# The Auditor Who Became a CISO: What Andreas Gaetje's Career Says About Who Gets to Lead Security


There's a reasonable chance that a vaccine you received — for flu, COVID, or something else — was processed by a machine built by a company you've never heard of. Körber AG, a German technology and manufacturing conglomerate with 13,000 employees spread across a hundred locations, sits in that invisible layer of the global supply chain: critical infrastructure without a consumer brand.


That makes the company a fascinating case study in industrial cybersecurity. And its CISO, Andreas Gaetje, is an equally interesting study in how security leadership actually gets built — because he didn't start as a hacker, a programmer, or even a systems administrator.


He started as someone who cared about economics and business politics.


## The Audit Pipeline Nobody Talks About


When people sketch the archetypal CISO origin story, it usually involves a teenager disassembling a PC, a CTF team in college, or a stint reverse-engineering malware at a government agency. Gaetje's path was different: he fell into the computer industry in the mid-1990s out of financial necessity, joined a consulting firm, then moved to an insurance company where he became an auditor.


"ITsec and audit had a natural affinity," he told SecurityWeek. "ITsec was primarily about compliance — it wasn't yet the business threat it has since become."


This is a path that produces more CISOs than people realize, and it's chronically undervalued in conversations about security talent pipelines. Auditors learn something that most engineers don't: how business processes fail, where controls drift from documentation, and how to communicate risk to people who don't speak TCP/IP. Gaetje explicitly credits his business knowledge as the foundation that made his security career possible — not a technical credential.


That framing matters now more than ever. The CISO role has been fragmenting for years between two competing models: the technical CISO who can dig into packet captures and threat intelligence, and the business-aligned CISO who operates closer to the board and manages vendors, risk frameworks, and regulatory exposure. Neither is wrong. But the industry still defaults to assuming the former is the "real" version of the job.


Gaetje is a deliberate counterexample.


## 2017 Changed Everything — Including What CISOs Need to Be


The timeline in Gaetje's career intersects with a pivotal moment in security history. He describes the 2010s as when "the fun started" — which is one way to characterize the era that gave us WannaCry and NotPetya.


NotPetya in particular was a clarifying moment for manufacturing and logistics. Maersk lost an estimated $300 million. TNT Express, part of FedEx, posted a $400 million hit. Dozens of industrial and pharmaceutical companies were hit across Europe. The attack weaponized a supply chain software update from Ukraine and spread through corporate networks that had prioritized uptime over segmentation.


Companies like Körber — embedded in pharmaceutical manufacturing, industrial equipment, and supply chain logistics — were exactly the type of target that NotPetya exploited. Not because they were directly targeted, but because their operational technology environments and interconnected partner networks created attack surfaces that compliance-driven security teams had systematically underweighted.


"We weren't talking about a simple compliance issue anymore," Gaetje said. "This was a serious business threat."


That shift — from ITsec-as-compliance to security-as-existential-risk — is exactly where someone with Gaetje's background becomes an asset rather than a liability. He understood business continuity, risk quantification, and how to translate technical failure into board-level language. The finance and insurance sectors where he'd spent the prior decade had already done that translation, under regulatory pressure from Basel II and Solvency II, years before manufacturing caught up.


## The Advice That Actually Matters


Gaetje offers one piece of career guidance that stands out: if you want to understand security, don't stay too long in any one company or industry sector.


This runs counter to how security careers typically develop, where depth in a specific domain — cloud, OT, AppSec, identity — is the valued commodity. Generalist paths get dismissed as lacking rigor.


But Gaetje's argument is that different industries have fundamentally different risk profiles, and staying too long in one sector calcifies your threat model. A security professional who spends fifteen years in financial services has a sophisticated understanding of fraud, insider threat, and regulatory compliance — and a potentially naive understanding of operational technology, supply chain risk, or pharmaceutical manufacturing constraints.


The cross-sector move forces re-examination of assumptions that felt like universal truths but turned out to be industry-specific patterns. That process of re-examination is, arguably, where security judgment actually develops.


## HackWire Analysis


The Gaetje profile arrives at a moment when the CISO talent pipeline is being scrutinized from multiple directions. CISOs are burning out at record rates, tenure has dropped to under three years at many organizations, and boards are demanding leaders who can hold an intelligent conversation about cyber risk without requiring a glossary.


What the profile doesn't say explicitly, but implies clearly: the audit-to-CISO track produced a CISO who has lasted. Gaetje has been at Körber since 2018 — first at Körber IT Solutions, then elevated to the group CISO role in 2019. That's seven years. In an era of 24-month average tenures, that's remarkable, and it's worth asking why.


The answer probably has less to do with technical depth and more to do with business fluency. CISOs who can articulate risk in financial terms, who understand how operational constraints trade off against security controls, and who have the boardroom credibility to get budget approved — those are the people who survive. The pure technicians who can't translate their knowledge upward tend to cycle out faster, regardless of how brilliant they are technically.


There's also a supply chain angle here that deserves more attention. Körber makes equipment used in pharmaceutical manufacturing, tobacco processing, tissue production, and logistics. The attack surface for a company like this includes not just IT infrastructure but operational technology embedded in production lines, plus the software and service relationships connecting them to pharmaceutical customers under regulatory scrutiny. The CISO of a company in that position needs to understand GMP (Good Manufacturing Practice) compliance, FDA cybersecurity guidance for medical device adjacent systems, and the operational constraints of environments where you can't just patch and reboot. That's not a bit-crawler problem. That's an OT/IT convergence problem that requires the exact profile Gaetje represents.


The broader pattern: as cybersecurity matures from a technical specialty into a business function, the career paths that produce effective security leaders are diversifying. The industry should stop treating that as a dilution of standards and start recognizing it as an evolution of requirements.


— HackWire Editorial


## Related Coverage


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)