AI-Driven Cybersecurity Transformation
Q1. Could you start by giving us a brief overview of your professional background, particularly focusing on your expertise in the industry?
I've spent close to twenty years working in cybersecurity, but what really connects the different parts of my career is a focus on building and growing capabilities—not just keeping them running. When I led Cybersecurity Operations in Italy for one of the country’s top MSSPs, I managed everything from the SOC and Red Team to Cyber Threat Intelligence, Incident Response, and Security Advisory. I helped double the team from 40 to over 80 people while also launching new services and taking on direct go-to-market responsibilities. Managing the entire range of services, rather than focusing on just one area, pushed me to see cybersecurity operations as a single, integrated business instead of a collection of separate technical functions.
After that, I took on a General Manager role for Cybersecurity in the DACH region. My job was to build cybersecurity operations from scratch: understanding the local market, shaping the service model and priorities, building vendor partnerships, testing the go-to-market strategy, and setting up delivery teams. At the same time, I focused on ensuring our work in DACH stayed connected to our global teams, so we could scale and future-proof the local business instead of operating as an isolated branch.
These days, I work as a Senior Strategic Consultant to major clients, partnering with C-level leaders as they shape their cybersecurity strategy. I bring the ability to connect business goals with practical technical execution. I help translate the board’s risk appetite and commercial priorities into plans operations teams can deliver on—and I also make sure the board gets an honest picture of what’s happening on the ground, not just what’s shown in presentations. My strength is in bridging regulations, technology, and governance, making sure nothing gets lost in translation between the business and technical sides.
Q2. What structural forces do you believe are fundamentally reshaping the cybersecurity industry today, and which of these are likely to have the most lasting impact?
Three big forces come to mind, and I’d rank them by how long-lasting I think they’ll be.
First, new regulations like NIS2, DORA, CRA, RED, and others are changing how companies decide where to spend their security budgets. For a long time, the story driving industry spending was all about attack numbers—how cyberattacks kept getting more frequent and more sophisticated. That certainly led to more investment, but it wasn’t enough, and it clearly wasn’t working as well as hoped, since attacks kept rising anyway. What’s changed is that regulations with real accountability for executives have pushed spending to grow even faster—way more than threat statistics alone ever could. Security is now seen less as a way to reduce risk and more as a way to survive in a regulated environment. When execs are personally on the hook, spending on security is no longer a nice-to-have—it’s non-negotiable.
Second, we’re seeing more “platformization”—where lots of narrow, specialized solutions are getting bundled together into bigger, more comprehensive platforms. This trend has a big impact, but I don’t think it’s permanent. Every time things get consolidated, it tends to set the stage for new, specialized solutions to pop up again once the big platforms become too rigid.
Third, there’s the arrival of AI—which is shaking things up on both sides. For attackers, AI makes it easier and faster to build and scale their operations. Defenders, in turn, are having to adopt AI themselves to keep up. I see this most clearly in MSSP SOCs, where AI is taking over much of the triage work. The real shift is that analysts are moving away from endless alerts and can now focus on higher-value work—like deep investigations and judgment calls—where human expertise still matters most.
Q3. How is the competitive landscape changing as platform vendors, cloud hyperscalers, and niche cybersecurity specialists increasingly compete for the same enterprise budgets?
This isn’t just background noise—it’s a real structural squeeze. Hyperscalers have a lasting edge in distribution and bundling. For example, Microsoft including security in its E5 licensing creates real budget headaches for specialized vendors, and it’s not something a better product alone can solve. We’re seeing the same thing happen with AWS and Google Cloud, wherever security gets bundled into the infrastructure or productivity contracts customers already need to renew. That bundled approach doesn’t have to be the best technically to win out—it just has to be “good enough” and already covered in the bill.
But it’s not as simple as hyperscalers winning everything. What’s really happening is a split. Basic detection, identity, and posture management are moving toward the big platform bundles because it costs vendors almost nothing to add those features, and it’s easy for buyers to approve them. On the other side, specialists are thriving by focusing deeply on areas where platforms can’t compete, either because the technology is too complex for generalists to copy or because regulatory needs are so specific that only a true specialist can deliver the right solution.
The services that tend to hold up best—despite pricing pressure—aren’t the basic monitoring functions, but the ones where real specialist know-how is the product: things like CTI, Cloud Security, and DFIR, as well as sector-specific areas like OT security. That’s why I think the mid-market generalist, who doesn’t have the massive reach of a hyperscaler or a defensible technical niche, is in the toughest spot. They’re getting squeezed from both directions, and I’d expect to see many of them consolidate or even disappear in the next few years.
Q4. How have enterprise cybersecurity buying decisions evolved over the past few years, and what factors now carry the greatest weight during vendor selection?
One of the biggest changes I’ve seen is that procurement now involves legal, risk, and even the board—not just IT and the CISO. In my conversations with CISOs, it’s clear they’re expected to bridge the gap between business and technology in real time, since budget approvers are no longer just technical experts. If a vendor only talks about technical features—like detection rates, coverage, or integrations—the message often misses the mark unless it first frames them in terms of risk and liability.
