What CISOs Can Learn Across Industries

Auteur zonder afbeelding icoon
Sander Hulsman
03 August 2026
4 min

Martin de Vries of VDL Group at Cybersec Netherlands 2026

How does the role of a Chief Information Security Officer change when the environment changes? At Cybersec Netherlands 2026, Martin de Vries, CISO of VDL Group, will share the lessons he has learned across banking, academia and manufacturing.

A CISO in the financial sector operates in a highly regulated environment. A university depends on open knowledge sharing, while an industrial organisation must connect digital security with production, innovation and international supply chains.

Despite these differences, the fundamental challenges are often similar. The way an organisation assesses risks, makes decisions and deals with uncertainty ultimately determines how effectively cybersecurity is organised.

Martin de Vries will explore this topic during his keynote, “From Banking to Academia to Manufacturing: What Every CISO Can Learn Across Industries,” on 9 September at 13:30 during Cybersec Netherlands 2026.

De Vries has been CISO of VDL Group since September 2025. He is responsible for creating secure, future focused and innovative digital facilities that support the strategy of the international industrial group. Before joining VDL Group, he held cybersecurity roles in sectors including finance and academia.

Every sector defines risk differently

One important lesson from working across different industries is that there is no universal blueprint for cybersecurity. The context determines which risks matter most and how a CISO should fulfil the role.

In the financial sector, the emphasis traditionally lies on governance, regulation and control. Banks operate in an environment where trust is essential and where incidents can immediately have financial and societal consequences. Processes, responsibilities and risk management are therefore often highly mature.

“It is a continuous search for the right balance between security and the freedom required for innovation.”

The academic world has a different dynamic. Universities are built around openness, collaboration and international knowledge exchange. Researchers need access to systems and information, while sensitive data and intellectual property must also be protected.

For a CISO, this means continuously searching for the right balance between security and the freedom required for innovation.

In manufacturing, the focus changes again. At VDL Group, cybersecurity is not only about digital systems, but also about the continuity of production processes, OT environments and international supply chains. Digitalisation creates new opportunities, but also introduces new dependencies and risks.

Influence and communication

Despite the differences between sectors, De Vries sees one important similarity: the CISO must connect cybersecurity with the wider organisation.

“Although the sector in which you work may differ, the most important message is to share your insights with the board and your stakeholders in order to start the conversation.”

Martin de Vries, CISO of VDL Group

This reflects a fundamental development within cybersecurity. The CISO is no longer only responsible for technical security measures, but must also translate risks into strategic choices.

The objective is becoming less about preventing every possible risk and more about helping organisations make conscious and informed decisions.

According to De Vries, security professionals can also benefit from looking beyond their own industry.

“I encourage everyone to work across different sectors.”

Experiencing different environments helps professionals develop new perspectives on risk, governance and collaboration.

New regulation and AI

Alongside sector specific differences, De Vries sees several developments affecting all organisations. One positive trend is the growing attention being paid to cybersecurity at board level as a result of the NIS2 Directive.

“The position of the CISO is changing from specialist to strategic discussion partner.”

Cybersecurity was long regarded primarily as a technical subject. New legislation is placing it more firmly on the agendas of directors and supervisory boards. As a result, the CISO is evolving from a specialist within the IT organisation into a strategic partner for the entire organisation.

At the same time, De Vries believes that AI is creating a fundamental change within cybersecurity.

“The fundamental change that AI brings to the security community and our daily lives cannot be ignored. It requires our full attention, alongside everything else we are already dealing with.”

The future remains uncertain

The speed of technological development is making the future increasingly difficult to predict. Even experienced security professionals cannot know exactly how cybersecurity will evolve over the coming years.

“To be honest, I do not know. Did we know or could we have predicted the full impact of the internet? What I do see is that the pace of development will only continue to accelerate.”

That uncertainty makes the role of the CISO even more important. Organisations need more than technical expertise. They need leaders who can manage change, connect different interests and create open conversations about risk.

This is the central theme of Martin de Vries’ keynote at Cybersec Netherlands 2026. His session will examine cybersecurity from the perspective of leadership, organisational dynamics and human decision making, while exploring the lessons that emerge when professionals look beyond their own sector.

Register for free for Cybersec Netherlands 2026

As cyber attacks continue to threaten today’s tech landscape, this event is the premier platform for seasoned cyber security professionals and innovative start-ups to exchange knowledge and tackle cybersecurity challenges together. Organizations across all sectors will discover strategies to boost cyber resilience and safeguard critical assets. Don’t miss this chance to strengthen your cyber defenses, register for free now!