Wisdom From The Women Leading The Cybersecurity Industry, With Izabella Stueflotten of Elasticito

Wisdom From The Women Leading The Cybersecurity Industry, With Izabella Stueflotten of Elasticito

The cybersecurity industry reshapes itself constantly — it’s just a matter of staying ahead and seeing what’s possible next before someone else gets there.


As a part of this interview series we had the pleasure of interviewing Izabella Stueflotten.

Izabella Stueflotten is a GRC Professional and VP of Digital Security Strategy at Elasticito. She helps European businesses reduce cyber risks, comply with frameworks such as DORA, CMMC, ISO27001, and NIS2, and achieve total cyber resilience using a collaborative approach. Many European firms struggle to stay ahead of risks and threats while meeting strict regulations like DORA, but she leads efforts to mitigate risks before they become breaches, ensuring businesses remain compliant and operational.

Thank you so much for joining us in this interview series! Before we dig in, our readers would like to get to know you a bit. Can you tell us a bit about your backstory and how you grew up?

I grew up with an engineer father who taught me to stay curious and never fear tinkering. From helping him copying floppy disks in the early 80s, to the familiar screech of a modem connecting in the 90s, to building my first HTML pages with marching-ant backgrounds and creating online marketplaces in the 2000s, to stepping into cybersecurity marketing in the 2010s… I’ve been hooked by technology’s creative and protective power ever since. Today, as VP of Digital Security Strategy at Elasticito, that very same curiosity drives my work helping European businesses navigate frameworks like NIS2, CyberEssentials+, DORA, ISO 27001, and to reduce cyber risks and monitor your supply chain like your business depends on it. (Hint: it does!)

Is there a particular book, film, or podcast that made a significant impact on you? Can you share a story or explain why it resonated with you so much?

There are a few books by Paolo Coelho that resonated with me, and really touched me with their beauty and poetic writing: The Alchemist and By the River Piedra I Sat Down and Wept are two of my favorites. It’s been a while since I read them, but the feeling left behind has remained. That feeling is one of perseverance, resilience and finding your true calling, even when it feels like the world conspires against you. In our professional world, I encourage people to find their passion and work with that. It makes work fun and easy, and I believe that if you’re having fun, you’ll make more than just a living, you also have the capacity to create a life worth sharing.

Is there a particular story that inspired you to pursue a career in cybersecurity? We’d love to hear it.

Before I started helping European firms finding solutions to their compliance and cyber resilience problems, I endured the daily grind as the EMEA Marketing Manager for a cybersecurity company based in the Shard. Squeezing into hot, crammed tube carriages every morning to get to work managing marketing budgets, strategy reports, and a social media and creative team eventually lost its charm.

So, armed with an MBA in International Management my interest was piqued when a consultancy role popped up in sunny Mauritius during the 2020 pandemic. I phoned my former boss (who unbeknownst to me had left to establish his own cyber risk organization, Elasticito) to ask if he would still act as a professional reference. I asked if he thought I could handle the leap to go work for one of the Big 4. He was incredibly encouraging: “You would be great!” But when I asked if he would still be my reference, there was a silence. He said: “No.” !! I asked him why not (being me, I don’t easily take no for an answer). And his response changed my entire career and work life: “You should come work for me instead.” That single, unexpected “no” was the ultimate turning point. I swapped the idea of white sandy beaches in Mauritius for a work from home position where I am entirely in charge of my own destiny (ironically, I now live by the British seaside with white sandy beaches!), and I have never looked back. It was the moment I stopped working just to earn a living and found my true calling.

Are you working on any exciting new projects now? How do you think that will help people?

Every single day I work on exciting projects with clients and potential clients! There is a particularly interesting project where we are using various data sources to gain insights into several risk domains, and even can tap into auction pricing data, to get the best possible price for the raw materials our manufacturing client needs. It’s incredibly valuable to the client to have a highly automated, AI-powered system, specifically designed to help large companies like them to manage their suppliers, track spending, and avoid supply chain disasters.

Ok super. Thank you for all that. Let’s now shift to the main focus of our interview. The Cybersecurity industry seems so exciting right now. What are the 3 things in particular that most excite you about the industry? Can you explain or give an example?

The first is the learning part of the job. I love learning and never feel like I’ve learned everything there is. Being complacent about what you’re doing is not an option. If you’re not on it, you might miss the ball completely. Take AI for example. There is genuine concern about using AI for malicious content and even cyber attacks. But AI can also be used for good, for efficiency. It’s a little bit like the Spinning Jenny during the industrial revolution; everyone was scared of it, but it transformed the industry from small spinners at home to industrial factories where these machines were run more efficiently. We don’t necessarily know where AI is going to take us, but I don’t think it is backwards.

