The Connectivity Cloud Podcast · 2025-07-07 · 28 min
Key moments - from our scoring
Substance score
58 / 100
Five dimensions, 20 points each
Olivier Bussolini brings 30 years of IT and cybersecurity leadership spanning the French Ministry of Defense, pen testing, consulting (Big Four, JPMorgan), and CISO roles at Signum Bank, BNP Paribas Switzerland, and now Mashraq Bank across 12 countries. He articulates a clear evolution in how CISOs should think about impact: moving beyond vulnerability metrics and audit findings to becoming integrated business enablers within strategic initiatives. Rather than remaining gatekeepers, modern security teams should embed security DNA across the organization through Business Information Security Officers (BISOs) and shift-left practices in development - automating security culture rather than scaling headcount. Bussolini also champions a geopolitical shift where 40+ CISOs from Salesforce, Microsoft, and AWS recently petitioned the G7 and OECD for harmonized international cybersecurity regulations, arguing that fragmented regional requirements (ranging from Singapore's 182 prescriptive MAS controls to Switzerland's 10 principles) waste organizational resources on compliance demonstration rather than actual defense. His core message: legitimacy through technical roots, strategic contribution through business integration, and policy influence through coordinated industry leadership.
Start with a solid technical foundation (pen testing, SOC analysis, or DevSecOps work 2-5 years), then move into advisory or consulting roles to broaden perspective, then join large regulated organizations like JPMorgan where you can learn advanced processes and culture, always staying connected to reality and following your passion for impact rather than pure technical work.
Beyond security metrics like vulnerability counts or ratings, real impact is measured by enabling business initiatives - being part of the team when strategic projects launch new products or regions, and receiving validation from regulators that your security advice directly contributed to business success and regulatory alignment.
Banks operating in multiple countries (Mashraq operates in 12 countries) must comply with vastly different regulatory approaches: some regions demand 182+ prescriptive controls (Singapore's MAS TRM), others use 10 principles (Switzerland), and others focus on outsourcing controls, forcing organizations to waste budget on compliance demonstration rather than actual defense against threats that don't respect borders.
Shift-left by embedding security culture and tools into development teams - creating automated evil stories for developers, training business information security officers (BISOs) embedded in business departments, and transferring security knowledge and habits to non-security teams so they can self-serve security requirements at agile speed.
As CISOs move from purely operational pen testing and compliance roles to strategic business enablers contributing to financials, product development, and cross-border expansion, they transition from isolated technical roles to core business leadership positions requiring fluency in business language, culture, and stakeholder thinking - similar to diplomatic negotiation.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains solid mid-level insights about shifting from technical roles to strategic CISO work, embedding security left in development, and the business enabler model. However, much of the substance consists of career narrative and philosophy rather than operational specifics. The discussion of regulatory fragmentation is valuable but lacks depth on implementation solutions.
we are shifting left. So you are providing, in the example of the development, you are providing the developers with more and more culture reflexes, tools to embed security right from the design
I really want to make sure that I am part of the team when I'm saying I am, it's my own organization. It's not just me and that when we are working over the weeks or months of the project that we are really not just giving advice or doing controls.
The core ideas - shifting left, security as business enabler, CISOs at the strategic table - are well-articulated but largely established concepts in modern CISO discourse. The regulatory harmonization angle is fresher, but the episode does not offer novel frameworks or counterintuitive arguments. The guest recycles familiar thinking about moving from technical to strategic roles.
we don't want to be the showstopper, the gatekeeper. We want to repart. We when I'm saying we is we want to instill some Security DNA
if I look at when I was doing pen testing or when I was doing more operational work, the contribution was very limited
Olivier Bussolini is a credible senior operator with genuine CISO tenure at major financial institutions (Mashreq Bank, BNP Paribas Switzerland, JP Morgan 2010-2017, and consulting background). His 30+ years in IT/cybersecurity and involvement in international policy initiatives (G7/OECD letter) demonstrate substantive influence. However, the episode does not deeply probe his specific accomplishments or quantifiable business impact.
