About

I'm Johannes, and this is where I think out loud about whatever I'm working on - AI, security, technology in general. No fixed beat, no schedule. The recurring question is just which of it holds up under real load and which of it only looked good in the demo.

Security is the day job. Eighteen years of it, the last seven as Group CISO of a private investment office in London, owning the posture, the budget and the team - and a scope that stretches from incident response and third-party risk to the physical side most people leave off the CISO's desk.

Before that: built and grew a cyber practice inside a law firm defending people with unusually targeted threat profiles, ran application security and incident response across EMEA for a very large payments platform, consulted for a Big Four and a global risk firm, and started out in Germany doing hands-on penetration testing. I also sit on the advisory board of a US security company working on ransomware resilience.

The thread through all of it is the same: a control is only worth what you can verify about it. Everything here is written by me and reported honestly - including the parts that didn't work.

Day job
Tidebreak
LinkedIn
johannesstillig