A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

Motor Oil
Syngelakis J. Christos, Group Data Protection Officer
Trust, Security Strategy and the AI-Driven Threat Landscape


Christos J. Syngelakis serves as the Group Data Protection Officer at Motor Oil, bringing extensive expertise as both a CISO and Data Protection Officer within the oil and energy industry since 2016. With a career spanning nearly four decades, he has played a pivotal role in shaping and implementing security strategies for Information Systems, Operational Technology and Personal Data management.
Christos holds an impressive array of certifications, including CISSP, CISM and ISO27001 LA and boasts academic credentials such as a BSc in Informatics, a BSc in Electrical Engineering and an MBA. His leadership and contributions to the field have been recognized on a global scale, with accolades such as being named in the Cyber Defense Media Group's Top Global CISOs for 2022, 2023 and 2024, as well as being listed in the CISO Platform TOP 100 for 2022.
Leveraging his diverse technical and managerial experience across multiple dynamic industries, Christos has developed a balanced and profound technical perspective. Over the last decade, he has been instrumental in guiding Motor Oil Hellas through its transformation from a traditional heavy refining industry to a multidimensional, innovative European energy provider. His dedication and vision continue to shape the future of cybersecurity and operational excellence in the energy sector.
Building Trust and Effective Security Communication
I have learned the importance of avoiding technical jargon, especially when speaking to those unfamiliar with the subject. Even if asked to explain technically, doing so may result in losing the audience. Trust is the first thing you must earn. People quickly recognize passion for work and can understand over time if you have the knowledge. On top proving your effectiveness unlocks the first barrier and they may take you seriously.
Trust is essential, not only from them to you but also from you to everyone. Insider threats are a real danger, but it's important to communicate that monitoring activities are not about distrust but about preventing mistakes and dealing with them. We don't criticize mistakes in technology use; we try to prevent and address them.
Unfortunately, third parties can gain access to systems using someone's identity. Security measures are implemented not to limit access for those who need it but to prevent third parties from exploiting these accesses without the employee's knowledge. This approach allows you to activate control procedures without friction and without objections that you do not trust them.
Prioritizing Security Challenges and Future Threats
We must address existing challenges before focusing on future issues like post-quantum cryptography. While post-quantum cryptography is a problem that will arise, not every security team should be a laboratory for experimentation. We still face many unresolved issues from the past and some security problems have theoretically tested solutions that we have yet to implement. The problem of post-quantum cryptography will be solved as other problems have been over the years. Some will create products and techniques that security teams will implement, just as cryptographic algorithms are now used without the need to know them. In a few years, post-quantum cryptography products will be similarly implemented.
Trust is the first thing you must earn. People quickly recognize passion for work and can understand over time if you have the knowledge.
The development of post-quantum cryptography is a brilliant field for those in theoretical research and product creation, not for those involved in operation and production. When the time comes, they will evaluate and use these solutions. Similar theoretical questions, such as whether it is too early to take measures on post-quantum cryptography, can be answered with the reasoning that everything is risk management. Is it worth allocating money now and if so, how much, to search for solutions that have not proven their effectiveness in protecting data from future decryption?
In my opinion, the bigger problems and priorities are maintaining production and rationally financing security investments. Digital security has been an office problem for years, with companies investing to ensure the CIA triad of information for those using computers. A significant challenge now and in the foreseeable future is ensuring the production process and citizens' access to goods both digitally and physically, as the supply chain can be disrupted. Regulators of European policies like NIS2 believe they will face this issue without understanding that many security managers in industrial production lack knowledge and contact with the complexities of the field and strategic planning is often limited to the office environment.
Cybersecurity Leadership and AI-driven Threats
Artificial intelligence is a stone that has gone and we do not know where it will sit. It gives great opportunity, among others, to which malicious actors to use effective ways to overcome protection measures at an increasingly lower cost. At the same time, it gives the possibility of multiplying the number of attacks. Naturally, similar AI tools are created to deal with them. However, the good ones have a cost that is high and businesses are required to have a continuous financial outflow that continues to grow as the cost of an attack decreases. It is a lost exercise from an economic point of view that few will be able to follow as attackers have the ability to finance thousands of new ones with a successful attack.
Organizations need strong and independent leadership in cybersecurity to create strategies tailored to their specific needs. Leadership without adequate resources does not bring results, so it is essential to provide the necessary resources. If the appropriate framework is created, selecting suitable products will not be a problem. Leadership should not be a scapegoat removed at the first sign of trouble. Problems will arise no matter what. Implementing a solid, effective strategy is a long-term project and cannot be achieved with short-term leadership changes.
Weekly Brief
I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info