Olivier Bussolini, Group CISO at Mashriq Bank. Olivier brings over 30 years of experience in IT and cybersecurity leadership
Prior to Mashreq, Olivier served as CISO at Signum bank and BNP Paribas Switzerland, where he led multi year cybersecurity transformation programs
The episode lacks concrete metrics, timelines, and specific quantifiable outcomes. While Olivier mentions Singapore's TRN with 182 controls and references JP Morgan experience from 2010-2017, most claims remain anecdotal. The regulatory letter to G7/OECD is named but not substantiated with actual policy impact or timelines. Few concrete examples of security initiatives or business results are provided.
At the same time we were operating in Switzerland. And Switzerland is very much principle based. So they are rather telling you, okay, you are processing the client data. We give you 10 principles
the TRN, the technology risk manual of MAS, was 182 controls. At the same time we were operating in Switzerland.
The host asks competent opening and follow-up questions but rarely pushes back or challenge claims. Questions are generally affirming and surface-level ('how do you measure impact?' 'what do you mean by the kids table?'). No genuine friction or productive disagreement emerges. The interview reads more as a conversational biography than rigorous interrogation of complex tradeoffs.
I always try to start with like a simple light question so that people get to know you. If you weren't a cybersecurity leader, what would you be doing today instead and why?
Can you explain a little bit further this trend and what kind of benefits you see?
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of The Connectivity Cloud Podcast with Cloudflare, host Mark Dembo is joined by Olivier Busolini, Group Head of Information Security at Mashreq, to explore how cybersecurity leadership has transformed from a purely technical function to a strategic business partnership. What You’ll Learn How to transition from technical roles to strategic security leadership The framework for measuring meaningful security impact through business enablement Why embedding security through shifting left and Business Information Security Officers (BISOs) is crucial for scaling security How to effectively communicate security priorities across different business units, cultures, and stakeholders Why developing cross-cultural communication skills is essential for modern security leadership Olivier Busolini is the Group Head of Information Security at Mashreq, bringing over 30 years of distinguished experience in IT and cybersecurity leadership.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Welcome to the Connectivity Cloud Podcast, the podcast that provides expert insights into the cloud and IT landscape. I'm Marc Dembo and each month we'll explore key topics like scaling secure infrastructure, tackling emerging risks and staying ahead of the latest trends. Whether you're managing multi vendor environments or navigating cloud modernization, this is the show for you delivering practical advice for today's decision makers. Welcome to the Canary Activity Cloud Podcast, your trusted source for insights into the latest trends, strategies and technologies shaping cloud security and infrastructure. I'm your host, Mark Dembo and today we have a truly distinguished guest, Olivier Bussolini, Group CISO at Mashriq Bank. Olivier brings over 30 years of experience in IT and cybersecurity leadership with a proven track record driving security strategies that empower innovation and resilience and some of Europe's and the Middle East's most m highly regulated financial institutions. Prior to Mashreq, Olivier served as CISO at Signum bank and BNP Paribas Switzerland, where he led multi year cybersecurity transformation programs. In this episode we'll explore how cybersecurity leaders are stepping onto the global stage, collaborating across industries and borders to influence international regulation. We'll also dive into pragmatic strategies for managing regulatory complexity and the future of secure digital transformation in banking. Olivier, welcome to the Connectivity Cloud Podcast.
Speaker B: Thank you, Mark. Thanks very much for having me. It's a pleasure.
Speaker A: Let's get right in. I always try to start with like a simple light question so that people get to know you. If you weren't a cybersecurity leader, what would you be doing today instead and why?
Speaker B: So I started my professional career, Mark, uh, in the French Ministry of Defense. I had some interactions both on the Navy side as well as on the IT and ITSEC side. So if I had not chosen to be leaving, uh, the service and going into the private sector, probably you would find me somewhere in the MOD or in some other area of the government doing probably either program management or why not, you know, having still being able to jump on the bag wagon of cyber and being doing cyber for the government. That would be something I could see my myself doing in my next life.
Speaker A: That is super interesting, Olivier. You mentioned your early career start in the military, right? You went from really being ingrained into deep technical skills and really operational hands on to basically becoming business leader at cisa. Right. How can people that are currently really operational hands on, I don't know, Red Team or pen testing, how can they broaden their focus and also go beyond pure technical Skills to incorporate, I don't know, strategy and risk management.
