Five Questions with Christiane Baetz
For our latest '5 Questions With', we sat down with Christiane Baetz, vCISO at the Financial Conduct Authority and former CISO at Barclays and Thames Water. Her career spans over 18 years, during which she has worked across a wide range of sectors, including Financial Services, Critical National Infrastructure, Utilities, Chemicals and more.
Baetz believes good cyber security should enable the business, not become a barrier to it. She helps organisations reduce cyber risk, strengthen resilience and make informed business decisions. She discusses her career path into cyber leadership, what drew her to fractional and virtual CISO work, and how she helps organisations navigate change with confidence.
What’s usually missing from a company’s crisis comms plan?
One of the biggest gaps I see is assuming that your normal communication channels will still be available during a cyber incident. If email, Teams or your identity platform are unavailable, how do you communicate with employees, customers, and suppliers? Organisations should have pre-agreed and pre-tested alternative channels and offline access to key contact details. Just as importantly, there needs to be absolute clarity on who is authorised to communicate. Everyone knows the CEO will speak, but who steps in if they're unavailable? Having a clear chain of deputies, agreed messaging principles, ideally with pre-approved holding statements and media templates, and regular rehearsals makes the difference between a coordinated response and confusion.
How much of the AI security narrative is real risk versus hype?
There's certainly a lot of hype. Many vendors now describe almost every capability as "AI-powered", but when you look more closely it's often traditional automation or large language models rather than truly autonomous AI. That doesn't mean the risks aren't real. The pace of AI adoption is unprecedented, and security practices are still catching up. Incidents involving AI platforms and model ecosystems demonstrate how quickly new attack surfaces emerge (e.g. the latest Hugging Face incident). Organisations shouldn't panic, but they also shouldn't dismiss AI as simply another technology trend. The challenge is separating genuine capability from marketing while ensuring governance, security and risk management evolve at the same pace. Boards should be prioritising AI governance, data protection and model security to ensure appropriate oversight, safeguard sensitive information, and manage emerging risks across the AI lifecycle.
Does fear-based cybersecurity messaging actually work?
Fear can be effective in getting attention, but only to a point. If every message focuses on catastrophic outcomes, people eventually become desensitised and stop engaging. The most effective communication puts cyber risk into the context of the organisation. Rather than simply talking about hackers or ransomware, explain what an incident could mean for customers, operations, reputation, and financial performance as well as the individual employee. Worst-case scenarios still have value because they help organisations understand potential impact, but they should be balanced with realistic likelihood and practical actions people can take. Good communication informs and motivates rather than simply alarming people.
How should comms teams and CISOs collaborate during a breach?
The communications team and the CISO need to work as one team before an incident, not meet for the first time during one. Agreeing language in advance is incredibly valuable because technical accuracy and public messaging do not always align naturally. It is also important to establish a single source of truth so that everyone is working from the same verified information and conflicting messages are avoided across internal and external communications. Teams should decide in advance how much information can be shared at different stages of an investigation. Being transparent builds trust, but information also needs to be accurate and must not compromise the response. Regular joint exercises involving security, communications, legal teams, and key senior stakeholders help everyone understand their role, maintain alignment, and avoid unnecessary delays when every minute counts.
What makes employee cybersecurity awareness programmes actually effective?
The best awareness programmes make security personal. When people understand how to protect themselves and their families from phishing, scams, or identity theft, they're much more likely to adopt the same behaviours at work. Security shouldn't feel like another mandatory training exercise; it should provide regular practical advice people can immediately apply. Partnering with internal communications helps keep security visible throughout the year with short, relevant messages rather than one annual campaign. I've also found that sharing real incidents, lessons learned and simple success stories resonates far more than technical presentations or compliance-driven messaging.
How do you present cyber risk to a non-technical board?
Technical detail rarely changes decisions. What works is bringing cyber risk to life through realistic scenarios that reflect the organisation's environment. During board exercises, for example, we might simulate a ransomware attack alongside media enquiries, social media activity and customer complaints, all happening at the same time. That reflects the reality of managing an incident and helps leaders understand the decisions they will need to make under pressure. Organisations rarely respond perfectly, but those that rehearse respond far more effectively. Avoid technical jargon and focus instead on business impact, customer outcomes, and operational resilience. If people can picture the situation, they make better decisions.