The second part is helping others. To be successful at work (and maybe at life!) you should always strive to help others. When you’re working in cyber, you are an active participant in helping others. And what better feeling is there, than helping others? It’s rewarding to help organizations become more efficient, avoid data breaches, get certified / compliant and connect dots that otherwise might be missed. It is my belief that when my clients feel they get value for money (and with us they do) trust is built and they’re then more willing to listen to other things we have to say that might help them. Business is not made between organizations, but between people…

The third reason I’m excited about cybersecurity is that it is ever-changing. It’s like living in a movie full of plot twists, discoveries, a-ha — gotcha!” moments. The only thing that’s missing is the robots, but then again, we have APIs and agents — ha!

What are the 3 things that concern you about the Cybersecurity industry? Can you explain? What can be done to address those concerns?

The main worry I have is that we aren’t enough professionals working in this industry. It’s estimated that in EU alone we are short hundreds of thousands of auditors, pen testers, cybersecurity professionals and GRC professionals like me. It’s a mystery as to why people aren’t flocking to the cybersecurity industry. To me, it’s a no-brainer; there’s job security because of the scarcity of people, and thus higher salaries, and best of all: you can work from home or even start your own business. The possibilities are endless.

The second concerning thing in the industry is that there are still companies out there with an attitude of complacency. They are doing as they always have, just because that’s how they’ve always done it. The larger the organization, the less innovative they are. New ideas and solutions aren’t tried, tested and adopted, and I think that’s a shame. There is so much efficiency to be had when finding new solutions to old problems, and guess what happens when monotonous tasks get automated? Well, that frees up time by avoiding repetitive mind-numbing tasks. (That in turn will avoid the endless employee churn!) That employee can now start to do more fun things — like train to be an internal IT auditor or GRC professional!

Lastly, but perhaps most importantly, I think organizations must consider what is ethically right and not only legally right when implementing AI agents and tools. There was a recent article in the Guardian about how Meta was using an AI employee-monitoring program to capture workers’ keystrokes, mouse activity, browser history, along with messages, emails and location data on company devices. This disproportionate surveillance simply can’t be right (even if it is legal in the US). An employee cannot freely give consent to surveillance because of the power imbalance with their employer…

Can you share how you are helping to reshape the cybersecurity industry?

The cybersecurity industry reshapes itself constantly — it’s just a matter of staying ahead and seeing what’s possible next before someone else gets there. I’ve seen how we use AI for enhancing data from SaaS platforms (extracting the core data through APIs) and have created a way to implement various data sources into one single report / view, without having to log in to several portals. I think when people say “SaaS is dead” because of AI, they’re missing the point. Yes, people might not need the actual portals anymore — but processing vast amounts of data, and making sense of it, to make predictions about the future is not dead.

As products, devices and vehicles become connected, this is creating a new and emerging threat vector. How do you think manufacturers and their customers should prepare to be as safe as they can be?

While Elasticito focuses on software risk and digital supply chains rather than hardware production, managing this expanding threat vector requires a shared responsibility model: For Manufacturers: They must adopt security-by-design, treating embedded firmware with the same continuous vulnerability scanning and patching protocols used in enterprise software.

For Customers: They need to practice strict network segmentation. Keep IoT devices isolated on a dedicated guest Wi-Fi network, update firmware regularly, and avoid connecting legacy hardware that lacks active support, to the internet.

Can you share a story from your experience about a cybersecurity breach that you helped fix or stop? What were the main takeaways from that story?

There might be hundreds of breaches that I’ve helped stop because the cyber risk was identified in time. It would be impossible for me to pinpoint one specific incident. And I guess that’s why I get so anxious and eager to get in touch when I see red flags in a cyber risk report. I genuinely want to help companies stop attacks, but if they won’t engage with me or my company when I reach out to tell them… well there’s nothing I can do!

As you know, breaches or hacks can occur even for those who are best prepared, and no one will be aware of it for a while. Are there 3 or 4 signs that a layperson can see or look for that might indicate that something might be amiss?

If you as an employee get very urgent and persistent requests for access to a system, I’d be very wary. Likewise, be suspicious when you notice unexpected password changes, suspicious emails, and maybe even slow or unexpected system behaviors.

After a company is made aware of a data or security breach, what are the most important things they should do to protect themselves further, as well as protect their customers?