Speaker B: Yeah Mark, this is uh, really talking to me because at the turn of the century, so a long time ago I started my hands on career as a pen tester. So 2001 to 2005. So I've been through this very important foundational stage of developing your cybersecurity roots. Because if you are going to grow as a manager and as a leader, you still want to be connected to reality, you want to be legitimate, uh, and just make sure that you are not being too much at the consulting level. So if you are today a SOC analyst, uh, if you are a developer that is doing a lot of DevSecOps work or if you are a pen tester, this is for me fantastic. You are developing your roots that are technical. Because even if we are today talking about a role that is more a risk manager role, a business oriented role, let's not forget that we are risk manager in a very niche area which is information security or technology security operations, uh, in some appellations. So I really cherish profile that have been rooted in, in the technical realm. However, it's not the only way to grow in this work. You can also grow by just being a risk manager and developing your knowledge in an area that is in fosec. So from my side I started that. It was a couple of years as I said, and then I moved away from the service. I continued to do the same type of practice in the consulting world, but rapidly I realized that even though pen testing was so exciting, when you are looking at the impact that you are actually having on the organization, pen testing is a very small part of cyber. Even at the time, I'm talking about 20 years ago. And I really realized that I was not being able to deliver the impact I wanted. So I looked around and I saw that going and speaking about the organization of security policies and making sure that you help the organization grow beyond just highlighting gaps, uh, and vulnerabilities was something that looked to me to be more impactful. So I left a purely technical world, technical activities in cyber to go through a more global, more advisory role. And then after a couple of more years I did a small boutique film, a large big four. I realized again that by being just a consultant I was able to help but I was not feeling the heat and you know, and the intensity of being inside a client. So after a couple of years, four or five years in the consulting room, I went to uh, the client, you know, as you have when you are a consultant you mentioned Signum and bnp, but I also did quite a lot of years at JP Morgan and that was also a fantastic way to really be in a major organization. So 2010 to 2017. So fantastic way to learn from really advanced people, advanced processes, an advanced organization. That was crazy accelerator for my career. After being in jp I really felt that I was able to bring value to other organization and then I went, you know, on my journey. So you start by you developing your roots, then you let your internal fire telling you where you want to go. Maybe you want to do some development and then become a developer, a hardcore developer that has in his DNA or her DNA security all you want to do. More my job, my CISO role. I have also seen colleagues that after a very solid foundation in security, found that risk management was more exciting for them. And they went from infosec risk management to for example operational risk management. So there's a lot of things that can happen. The importance for me is the right connection to reality and where your passion is leading you.
Speaker A: And uh, that is so cool. I feel like that is true for so many jobs out there. I think as you go like from being an individual contributor to management, but you need to have that foundation, right? You need to understand what is it actually like to be in that individual contributor role, be connected to business and then be in an environment where you can actually grow and learn from someone or an organization or have leaders. Really cool. One thing that you mentioned over and over again is meaningful impact. I feel like being in a leadership role, being a ciso. I'm curious, how do you define impact and how do you measure it?
Speaker B: Yes, that's a fundamental question mark. Thanks for asking that. So I don't see my role limited to some operations activity. I rather see my organization that has grown to become a second line risk management organization and really a business enabler. And I'll try to develop that because for me the impact that you have in an organization when you consider that your role is strategic and it's not arrogance, it's just trying to be contributing at a strategic level to the organization. I see my impact as being an enabler, a contributor, uh, to our most important business initiatives. We have so part of a bank, we have different line of business. We have four at bashrec. When one business line is developing a strategic initiative, it might be a new product, a new service or a new region. I really want to make sure that I am part of the team when I'm saying I am, it's my own organization. It's not just me and that when we are working over the weeks or months of the project that we are really not just giving advice or doing controls. We are really skin. Our skin is on this game. We want to be part of what will make us cross the finish line. And I have a very clear example where my team was contributing very actively with both the business team, the technology teams. And at some point in time, because we are a bank, we had to have an inspection, inspection by the regulator. And you know, it's this moment where you are really finding yourself completely naked and those professionals are coming and scanning you. And we had this aha moment in the team where at the end of the cybersecurity inspection the inspector said, you know what you talking to the business people. If you do what the security team has advised you to do, we are good. You are going in exactly in the right direction and you'll be uh, good to go. In production, you cannot hope to have a better impact than a third party telling you that you have been a small enabler. Of course we were not doing everything, but we brought our piece of the puzzle and we contributed to the success of this business initiative. This is for me the real impact. It's not about, you know, driving down your number of vulnerabilities, uh, or having your best security rating. This is important, but it's more the information security metrics that I would see. Of course we are piloting those metrics, but when I was talking about business impact, I was really talking about being transformative at the business level.
