Ashish Shrestha on leadership during cyber crises
Every organisation has a crisis plan for a cyber incident. Playbooks are ready, crisis teams are activated and technical specialists know which steps to take. But almost no organisation prepares the person who must make the most important decisions during such a crisis.
“The organisation has a crisis plan,” says Ashish Shrestha, “but nobody prepares the leader who ultimately carries the responsibility.” The former Jaguar Land Rover Group CISO was at the helm during one of the most widely discussed cyber crises of recent years.
Although Shrestha spent almost twenty years working in international cybersecurity and held key positions at organisations including Shell and Jaguar Land Rover, he prefers to talk about people rather than systems.
“Cybersecurity is no longer exclusively a technology issue,” he says. “It is increasingly about decision making with profound human consequences.”
He could talk about ransomware, advanced threat actors or the latest AI attacks. Yet he deliberately chooses a different perspective. “Technology continues to evolve. Human nature changes much more slowly. Ultimately, people determine the quality of the decisions made under uncertainty.”
No straight path
Shrestha did not start his career with a plan to become a Chief Information Security Officer. “I never said: one day I want to become a Group CISO. My ambition was always to do meaningful work and keep taking on the next challenge.”
That mindset took him into a variety of international environments. His years at Shell provided an important foundation. “You learn to manage enormous complexity. Different countries, cultures and risks. But most importantly, you learn that security is never just a technical issue. In the end, it is always about people.”
It was there that his fascination with leadership began. “At the start of your career, you mainly think about solutions. Later, you realise that the real challenge is not the technology, but getting people to move with you.”
During a crisis, there is rarely a lack of information
The new CISO
According to Shrestha, the role of the CISO is changing fundamentally. What was once mainly an IT and data security discipline now concerns the protection of organisations, economies and societies that are increasingly dependent on digital infrastructure.
“The question is no longer only what we need to protect, but why that protection matters. Who are we protecting? What are we trying to preserve, and what happens if we get it wrong?”
Technical knowledge remains important, but it is no longer enough. “Can you explain complex risks clearly? Can you build trust? Can you guide people through difficult decisions? Can you create calm when everyone is looking at you? Those are leadership qualities, not technical ones.”
Judgement
Shrestha does not believe organisations suffer from a shortage of information. “We have more data, dashboards and AI than ever before. During a crisis, there is rarely a lack of information.”
What organisations do need is good judgement. “More information does not automatically lead to better decisions.”
AI can help identify patterns and reduce cognitive strain, he says, but it cannot take over every aspect of leadership. “Context, ethics and responsibility remain human qualities.”
This belief also forms the foundation of Zyn Global, the company he co founded. “We must use technology to help people make better decisions. Humans must lead. Technology must augment.”
Jaguar Land Rover
When Jaguar Land Rover comes up, Shrestha avoids discussing operational details. “Out of respect for my former employers and professional confidentiality, I will not discuss them.”
His experiences did, however, confirm the leadership principles he had long believed in. “During a crisis, your role changes completely. People no longer look at your job title. They look at you.”
We are not only protecting organisations. We are protecting our society
For Shrestha, leadership during a crisis is not about having every answer. “It means creating clarity when uncertainty dominates, remaining calm when others feel unsettled and helping people make good decisions together.”
He sees leadership as a form of service. “When people leave a difficult situation with more confidence, more connection and a clearer ability to act, you have done your job as a leader.”
The loneliness of responsibility
For many outsiders, a cyber crisis ends when the systems are back online. For the CISO, that is often when the processing begins.
“The pressure does not disappear once the technical response is underway,” Shrestha says. “For the leader, that is when it truly begins.”
Organisations invest heavily in business continuity, disaster recovery and crisis management. But few prepare the leader who must make decisions under intense pressure, even though the consequences may only become clear months or years later.
“We prepare organisations for operational recovery, but barely prepare them for the human toll a crisis takes on the people who carry the responsibility.”
Projecting calm
On the first day of Cybersec Netherlands 2026, Ashish Shrestha will share his practical experience and vision on the human side of cyber leadership and resilience.
“Most CISOs recognise this immediately. During a crisis, everything is focused on serving the organisation. Adrenaline takes over. You barely sleep, you live on coffee and decisions, while trying to project calm to your team, the executive board, regulators and external partners.”
Once the crisis has passed, however, everyone expects the leader to simply carry on. Shrestha sees this as one of the biggest blind spots in cybersecurity.
“We talk a great deal about cyber resilience. But how resilient are the people responsible for creating that resilience?”
The future of cybersecurity will not be won by technology, but by leaders
Building trust
When asked which quality separates a good CISO from an outstanding one, Shrestha does not have to think for long. “Trust.”
“Trust is built before a crisis. During a crisis, it is tested.”
That is why he invests so much in relationships with executives, colleagues and teams. Trust is not a soft leadership skill, he argues, but an important accelerator during an incident.
“When executives trust you, you do not have to prove your credibility during a crisis. The conversation can focus entirely on making the right decisions.”
A CISO is not judged only by the number of attacks prevented. “You are judged on the quality of your leadership when the pressure is at its highest.”
That requires judgement, especially because cyber leaders rarely have complete information. “We need better decision making, not more dashboards.”
A misconception about cybersecurity
If Shrestha could correct one misconception, it would be the idea that cybersecurity is primarily a technical problem.
“Cybersecurity is ultimately about human behaviour. About trust, collaboration and responsibility.”
He still sees organisations treating cybersecurity as a department rather than a shared responsibility. “As long as employees think cybersecurity belongs only to the security department, we will continue to fall behind.”
Cybersecurity has become a societal responsibility, he argues. “We are not only protecting organisations. We are protecting a society that is becoming increasingly dependent on digital infrastructure.”
Five career lessons from Ashish Shrestha
- Build trust before you need it.
- Understand the business, not only the technology.
- Seek feedback, especially when it feels uncomfortable.
- Never allow your job title to become more important than your purpose.
- Remember that leadership is about service, not status.
You define your own purpose
After almost twenty years in international leadership positions, Shrestha founded Zyn Global. “I wanted to build something that helps leaders make better decisions.”
Purpose is central to his view of leadership. “Never confuse your job title with your purpose. A title is given to you by an organisation. You define your own purpose.”
The leader of tomorrow
His advice to young cybersecurity professionals is straightforward. “Remain curious, invest in communication, learn to listen and deliberately seek out people who think differently from you. Never lose sight of why you do this work.”
Technology will continue to evolve, but people will remain decisive. “The future of cybersecurity will not be shaped by technology alone, but by leaders who build trust, strengthen judgement and bring people together around a shared purpose.”
The CISO of tomorrow
According to Ashish Shrestha, future cybersecurity leaders will need:
- Strategic thinking and an understanding of the organisational context
- Strong judgement and decision making skills
- Clear communication that builds trust
- Empathy and emotional intelligence
- The ability to influence through collaboration and shared purpose
- Curiosity and a commitment to lifelong learning
“Technology will remain important, but ultimately, organisations will distinguish themselves through leaders who know how to connect people.”
Register for free for Cybersec Netherlands 2026
As cyber attacks continue to threaten today’s tech landscape, this event is the premier platform for seasoned cyber security professionals and innovative start-ups to exchange knowledge and tackle cybersecurity challenges together. Organizations across all sectors will discover strategies to boost cyber resilience and safeguard critical assets. Don’t miss this chance to strengthen your cyber defenses, register for free now!