A few other factors now matter much more than before. Concrete proof of regulatory alignment matters more than vague promises about best practices—buyers want to see exactly how a vendor will help them prove NIS2 or DORA compliance, not just hear that it’s supported. The total cost of getting a new tool up and running now matters more than the sticker price; many buyers have learned the hard way that a cheap tool with lots of tuning and integration headaches can cost more in SOC headcount than a more expensive, truly turnkey solution. Vendor resilience has also become a deciding factor—buyers now dig into a vendor’s own business continuity and supply chain, partly because rules like DORA and NIS2 make financial-sector customers treat their security vendors as another layer of risk to manage, not just a service to buy.
Buyers are also paying much closer attention to what happens after the contract is signed—how well a vendor delivers on its promises, not just how good its sales pitch sounds. References and real-world proof of delivering at scale matter far more in final decisions than they did a few years ago.
Q5. Beyond AI-powered threat detection, which emerging technologies do you believe will create the next wave of cybersecurity innovation?
There are three areas I’d keep an eye on, though it’s hard to say exactly when each will take off. First is post-quantum cryptography migration tools—not because quantum attacks are right around the corner, but because “crypto-agility” (the ability to easily swap encryption methods without rebuilding everything) is fast becoming something buyers and auditors ask about. Big organizations and regulators now expect migration plans as a basic part of governance, which means demand for these tools is already growing well before a real-world quantum threat.
Second is the challenge of non-human identity and machine-to-machine authentication. Things like workloads, service accounts, APIs, and now even autonomous AI agents are multiplying much faster than human identities ever did. Most current identity tools were built for a world with about as many machine identities as people, but that’s no longer true. I expect the identity security market will shift significantly to address this gap in the coming years.
Third is security around the convergence of OT and IT—especially in industrial and manufacturing settings. From what I’ve seen, this area is still underserved compared to the regulatory pressure that’s building, especially with new requirements like Machine Regulation and CRA pushing companies toward capabilities they often don’t have yet.
That said, I wouldn’t bet everything on any one of these being “the next big thing.” The market still hasn’t settled on which will become a lasting category with its own vendor ecosystem, and which will remain important but more niche. I’d be cautious about anyone who claims to know for sure how that will play out right now.
Q6. How are regulations such as NIS2, DORA, GDPR, and evolving AI governance frameworks influencing enterprise cybersecurity investment priorities?
Regulation has become the single largest driver of budget approval in my direct experience, more than breach fear, more than insurance premium pressure. I've seen GRC & Advisory practices scale quickly on this, alongside CTI and IR, because NIS2 and sector-specific requirements made them near-mandatory line items for clients, not optional upgrades. NIS2 in particular has had a broadening effect: it pulls in a much larger population of mid-sized companies and supply-chain entities that previously sat outside formal cybersecurity regulation entirely, and many of them are now building a security function essentially from a standing start.
The practical effect, as I now see it, is a reallocation within budgets. Money moving away from generic "best practice" spend and toward specifically evidenceable controls: incident reporting mechanisms that meet regulatory timelines, third-party and supply-chain risk registers, and board-level reporting structures that can demonstrate oversight rather than just describe it. DORA pushes this further for financial services specifically, requiring genuine operational resilience testing rather than paper-based compliance exercises, which has driven real investment in testing and simulation capability that many organizations didn't have before.
AI governance frameworks are earlier-stage and considerably less settled. I expect they'll follow the same pattern GDPR did in its early years: a period of real ambiguity about what compliance actually requires in practice, followed by enforcement actions and regulatory guidance that retroactively clarify the standard. Organizations investing heavily in AI governance tooling today are, to some extent, making an educated bet on where that clarification eventually lands, rather than responding to a fully settled requirement.
Q7. If you were an investor looking at companies within the space, what critical question would you pose to their senior management?
I'd ask: "What percentage of your current gross margin depends on human analyst labor that AI-driven automation could plausibly replace within three years, and what is your actual operating plan for that transition. Not the roadmap slide, the plan?"
The reason I'd lead with this rather than a growth or churn question is that most of the industry's current valuation narratives implicitly assume one of two things: either that AI-driven automation erodes competitors' margins while somehow sparing theirs, or that they'll manage to re-platform their labor-heavy service lines onto an automation-first delivery model before a leaner competitor undercuts them on price. Both are comfortable assumptions to put in an investor deck. Very few management teams can actually answer the question with a real operating model: headcount trajectory, retraining plan, revised pricing model, margin bridge, rather than a slogan about "AI-augmented analysts" that doesn't survive a second follow-up question.
For an MSSP or any service-heavy security vendor specifically, this single question tends to separate genuine structural advantage from a story that only works as long as top-line growth is large enough to mask the underlying labor economics. A management team with a real answer will typically have already restructured its delivery pyramid and repriced at least part of its portfolio. It can point to a concrete reduction in cost-to-serve that isn't just attributed to scale. A management team without a real answer will talk about AI in the future tense and pivot quickly back to bookings growth, which is itself useful information for an investor, because it tells you the margin risk hasn't been priced into their own thinking yet, let alone into the valuation you're being asked to pay.
Need an expert in this space?
Talk to an Industry Expert
Knowledge Ridge connects decision-makers with carefully vetted subject matter experts for one-on-one calls, research sprints, and advisory engagements — across 11 sectors and 163 sub-industries globally.
Comments
No comments yet. Be the first to comment!