Entire handbooks and chapters in business continuity plans have been written around this, so I’ll try to keep it brief.

First step: Stop the bleeding. The immediate goal is to close the door on the hackers and figure out how much damage they did. Lock down the system: Freeze compromised user accounts and cancel digital “keys” (tokens) so the hackers lose access. Investigate the damage: Figure out how the hackers got in, what they stole, and which parts of the business are affected so the company knows what to fix first. You might need to hire some expert consultants for this bit.

Second step: Tell the right people. A company has a legal and professional duty to report a data breach within a designated timeframe. Inform the bosses: Tell senior management immediately and start an official internal record of what happened. Warn customers and partners: Let clients, suppliers, and the public know if their data was compromised. Report to authorities: Inform the right government watchdogs (like the ICO in the UK), the police, fraud centres, and others. Call the insurance company: Alert the company’s cyber insurance provider right away to help cover the costs.

Third step: Make sure it doesn’t happen again. Once the crisis is over, the company should evaluate and upgrade its security based on what they learned. They usually do this in three ways: Fix the tech: Install better antivirus software, tighten firewall rules, and strengthen overall computer settings. Train the staff: Since human mistakes (like clicking a bad link) often cause breaches, give employees fresh cybersecurity training. Change the rules: Keep a closer eye on system activity moving forward and hold a debrief meeting to review the lessons learned from the mistake.

What are the most common data security and cybersecurity mistakes you have seen companies make? What are the essential steps that companies should take to avoid or correct those errors?

Last year I contacted a pan-European physical security company about their heightened risk of a data breach. Their CISO was dismissive of the evidence I provided, and although we can never predict when a data breach will happen, this time it happened rather quickly after I sent the report. So the first mistake I’ve seen is that when someone reaches out to you with a genuine interest in helping; be curious, find out what they know, and reduce the risk before it turns into a breach. Secondly, you’re only as strong as your weakest partner. A security flaw in a supplier’s system could open the door to a cyber-attack on your company, which is a massive threat to your customer data, the uptime of your service, and also your reputation. So keep an eye on your supply chain, especially.

Thank you for all of this. Here is the main question of our discussion. What are your “Five Things You Need To Create A Highly Successful Career In The Cybersecurity Industry? (Please share a story or example for each.)

  1. Stay curious and never stop learning! My engineer father taught me this from the dot matrix printer days onward. In cybersecurity, complacency is dangerous. I’ve seen AI evolve from a buzzword to a powerful tool (and a threat) in just a few years. Curiosity keeps you ahead, whether that’s adhering into a new regulation like NIS2 or experimenting with AI for risk aggregation.

2. Find your true calling and bring passion to your work. The “No” from my reference that turned into a job offer at Elasticito was a turning point. I went from enduring a sweaty, crammed daily commute and cybersecurity marketing work to doing something that genuinely excites me. When you love what you do, you have the energy to persevere through tough projects and create real value for clients.

3. Build relationships and always strive to help others. Business happens between people. I’ve built trust by focusing on client outcomes first and speaking their language: helping them avoid data breaches, achieve compliance, and gain efficiency through automation. When clients see you’re truly on their side, doors open and long-term partnerships form.

4. Embrace change and look for opportunities in disruption. The industry is full of plot twists. Instead of fearing AI, we use it to pull data from multiple SaaS platforms into unified risk views. The companies that thrive treat change as an ally. Automating repetitive tasks means teams can focus on higher-value work like strategic GRC.

5. Act with integrity and ethical courage. Compliance is the floor, not the ceiling. I’ve seen the damage when organizations ignore red flags or prioritize legal minimums over what’s right (e.g., excessive employee surveillance). Stand up for ethical practices! It protects your clients, your reputation, and the industry as a whole.

We are very blessed that very prominent leaders read this column. Is there a person in the world, or in the US with whom you would like to have a private breakfast or lunch, and why? He or she might just see this if we tag them :-)

There are so many interesting people to choose from, but if I wasn’t allowed a brunch with a group of them, I would probably choose Robert Herjavec. I’d love to hear his story first-hand as he seems like such a personality.

Thank you for these fantastic insights! We wish you continued success in your career.

TechVIP InterviewsPolaris
AM
Written by

Authority Magazine Editorial Staff

Writer & Contributor

Contributor at Authority Magazine covering leadership, innovation, and industry insights.

Authority Magazine
Published inAuthority MagazineTop Lessons, Top Authorities · 42K Followers

Exclusive, curated interviews with the leaders and changemakers shaping tomorrow. Leadership lessons, industry deep dives, and executive profiles.