Cybersecurity Star Izabella Stueflotten
top of page

Cybersecurity Star Izabella Stueflotten

  • 10 hours ago
  • 9 min read

An interview with Izabella Stueflotten


Cybersecurity strategist Izabella Stueflotten
Cybersecurity strategist Izabella Stueflotten

In an era where cyber threats are evolving at a breakneck pace and regulatory pressures are at an all-time high, Izabella Stueflotten is a voice of clarity.


As the VP of Digital Security Strategy at Elasticito, Izabella has carved out a distinguished career spanning more than two decades, rising to the highest echelons of the male-dominated cybersecurity sector to lead European contracts for the entire network.


Known for her unique blend of technical expertise and a vibrant, approachable communication style, she excels at translating complex compliance frameworks like DORA, GDPR, and NIS2 into practical, high-value commercial strategies. In this exclusive interview, we sit down with the 2024 GRC Ambassador Award winner to discuss the reality of modern cyber resilience, the commercial power of robust governance, and what it takes to lead with impact in today’s digital landscape.


You’ve risen to the very top of a traditionally male-dominated industry to head up European contracts for the Elasticito network. Looking back over your 20-year career, what was the defining moment that shifted your path from navigating the cybersecurity landscape to actively shaping it?


Ever since I was a little girl I’ve loved computers and IT. When our dot matrix printer in our living room in the mid 80s printed out Happy Birthday banners for my party, and I was tasked with copying floppy disks for my father, or playing California Games, I was in my element. So, the interest in IT has been there from the start.

But the defining moment when I realised I was shaping the way people work with compliance and cybersecurity, must’ve been when people started approaching me online in my DMs, asking for my help with certifications and compliance. I was writing posts, articles and researching the impact of frameworks like NIS2, ISO27001 and Part-IS on organisations and finding statistics on GDPR fines and other fun stuff.

By adopting my sense of humour, communication and logical application skills to translate a very tech- and jargon-heavy industry to something they can understand, I am adding value to people’s work. In essence, I strongly believe communication is underrated as a tech resource, whereas it can make or break an organisations willingness to assign sufficient budget to prevent cyber threats or decrease cyber risks.

What surprises me the most was – and is - how even seemingly small technical details can upturn an entire organisation, and large organisations won’t even be aware of them because they’re still doing what they’ve always done, with the vendors they’ve always used.

What’s more worrying though, is when corporations know about problems but cannot afford - or won’t - fix it because of internal red tape. But sometimes you just have to pull the plaster off to not get an infected wound. It hurts, but you have to do it. That part of the job is probably the most frustrating! Seeing the vulnerabilities and not being allowed to fix them…

 

Cybersecurity is notorious for being wrapped in dense, highly technical jargon, but you are widely known for your energetic and approachable communication style. How do you strip away the complexity of cyber risk when speaking to board members who might not have a technical background?


Communication is really underrated, and with the rise of new acronyms appearing seemingly every week, it’s becoming harder for boards to follow the cyber risk & cyber threat space than it is to follow the latest teen TikTok trend.

In client meetings about cyber risk, if I notice someone isn’t following the logic, I sometimes act like I don’t know the answer to a question and ask our cyber engineers to walk me / them through it. It’s easier for me to look “dumb” and “lose face” than it is for the board of a global organisation. Once they’ve heard and seen the technical deep dive explanation once more, then I “translate it” to board-speak: “oh, I see, so if X then Y, which could result in a data breach costing Z and savings of 2 FTEs who can now be put to use for more analytical or tactical work (or a fine of N or another example)”. Nobody likes to admit they don’t understand a concept or that they haven’t heard of a certain thing.

It’s all about finding out who is on the call and tailoring the message to them. If a CFO is on the call, she’ll be more interested in the savings. If a Compliance Officer is on the call, he’ll be keener on dodging fines by avoiding being in breach of compliance. So, it really is helpful that I understand technical details on a high level, in order to explain the consequences and benefits to others. I never dig down into specific CVEs or patch management details, for me, it’s more about the principle and how it relates to the organisation.


With frameworks like DORA, NIS2, and GDPR, European enterprises are facing an unprecedented wave of regulatory pressure. How can CISOs stop looking at these compliance frameworks as expensive "check-the-box" burdens and start treating them as commercial competitive advantages?


It’s rather easy; if you’re up against a competitor who has an ISO 27001 certification and can prove continuous compliance to NIS2 and you can’t… Well, you can guess who the client is going to choose. Or even worse, if you’re working with clients in a regulated industry and they’re monitoring your organisation (as per the regulation) for cyber risk and you don’t have the same visibility as them, you’ll be out the door when it comes time for a renewal if you’re not on top of it. 

I want to iterate that compliance doesn’t mean you won’t be breached – but it shows you have given thought to what you can do to prevent it. You have proven the intention to avoid excessive risk by having the policy in place. If you’ve been through an ISO 27001 or SOC 2 audit, then you also have proof that your policies are being applied (or at least once a year when the audit renews). Continuous validation and operationalisation of tools is where the real sweet spot is, though.


DORA (Digital Operational Resilience Act) in particular has put a massive spotlight on financial institutions and their third-party partners. What is the single biggest blind spot you see European firms overlooking as they scramble to meet these resilience deadlines?


