Berlin’s Security Chiefs to Watch: The CISOs Behind Its Tech

Related

Share

Berlin’s technology scene has matured past its move-fast phase into something more regulated, more audited, and more accountable, and its security leadership has grown with it. The CISOs below certify mobility platforms against Deutsche Bahn’s standards, defend Europe’s biggest digital news brands, and make AI pathology companies investable. Their common ground is not a sector. It is the ability to build a security programme that holds up under an auditor, an investor, and an attacker in the same year.

Sven Zehl – Director of Information Security and CISO, Moss

Building security inside a regulated fintech means the auditors arrive whether you are ready or not, and Sven Zehl has spent his career being ready. He joined Moss, the Berlin spend-management platform, in February 2026 as Director of Information Security and CISO, reporting to the Chief Risk Officer and leading a team spanning security GRC, security engineering, and technical operations. The mandate is explicitly audit-ready: scalable structures aligned to ISO 27001, SOC 2, and DORA, with KPI-driven security management and third-party risk oversight built in. He arrived from sevdesk, where he spent over two years as CISO and Director of Security and Corporate IT, and before that led Doctolib’s global security compliance function, owning a certification portfolio across ISO 27001, ISO 27701, and BSI C5. Earlier still he set group-wide IoT and product security governance at Bosch and headed the IoT domain at Bitkom, Germany’s digital industry association, advising policymakers on security and regulation. He also lectured on digital systems security at Berlin University of Applied Sciences and advises startups through his own consultancy, Zehl CyberConsult.

Kai Gansert – Group CISO, CHAPTERS Group and Altamount Software

Securing one company is a job. Securing more than sixty of them at once is Kai Gansert‘s. As Group CISO of CHAPTERS Group AG, working out of its Altamount Software platform, he drives information and cyber security across a Europe-wide portfolio of mission-critical software companies, with the role running through Hamburg and Berlin. The resilience argument is a practical one for him: as CISO of DB Energie, Deutsche Bahn’s energy utility, he held responsibility for the cyber security strategy protecting critical infrastructure that moves five million people through Germany every day. Earlier roles as senior information security expert at DB Cargo and CISO at open-source IT services firm it-novum built the logistics and IT foundation. Across those posts he has prepared and secured certifications spanning ISO 27001, BSI IT-Grundschutz, IT-SiKat, and audits under §8a. His through-line is security as DNA rather than department, which is what a buy-and-build software group needs.

Benoit Flippen – VP, Information Systems and Security, emnify

Before Benoit Flippen built security programmes, he broke things for a living. At SRA International he ran penetration tests and social engineering campaigns against the US Department of State’s worldwide networks, and helped build a vulnerability management capability that cut network vulnerabilities by ninety percent in its first year and won the NSA’s Frank B. Rowlett Award. He then moved to FusionX and, after its acquisition, to Accenture, where he built a global forensics and incident response practice from scratch. That adversary’s view now shapes his work as VP of Information Systems and Security at emnify, the Berlin IoT connectivity provider, where he has built and scaled the security team since November 2023 while also growing internal IT and data functions. At Scout24 he spent three years as CISO and later VP, including a stretch as temporary co-CTO while the group rebuilt its technology strategy, and before that he led cyber security at finleap and served as CISO of its small-business banking platform, Penta. Few security leaders can describe what the attacker sees. Flippen built a career on it.

Michael Steiner – CISO, Axel Springer National Media & Tech

Most CISOs delegate the console work. Michael Steiner still takes shifts as manager on duty and administers security tooling himself, a hands-on habit he has kept since becoming CISO of Axel Springer National Media & Tech in May 2024. His record there is concrete: application and cloud security introduced across multiple business units, a vulnerability management process rebuilt with SLA governance and escalation models, IAM controls tightened, a structured incident management process established, and a public bug bounty programme launched as an added defensive layer for BILD, WELT, and POLITICO Europe. He had run the group’s quality and IT security competence centre since 2020, and came to security by way of software quality, having built and led quality assurance for BILD’s web and app products through the organisation’s agile transition. The security community of practice he built still sets standards across teams. News brands are targets, and Steiner treats their defence as operational work rather than posture.

João C. – CISO, Mobimeo

An unusual route to the CISO chair runs through the chief of staff’s office. João C. spent two years on Mobimeo’s board as chief of staff to the CEO, turning strategy into OKRs across product and engineering teams, before moving through an information security officer role into the CISO seat in March 2025. Mobimeo, Deutsche Bahn’s corporate startup for mobility platforms, handed him a specific test: build an information security management system that could pass ISO 27001 certification while satisfying a railway group’s own demanding standards. He passed it, establishing a certified ISMS aligned to DB requirements, an incremental compliance strategy that lifted security posture without stalling engineering, and third-party risk processes that meet both international standards and group demands. His earlier career was commercial rather than technical, including launching Wunder Mobility’s operations in Brazil and later shaping a new product line that opened a quarter of the company’s addressable market. Security leaders who have sat inside the CEO’s operating rhythm bring a different fluency to governance, and his trajectory shows it.

Kwadjo Nyante – CISO, Aignostics

Investor due diligence has become one of security’s hardest audiences, and Kwadjo Nyante has made a specialty of passing it. As CISO of Aignostics, the Berlin AI pathology company, since January 2023, he supported a $34 million Series B by aligning the security posture with what investors actually examine, and has defended yearly audits and ISO 27001 recertification with a one hundred percent pass rate and zero major findings to date. His programme embeds security into cloud-native AI and data platforms across AWS and GCP, cut phishing susceptibility by roughly seventy percent through high-fidelity simulations, and operationalised a security-debt process for tracking remediation. He came up through product security at TIER Mobility and offensive and defensive security work at Takeaway.com, and while at BTC.com published a cryptographic vulnerability, CVE-2018-19589, often described as a reverse ransomware attack. An ISC2 Global Achievement Award winner and Top 50 CISO honouree, he also serves as virtual CISO to Teneo AI, a Stockholm-listed AI company, extending his board-level assurance practice beyond Berlin.

Aleksandar Antonijevic – CISO and Head of Cyber Security, kloeckner.i

Steel and security rarely appear in the same sentence, which is part of what makes Aleksandar Antonijevic‘s current brief interesting. Since October 2025 he has been CISO and Head of Cyber Security at kloeckner.i, the digital arm of steel distributor Klöckner & Co, after leading its cyber security function from February that year. The path there ran through SoundCloud, where he spent nearly four years as Head of Security and Corporate IT in Berlin, and Blueground, where he headed information security for the global furnished-rentals platform. His earlier years in Belgrade, leading eFront to ISO 27001 and SSAE 16 certifications and running his own consultancy, gave him the compliance craft he now applies to industrial digitalisation. Fifteen years in, he describes himself as a change agent, and the cross-sector record from music streaming to metals supports the claim.

What Berlin’s Bench Reveals

Security leadership in Berlin no longer borrows its credibility from elsewhere. These seven have built programmes that survive audits, acquisitions, due diligence, and adversaries, often all four in the same year. The city’s mix of industrial heritage and venture-backed ambition demands security chiefs who can certify, defend, and explain, and this group suggests the supply has caught up with the demand.

Related reading:

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.