Skip to content

Five Questions with Christiane Baetz, CISO

Cybersecurity today is just as much about effective communications as it is physical defences.

For the latest in our expert interview series, we sat down with Christiane Baetz, vCISO at the Financial Conduct Authority and former CISO at Barclays and Thames Water. Her career spans over 18 years, during which she has worked across a wide range of sectors, including financial services, critical national infrastructure, utilities, chemicals and more.

Berenice Baker

What’s usually missing from a company’s crisis comms plan?

One of the biggest gaps I see is assuming that your normal communication channels will still be available during a cyber incident. If email, Teams or your identity platform are unavailable, how do you communicate with employees, customers, and suppliers? Organisations should have pre-agreed and pre-tested alternative channels and offline access to key contact details. Just as importantly, there needs to be absolute clarity on who is authorised to communicate. Everyone knows the CEO will speak, but who steps in if they're unavailable? Having a clear chain of deputies, agreed messaging principles, ideally with pre-approved holding statements and media templates, and regular rehearsals makes the difference between a coordinated response and confusion.

How much of the current AI security narrative do you think is genuine risk and how much is hype?

There's certainly a lot of hype. Many vendors now describe almost every capability as "AI-powered", but when you look more closely it's often traditional automation or large language models rather than truly autonomous AI. That doesn't mean the risks aren't real. The pace of AI adoption is unprecedented, and security practices are still catching up. Incidents involving AI platforms and model ecosystems demonstrate how quickly new attack surfaces emerge (e.g. the latest Hugging Face incident). Organisations shouldn't panic, but they also shouldn't dismiss AI as simply another technology trend. The challenge is separating genuine capability from marketing while ensuring governance, security and risk management evolve at the same pace. Boards should be prioritising AI governance, data protection and model security to ensure appropriate oversight, safeguard sensitive information, and manage emerging risks across the AI lifecycle.

Do you think that cybersecurity messaging that appeals to fear works well?

Fear can be effective in getting attention, but only to a point. If every message focuses on catastrophic outcomes, people eventually become desensitised and stop engaging. The most effective communication puts cyber risk into the context of the organisation. Rather than simply talking about hackers or ransomware, explain what an incident could mean for customers, operations, reputation, and financial performance as well as the individual employee. Worst-case scenarios still have value because they help organisations understand potential impact, but they should be balanced with realistic likelihood and practical actions people can take. Good communication informs and motivates rather than simply alarming people.

What’s the best way for a comms team to work with the CISO during a breach or cyber incident? Any lessons learnt over the years?

The communications team and the CISO need to work as one team before an incident, not meet for the first time during one. Agreeing language in advance is incredibly valuable because technical accuracy and public messaging do not always align naturally. It is also important to establish a single source of truth so that everyone is working from the same verified information and conflicting messages are avoided across internal and external communications. Teams should decide in advance how much information can be shared at different stages of an investigation. Being transparent builds trust, but information also needs to be accurate and must not compromise the response. Regular joint exercises involving security, communications, legal teams, and key senior stakeholders help everyone understand their role, maintain alignment, and avoid unnecessary delays when every minute counts.

Education and awareness are a big part of cybersecurity - both externally but also internally to a company’s own employees. What are the best ways you’ve seen this done? How do you partner with internal comms to better educate employees? Have there been any great instances or case studies of this that you have seen?

The best awareness programmes make security personal. When people understand how to protect themselves and their families from phishing, scams, or identity theft, they're much more likely to adopt the same behaviours at work. Security shouldn't feel like another mandatory training exercise; it should provide regular practical advice people can immediately apply. Partnering with internal communications helps keep security visible throughout the year with short, relevant messages rather than one annual campaign. I've also found that sharing real incidents, lessons learned and simple success stories resonates far more than technical presentations or compliance-driven messaging.

When presenting cyber risk to a non-technical board or the media, what communication tactics have you found that actually work, and what fails? Any top tips?

Technical detail rarely changes decisions. What works is bringing cyber risk to life through realistic scenarios that reflect the organisation's environment. During board exercises, for example, we might simulate a ransomware attack alongside media enquiries, social media activity and customer complaints, all happening at the same time. That reflects the reality of managing an incident and helps leaders understand the decisions they will need to make under pressure. Organisations rarely respond perfectly, but those that rehearse respond far more effectively. Avoid technical jargon and focus instead on business impact, customer outcomes, and operational resilience. If people can picture the situation, they make better decisions.

Connect

Looking for a cybersecurity PR agency? Contact us to explore how we can elevate your cybersecurity brand’s visibility and success.

We use cookies to give you the best experience of using this website. By continuing to use this site, you accept our use of cookies. Please read our Cookie Policy for more information.