That would be identifying their Shadow IT and Shadow AI! Meaning – companies that are using an unapproved SaaS online (i.e. not having any contracts in place with them - Shadow IT). Think of it as someone who used Canva at their previous job, but their new enterprise uses Adobe. Because the employee has a personal Canva account, they’re tempted to use it anyway “just this once”. Or an employee using a consumer-grade Dropbox account to send files to clients because the company mailbox can’t handle large files. Shadow AI follows the same principle – without any guardrails in place, AI tools shouldn’t really be used freely. It’s a dangerous thing if e.g. HR starts using their own ChatGPT to check whether payroll has been paid out correctly, or Marketing puts client lists in Gemini to sort them alphabetically and by account size for example.

Catching the cyber criminals - Izabella Stueflotten shares her journey to cybersecurity leader
Catching the cyber criminals - Izabella Stueflotten shares her journey to cybersecurity leader

Elasticito specialises heavily in AI-driven cybersecurity automation. In a world where cybercriminals are also using AI to craft faster, more sophisticated attacks, how is Elasticito using automation to help businesses find and patch vulnerabilities before a breach actually happens?


We work with some of the best – but not necessarily most famous – solution providers out there. The ones on the frontline, the ones who are technical geniuses unencumbered by red tape and org charts – the Steve Jobs of cybersecurity if you will. One of my favourite solutions is using AI to detect when data isn’t going where it’s supposed to go. Did you know that the majority of data traffic is non-human? It’s APIs talking to each other. So if API 1 (Salesforce) is usually sending data to API 2 (HubSpot) and this is “labelled” safe, nothing happens. But the moment API 1 is sending data to Unknown API II – it is detected, contained and an alert goes to the team. Our analysis shows that with this type of solution in place together with the warning signs we can see, many data breaches, such as the one at the University of Nottingham, could probably have been stopped before it lost so much data. Exfiltration of data was on 27 May, but it wasn’t detected by the university until 9 June. That’s a long time!


Supply chain resilience is a major focus of your work. We often hear that a company is only as secure as its weakest vendor. What practical first step should a business take to truly get a handle on Third-Party Risk Management (TPRM) without getting buried in endless security questionnaires?


Stop sending questionnaires! Stop answering questionnaires!

We need to get organisations to shift from questionnaires to proven continuous validation of security controls, to providing proof that policies are followed, and perhaps have a preference to engage with businesses who are compliant with industry frameworks (again, you can check this using AI). An annual questionnaire or pen test won’t save you three months down the line when there’s a new vulnerability discovered and it isn’t patched.

But, the first step is to identify which vendors matter. Then put in their SLA or contract that they must remediate findings within a certain period or get “fined”. Say you’re a pharmaceutical company. If the company you buy pencils from has a data breach, that won’t affect you as much as the company where you get your pill casings from, for example. So, start off by categorising (using AI is fine!) your vendors. The next step would be to start analysing these critical vendors from a hacker’s perspective. What does the treat actor see? If you get an alert that Acme Pharma is getting a lot of Hacktivist shares (e.g. authenticated employee sessions being stolen) you should tell your vendor to remediate this.


You work closely with CISOs to help them communicate with executive leadership and the board. What is the most common "lost in translation" moment that happens between a CISO presenting technical vulnerabilities and a CEO looking at the bottom line?


That must be that a cyber risk score is the most important metric. A cyber score only tells a story, and that story has a lag. There are many other metrics to look at – such as what is the susceptibility of a ransomware attack, has the vendor had a data breach in the past year, are there hacktivist shares… The idea that a high score means “safe” is a dangerous notion. This isn’t something that is easily changed overnight. People have been duped into believing scores are the most important.


You were awarded the 2024 GRC (Governance, Risk, and Compliance) Ambassador Award. In your eyes, what does it mean to be a true "ambassador" for GRC today, and how has the definition of risk management changed since you first entered the field?


To me, a true GRC ambassador speaks the truth (even when it hurts), engages with the right type of discussion with the right audience and always works with integrity towards the business’ values and ethics.

Risk management has broadened incredibly in the past few years, and there is – as you probably noticed in my answers today – a huge shift towards operational resilience. I notice much more business continuity planning involved in cyber risks, and other non-cyber risks are becoming an integral part of risk management, in particular Operational and ESG risks. This is because organisations are trying to predict and protect themselves against supply chain risks to avoid financial consequences. It’s a very interesting time to be working in this industry!


If you could bust one persistent myth about cybersecurity that still circulates in boardroom meetings, what would it be?


That would be the importance attributed to a cyber score!

 

As a finalist for multiple GRC leadership awards and a prominent female leader in tech, what is your blueprint for encouraging more women to enter—and stay in—the cybersecurity and governance sectors?


Oh wow – what a great question! I would say to approach the industry from different angles. I’m not a hacker, but absolutely love working in the cyber industry because of how interesting and fun it is. One day is never the same, it offers so much room and breadth for growth and continuous at-work education through both work and courses you can take. And it’s a growing industry! Even with the advent of AI, we’re still going to need cybersecurity and to educate organisations about new solutions (and vulnerabilities!) coming out and what it can do. But the most important premise is really: If you enjoy what you’re doing, you will never work a day in your life!




Izabella Stueflotten
Izabella Stueflotten

Izabella Stueflotten is the VP of Digital Security Strategy at Elasticito, leading European contracts to help enterprises mitigate cyber risk, strengthen supply chain resilience, and navigate complex regulations like DORA, GDPR, and NIS2.

With over 20 years of experience in cybersecurity, governance, and international strategy, she partners with CISOs and boards to deliver AI-driven automation, third-party risk management, and practical, commercial solutions. Known for her energetic, approachable style, Izabella makes security highly actionable. She is the winner of the 2024 GRC Ambassador Award and a recognised finalist for multiple industry leadership awards.







bottom of page