Speaker A: Yeah, that makes sense. Keep the business alive, keep it agile, be integrated, be on this being integrated part. Right. You mentioned, hey, you want to be part of the project, you want to be part of the business. When we previously talked so we had a little bit of a pre discussion which I very much enjoyed. You mentioned like there's a growing trend of, I don't know, having business information, uh, security officers or DevSecOps which used to be just DevOps. Can you explain a little bit further this trend and what kind of benefits you see? Because you've been very passionate about that, I think.
Speaker B: Yeah, absolutely. Mark. The business is evolving at the speed of light. In this current bank or in a previous bank that uh, was more a uh, kind of neo bank, not startup anymore, but scale up. Things are developing really at the speed of light. We don't want to be the showstopper, the gatekeeper. We want to repart. We when I'm saying we is we want to instill some Security DNA. So you need to be part of the team who's running, you need to be on the field, running with the others. You cannot be just on the bench. That's one, two is as uh, the business is developing. The digital squad in my organization are part of the business. So you want to be with them, you want to be able to provide your insight and your added value at the speed of agility, at the speed of the agile development. So making sure that you are able to scale up and you need to find creative way to scale up. Scaling up is not about multiplying the number of people in my team. That's not going to be fast enough, that's not going to be efficient and from a money perspective it's going to be a nightmare. So what you want to do is to make sure that you are shifting left. So you are providing, in the example of the development, you are providing the developers with more and more culture reflexes, tools to embed security right from the design. So right, what we are doing now is we have developed even internally tools to help the developer when they are writing their user story to see evil stories being generated automatically. And those evil stories are going to tell the developer what needs to be changed in the code so that the application is secure by design and secure by default. This cannot be done if we add security expert to the dev team. It must be a transfer of knowledge, a uh, transfer of habit. Ingraining the security culture in the devs, the bizo is the same thing but at a uh, whole department level. The department has a lot of activities related to security. It's not just the security of the initiatives as I was discussing or the security of the development. It's also how do you build resilience, uh, in a department in a business department, how do you facilitate some of the challenges around BCM? Dr. Uh, how do you facilitate the management of the third parties that this business line is using and making sure that they are not just looking at the business performance but they are taking into consideration also security and privacy of their partners. This is much more efficient if it's done closer to the business teams. So very naturally you grow a uh, bezo. You can grow a bezo in your security team and then transfer the person in the department. You can start by having a person in the business department that is interested by what you are doing and you kind of shadow the person. You know, you always create the right setup uh, for your organization if you have the right target. So shifting left, enabling the businesses to have their own way to manage the requirements and finding the right way to improve their security is the solution. It's not about ramping up the CISO team. That's never going to fly.
Speaker A: This is so cool. Makes so much sense, right? This shifting left picture and operational level, like earlier in the process development, earlier in the code development, so to say, the strategic initiatives not being an afterthought, but being ingrained, being part of the team, makes a ton of sense. Take a step back, right, and look in general at, like, the CISO role. I very, uh, vividly remember from our conversations, I think that was like, a few weeks back, and you mentioned, like, the CISO is moving from the kids table to the adults table. Can you explain a little bit what you mean by that?
