THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.



Kim Larsen is the Group Chief Information Security Officer (CISO) at Keepit, with more than 20 years of leadership experience in IT and cybersecurity across government and the private sector. He specializes in business-driven security, aligning corporate, digital, and security strategies with risk management and threat mitigation appropriate for managing risk in line with real business priorities.
As a seasoned keynote speaker, negotiator, and board advisor, Kim has worked with organizations including NATO, EU institutions, Verizon, Systematic, and multiple industry security boards, operating at the intersection of geopolitics, technology, and executive decision-making.
Could You Talk About Your Professional Journey And Current Responsibilities As The Ciso At Keepit?
I have built my career in environments where trust, resilience, and operational discipline are not optional. That includes time in the police and military, as well as international institutions and global technology companies. Those environments teach you very quickly how to separate signal from noise, how to prioritize under pressure, and how to reduce risk in ways that hold up in the real world, not just in policy documents.
Working across international contexts also teaches you that security has to function across cultures, regulatory systems, and complex supply chains. If it cannot operate consistently across those realities, it does not scale. For me, that means building frameworks that are clear, measurable, and practical so teams can apply them consistently rather than simply understand them in theory.
During my time supporting large global networks, including at Verizon, I learned a lesson that still guides me. Security cannot be added at the end. It has to be engineered into systems, processes, and decisions from the beginning.
“Alignment happens when leadership can clearly see the trade-offs. They need to understand what we are protecting, why it matters, and what good actually looks like.”
At Keepit, my responsibility is to protect customer data and strengthen our cyber resilience as we grow internationally. I see security as a business capability. My role is to ensure we have the right controls, genuine visibility into risk, and a culture where security supports our mission to deliver trusted, future proof SaaS data protection.
As Cyber Threats Become Increasingly Dynamic And Unpredictable, How Do You Envision The Ciso Role Evolving, Especially Within Cloud-Based Backup And Recovery Environments?
The threat landscape has shifted. We are no longer dealing primarily with isolated incidents. We are dealing with persistent pressure, disruption, and targeted interference with infrastructure and data. That is becoming the baseline.
I think the role of the CISO is moving away from the illusion of control and toward something more honest and durable. The first step is acknowledging what we do not control. From there, the real work begins, which is building visibility and resilience where it actually matters.
In cloud based backup and recovery environments, the attack surface is broader than many people assume. It includes identities, integrations, administrators, APIs, and third parties. Risk accumulates in those dependencies. Managing that risk requires transparency with partners and vendors. It requires measurable and centrally governed security. Without that discipline, shadow IT expands quietly and accountability becomes fragmented.
Frameworks such as NIS2 can be constructive because they introduce discipline at a time when risk evolves faster than traditional control models. But compliance is not the end goal. What matters is clarity. I need the board to understand our threat picture and trust the foundation behind it. That means translating complex signals into decisions leadership can act on. My responsibility is to reduce noise and elevate judgment.
With Keepit’s Rapid Expansion Across Regulated And Global Markets, What Strategies Do You Use To Maintain Alignment Between Cybersecurity Operations, Executive Priorities, And The Company’s Mission?
I start from a simple premise. Cyber threats are global. If I truly understand our product and architecture, it does not matter whether we are operating in Australia or Europe. The core challenges are the same. I focus on building one strong security baseline and then adjusting it to reflect local regulatory requirements and risk realities.
Some markets attract more attention. Some organizations operate with a higher risk profile. What changes across regions is not the nature of the threat itself but the level of risk appetite and regulatory pressure. My role is to establish a solid foundation and then adjust the technical and geopolitical levers so we are prepared for different contexts.
Alignment happens when leadership can clearly see the tradeoffs. They need to understand what we are protecting, why it matters, and what good actually looks like.
If I spend my time reacting to every minor issue, I lose the broader perspective. So I prioritize carefully. Controls that protect customer trust, operational continuity, and recovery readiness always come first.
I also pay close attention to the physical and human dimensions. When pressure increases, it is people, process, and culture that determine whether security holds.
How Has Your Experience Across Nato, Eu Security Institutions, And Major Technology Organizations Influenced Your Approach To Risk Management, Threat Mitigation, And Resilient Digital Infrastructure?
My experience serving as a delegate to security committees in NATO and the EU, and later as CISO in global technology organizations, shaped how I think about risk in environments influenced by geopolitics and uneven risk appetites.
In those settings, threats are not theoretical. Assumptions are tested continuously. You learn to operate in conditions where dependencies shift and where resilience must function even when circumstances are uncertain.
Working across countries and cultures strengthened my ability to design security and compliance frameworks that hold up in complex conditions. Expectations and tolerance for risk differ significantly. I learned to design for principle and for practicality at the same time. Strong standards are important, but they have to be executable in day to day operations.
That is why transparency and trust are central to my approach. Teams need to understand why a control exists, what it protects, and how success is measured. If policies do not align with daily work, people will work around them. That is where unmanaged risk quietly develops.
At Keepit, I apply this mindset by focusing on measurable security, clear ownership, and controls that function coherently across people, process, and technology. The objective is always the same. Protect customer data and ensure recovery remains possible, even in unpredictable environments.
What Guidance Would You Offer To Emerging Cybersecurity Leaders Seeking To Transition From Technical Specialists To Strategic Advisors?
I believe the transition begins with perspective. Technical depth remains important, but influence comes from context and prioritization rather than from knowing the most.
The qualities I value most are measurability, transparency, realism, and the ability to listen beyond the IT function. Security leaders need to collaborate across the business. When that happens, security becomes a capability the organization depends on rather than something it works around.
Communication is decisive. Boards do not need to hear about every threat. They need to understand the few that truly matter and that represent broader systemic risk. My responsibility is to translate complexity into clarity and help leadership make informed, calm decisions based on evidence.
That is how security earns credibility at the executive level and sustains it.