THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Christos Syngelakis, Group Chief Information Security Officer (CISO) at Motor Oil, has garnered decades of experience in the oil and energy industry in managing and ensuring enterprise-level cybersecurity. Equipped with strong leadership skills and strategic industry expertise, he has been responsible for the security strategy of information systems, operational technology, and the correct use of personal data. He has served as an IT infrastructure and operations manager in many diversified industries for the past 18 years.
In an interview with Enterprise Security Magazine APAC, Syngelakis sheds light on some of the major challenges prevailing in enterprise security management and how setting up the right team, rather than using ChatGPT and AI-driven solutions, can play an instrumental role in strengthening the cybersecurity dynamics framework.
How do you think trends like ChatGPT will impact the future of the cybersecurity arena?
ChatGPT and other AI-driven technology solutions are far flung from reality. However, they will soon be widely leveraged. In the cybersecurity space, it is the infrastructure that we predominantly deal with. ChatGPT and other AI technology solutions are instrumental in sharing knowledge about attack and defense strategies, but they are limited to being used by novices. The experts already know how to work around their way in cybersecurity.
“Collective efforts from the entire team are more effective in tackling issues rather than individual efforts. All in all, having the right team in place is integral to strengthen the cybersecurity posture of organizations.”
The central aspect of cybersecurity is an endless to-and-fro attack and defense between machines. However, relying on machines alone is not going to serve the purpose. Cybersecurity professionals cannot judge the effectiveness of a machine’s ability to defend based on a particular environment because one size does not fit all. Using the same tactic to defend in one environment can turn out to be catastrophic in another. Although AI can improve attack and defense strategies, it is not the main aspect of cyber defense.
What, according to you, are the challenges faced by cybersecurity experts?
The challenges differ from one industry to another. For example, regulatory compliance and intellectual property breaches pose dire challenges when it comes to IT security. With a supportive internal team, organizations can accordingly implement robust solutions to safeguard their office environment.
However, there are other core areas, like industrial security, that must be paid attention to. With the huge underlying issue in the industrial environment caused by a lack of security, the need to always be connected and safely transfer information between different groups like the production and management teams and customers is more pronounced.
Organizations can address the issue differently in the office and the industrial environments. In the office environment, problems can be solved with the right mentality, money, and manpower. On the other hand, with multiple ongoing activities and innumerable issues, there is a serious dearth of solutions to enhance security in the industrial environment. It is not possible to hold one individual accountable for every attack that takes place in such an environment.
From the engineering perspective, industrial engineers are adept at running the infrastructure but do not possess complete knowledge of problems that exist in the cybersecurity space. There are major concerns about such issues because the problems in critical infrastructure are huge and can have deep implications for the public.
How significant is it for companies to source the right talent with deep-rooted expertise in cyber security?
There are two critical skills that organizations require in this line of work. The first would be strategic planning and security design, and architecture of solutions. For this purpose, businesses need an internal team who knows the organization inside out—the operations, the day-to-day challenges, and the employees. The internal cybersecurity team members can reap a higher level of efficiency if they are in complete alliance with other each other.
A CISO must also have a professional in the internal team who can understand technical architecture. This professional must be in a position to directly report to the CISO and properly understand the GRC concepts to run the risk assessments and the regulatory compliance procedures. The second skill is the implementation of cybersecurity solutions, which can be outsourced.
Having a CISO with ingrained technical knowledge and soft skills certainly adds value to the cybersecurity aspect of a company, but finding one is a challenge. Due to this acute talent crunch, novices are filling up the CISO positions.
What would be your word of advice for your peers in the industry?
Organizations must remain true to their words when speaking with industry peers. It is always better to give a clear picture of the existing problem while proactively searching for solutions to overcome it. If you are not a part of the solution, then you are a part of the problem. Overcoming fears can pave the path to achieving cybersecurity resilience. With too many tasks that need to be done to ensure security, businesses require all the necessary support from their cybersecurity team.
Of course, it is not easy to discuss these topics at the upper level of management because their responsibilities are not limited to handling cybersecurity problems. There are numerous other economic and political problems and risks pertaining to fires and hurricanes that they need to manage. Collective efforts from the entire team are more effective in tackling issues rather than individual efforts. All in all, having the right team in place is integral to strengthening the cybersecurity posture of organizations.