Speaker B: Yeah. So it was kind of the cliche that you see, you know, in all your LinkedIn and other platforms where you have this drawing where someone in a suit is taking you from the small table to the big table. That's just, for me, an illustration talking about the transformation of our role and our added value. As I said for the last half an hour that we've been discussing, if I look at when I was doing pen testing or when I was doing more operational work, the contribution was very limited. That's what I, uh, was describing of those. Sometimes those images are describing as having a limited contribution that might be seen as being part of the kids in the family, but as you grow and as you become more strategic, you are really another member, another adult member of the family, someone that is managing the whole family and helping the family, uh, to thrive, to, uh, develop. That's really what I meant in terms of this image. But it's exactly the same thing as what we've been discussing, which means that when you join a new type of community in your journey, think about adopting the vocabulary, the way of thinking, the culture of this other community. I'm not saying that you lose the essence, uh, of who you are and what you are bringing to the table. Not at all. But you need to understand that you are part of a different culture. I think I connect to that very vividly. When I was at the MOD in France, one of my job has been to be part of an embassy. I was a diplomat for three years. And when you are leaving your country and interacting every day with another country, those challenges of language, culture, the way to look at a topic is your bread and butter. So it was so obvious to me that as I was growing and becoming more ingrained in the strategic discussion, in talking about financials with the CFO and the CEO of the bank, or when I was discussing or contributing to the development of a business line in another country, I really felt that I was back in the embassy trying to understand how you can speak a different language, how you can put yourself in the shoes of someone different that has not your background. But still at the same time, you bring your topic, your expertise on the table. Fascinating. Super exciting, quite challenging. But that's the very nature of now being at a different level.
Speaker A: That sounds indeed super challenging. You're not just translating from technical details to business, but also perhaps different cultures, different regulations, different environments, different stakeholders. And I feel like the more I advance my own career, you learn it's all about communication and translating into what resonates with your stakeholders and what they need to understand. And that's the way that you get stuff done and how you get your message across. Right.
Speaker B: Without transforming the essence of your message. It's really the form that is changing and not the essence. And so let me be realistic when I'm discussing with some of my business leaders, because please do remember, some of those business leaders, they are funding me because my budget is coming from the business. I'm a cost center. So sometimes there's friction, sometimes there's, uh, negotiation, pull and push. But if you have established your legitimacy, if you are showing that you are really one part of the team, the discussions on the funding, on what you are bringing, and sometimes some of the pushback or the correction that you are doing, they will be taken very differently than if you are really seen as being an outsider, you know, oh, that's the guy in the second line of defense. We never see him in the business briefing. He's never speaking with clients. He's only coming when he's doing his pen test or his audit. This is a very different way to interact with the core of your organization.
Speaker A: So, Olivier, I did a little bit of research before our interview, and, um, basically what I noticed is that you recently posted on LinkedIn about over 40 CISOs, including leaders from Salesforce, Microsoft and AWS. They send out a letter to the G7 and OECD and urging for, uh, harmonized international cybersecurity regulations. You described this yourself in your own words as a historic shift where CISOs are, ah, no longer just managing internal controls, but influencing geopolitical policy. I am super curious. Can you tell me more about it? Why are you so passionate about it?
