customer data and strengthen our cyber resilience as we grow internationally. I see security as a business capability. My role is to ensure we have the right controls, genuine visibility into risk, and a culture where security supports our mission to deliver trusted, future proof SaaS data protection. As Cyber Threats Become Increasingly Dynamic And Unpredictable, How Do You Envision The Ciso Role Evolving, Especially Within Cloud-Based Backup And Recovery Environments? The threat landscape has shifted. We are no longer dealing primarily with isolated incidents. We are dealing with persistent pressure, disruption, and targeted interference with infrastructure and data. That is becoming the baseline. I think the role of the CISO is moving away from the illusion of control and toward something more honest and durable. The first step is acknowledging what we do not control. From there, the real work begins, which is building visibility and resilience where it actually matters. In cloud based backup and recovery environments, the attack surface is broader than many people assume. It includes identities, integrations, administrators, APIs, and third parties. Risk accumulates in those dependencies. Managing that risk requires transparency with partners and vendors. It requires measurable and centrally governed security. Without that discipline, shadow IT expands quietly and accountability becomes fragmented. Frameworks such as NIS2 can be constructive because they introduce discipline at a time when risk evolves faster than traditional control models. But compliance is not the end goal. What matters is clarity. I need the board to understand our threat picture and trust the foundation behind it. That means translating complex signals into decisions leadership can act on. My responsibility is to reduce noise and elevate judgment.
Building Resilience into Cybersecurity
Our cover story features Keepit, recognised as the Top Data Center Security Platform in Europe 2026. The company approaches SaaS data protection through independence, operating its own cloud infrastructure to keep backup data separate from production environments. Automated backups, granular recovery, immutable storage and regional data residency give organisations greater control over how critical information is protected and restored.
Also recognised is TSplus, the Top Remote Access Software Suite in Europe 2026, which combines centralised application access with layered protection for the infrastructure supporting it. Cyber Evolution | LECS, recognised as the Top Cyber Security Solutions in Europe 2026, brings agentless network visibility across IT, OT and IoT environments to help security teams identify meaningful threats without adding unnecessary operational burden.
Victor Pettersson, CISO at Sokigo, is also recognised among the Top 10 CISOs in Europe 2026 for his work in strengthening security as a shared organisational responsibility through education, engagement and continuous improvement.
The issue also features perspectives on resilience beyond technology alone. Peter Coughlan, Associate Director for Supply Chain Risk Management at Alkermes, discusses that genuine readiness comes from understanding operational dependencies, testing realistic disruption scenarios and placing ownership close to where decisions are made. Bernard Gavgani, Senior Advisor to the Group's General Management at BNP Paribas, examines the growing importance of collective cybersecurity capacity, stronger governance and international cooperation as digital threats become increasingly borderless.
Taken together, these stories show that effective security is built through preparation as much as protection. We invite our readers to explore these perspectives and discover how European organisations are building security practices designed to hold when they matter most.