Speaker B: Yes, Mark, thanks for asking the question. This is really something that has been, at least in my world, in the Very, uh, regulated environment. That has been a very big challenge for my whole career as a CISO. So for 15 years. So basically my simplest view, and then I'll bring a bit of nuance, My simplest view is every regulator, um, should have in mind roughly the same objective. Protection of the country, protection of their own citizen, protection of their market. So as we are talking about cybersecurity and even maybe privacy. But let's start by cyber, you would say, okay, when you have an apt, they are most probably, yes, they have some geopolitical motivation sometimes. But for the others who are just motivated by the money, they don't care if they are attacking country A, country B or country C. So if those different countries were, want to fight the same threats, why don't they harmonize their control requirement, their approach? Because today in every country I have 12 countries of Mashreq. And when I was at JP, it was even more, in every country there is a slightly different or sometimes vastly different requirement that I have to abide to Asia. I was at, I was in Singapore and Hong Kong. So, you know, they are very prescriptive. At the time, the TRN, the technology risk manual of MAS, was 182 controls. At the same time we were operating in Switzerland. And Switzerland is very much principle based. So they are rather telling you, okay, you are processing the client data. We give you 10 principles that you have to implement to protect your, your client data. So I have to spend time, so budget and people to look at all the controls demanded by the different countries, by the different regulators. And this is not one set of 20 controls that you can have across the whole region. But I have 10 principles here, 182 controls there. In another country, they take the problem completely differently. Oh, uh, no, we are not interested by that. We are interested by the way you are doing outsourcing to your headquarters in another country. And we want to control that. So we are spending literally time and money not defending the bank, but demonstrating compliance. Okay. And I've been discussing that and I've started this discussion around me here with some of the local regulator. And please keep in mind that I've been on the government side for 15 years, so I also can imagine that in their shoes they can see that they have a different view, they have maybe different objectives. They want to give their banks different type of level of controls. But we need to find something that is a bit more reasonable because we, all the banks, all the regulated institutions, we are spending so much energy not defending ourselves, but just demonstrating that we have the right level of control. I don't believe this is achieving the objective of the regulators and it's not helping us either. That's why I believe that this paper was super welcome. I mean we tried in my past world in Switzerland to have those conversations. It's very difficult, specifically when you speak about cross countries negotiations. But if we can start now and maybe achieve a result in three years, five years, I don't think we're going to have something before that that would be great because we would be refocusing more administrative activities of demonstration of the effectiveness of our control to actual defense.
Speaker A: Uh, yeah, that makes so much sense and I feel like it's so clear why you're so passionate about it. Less ticking checkboxes and more actually delivering value and protection. So to say just very naive question here, not my background. Is there any internationalized framework that you can follow right now or is there literally nothing? And it's all fragmented today.
Speaker B: So if I look purely from a regulatory perspective. So really regulations, national regulations? No. However, there's been some initiatives. You might have seen that the NIST csf, when they created their csf, they had I think two or three years after they started creating profiles and there was a financial service profile that was for me a uh, very interesting attempt to go beyond providing best practices and seeing, okay, if you are in the financial industry, those elements are specifically meaningful for you. So maybe that's where you should be looking at with more attention. If we could have that at the OECD or the United nations or who knows itu. Because ISO is not a regulator. Okay. ISO is trying to communicate best practices, but it has never, for me it has never had a real international impact. Some countries are very eager to have an ISO certification, others are considering that best practices are, are good enough. But I've never seen really regulators uh, speaking to each other and starting to align, uh, on their demand across the boundaries of their nations. Yet let me be positive. Yet.
Speaker A: Yeah, yet be positive. It's so funny. I have two questions prepared to ask you basically as like my last question. One is like, hey, what is one wish you would have for the future to improve like security posture? So you already answered that. I think so let me ask the other question. But if you imagine I was an aspiring ciso, what is one piece of advice you'd give me based on your experience, perhaps something that you felt like you wish you had received yourself earlier in your career?
Speaker B: Yeah, this whole journey of understanding what you are doing, why you are doing that and how you can be efficient. So moving from the technology to really bringing more added value, uh, by being a more strategic executive. This is something I discovered as I was failing on being very efficient left and right, failing at the technical level, failing by being part of tech, failing by being outside of tech, not failing, but not being that efficient. And then you get a massive incident and you go through that and you try to learn from that. So if at the time, at the beginning I was told, you know what, this is the direction you should be traveling, think always about what your organization is delivering. Think about aligning and being part of the, even if it's just a small piece of this larger puzzle. But don't work in your own isolation. Don't think that your world or your universe is limited to that. I think I would have maybe been a bit faster in my maturation, in my journey, but that's maybe when something you can say after having done that for 25 years. Uh, so, yeah, that's the best I can say for the young generation.
Speaker A: That's very fair. Olivier, thank you so much for joining. I learned a lot. One can tell you're clearly passionate about driving change for better and basically improving security postures, having impact, driving business outcomes. Really, really nice. Thank you so much.
Speaker B: Thank you, Marc. It was a pleasure to chat with you.
Speaker A: Thank you for tuning in to the Connectivity Cloud podcast. If you found today's episode valuable, be sure to subscribe so you won't miss future updates. Stay ahead of the curve, stay connected and stay secure. As always with Cloud Player.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.