Austria’s cybersecurity leaders took some of the most varied routes into the field of any country in this series. Among the seven below are a former professional martial arts athlete who analyzed threats for the Ministry of Defense, an IBM veteran of 36 years who started writing financial applications in 1989, and a security manager who co-founded a social enterprise supporting coffee producers in Mexico. One has served as Group CISO at three different Austrian banks. Another spent nearly two decades in oil and gas before taking charge of security for the national railway. Together they protect rail, banking, a technical university, industrial groups, and digital services.
Hansjörg Kalcher – Group CISO, ÖBB Holding
Hansjörg Kalcher spent nearly 19 years at OMV. He joined as an IT expert in 2002, worked in IT strategy, and served as the energy company’s CISO for more than 14 years before moving into OT security. He then spent a year and a half as CISO of ARZ Allgemeines Rechenzentrum, a financial services IT provider. Kalcher became Group CISO of ÖBB Holding in August 2022. He teaches IT security management at FH Technikum Wien and, since 2025, a course at FH St. Pölten on information security in the rail sector, where availability and safety sit alongside confidentiality and integrity as core protection goals.
Klaus Johannes Rusch – CISO, TU Wien
Klaus Johannes Rusch spent 36 years at IBM in Vienna. He started in 1989 as an application developer building financial applications and a document imaging system for a national bank. In 1997 he became a senior webmaster, consolidating more than 30 European IBM country sites onto a common platform, and later led global web effectiveness and enterprise architecture teams. He co-founded the Hyperledger Vienna meetup and contributed to IBM Academy of Technology blockchain studies. Rusch moved into security in 2019 as manager of IBM’s computer security incident response team, leading investigations into large-scale ransomware attacks. He went on to build a 24×7 European SOC team and led cybersecurity defense for Europe and India and security testing globally, with more than 50 professionals. He also served as IBM’s national security representative to Austria’s state protection and intelligence directorate. He became CISO of TU Wien in October 2025. He has run his own web design and hosting business since 1996, taught computer science at Webster University for seven years, and earned the GCIH certification with a 99% score.
Nikolaus Brandstetter – Group CISO, MM Group
Nikolaus Brandstetter competed as a professional martial arts athlete in Brazilian jiu-jitsu and Sanda for five years. He then spent three years as an analyst at the Austrian Ministry of Defense before moving into security consulting at SEC Consult, Accenture, where he led GDPR work for the DACH region, and EY. At SGS he headed secure networks, communications, and cloud, then served as global product lead for information security assurance. After nearly three years as CISO and head of security at Schoellerbank Wealth Management, he became Group CISO of MM Group in October 2024. He now protects operations spanning more than 70 locations and 15,000 employees across IT and OT environments, and has published on AI technology and leadership.
Gerald Schremser – CISO, Prinzhorn Holding
Gerald Schremser joined Prinzhorn Holding in 2021 as an IT infrastructure manager. He took on the dual role of CISO and chapter lead for IT infrastructure and integration, combining security leadership with responsibility for the group’s infrastructure for more than three years. Since February 2025 he has served as the group’s Chief Information Security Officer full time. He holds the CISM certification.
Andreas Schaupp – Group CISO, BAWAG Group
Andreas Schaupp has served as Group CISO at three Austrian banks. He started as a network manager at ÖTOB Clearing Bank in 1991, then spent more than nine years as a managing consultant for IT networks and security at HP. He was Group CISO and vice president at Raiffeisen Bank from 2005 to 2010. After running his own consultancy, which worked on Gemalto’s CardTAN e-banking project for Austrian banks, and leading cybersecurity for CSC in Austria and Eastern Europe, he headed group information security management at Erste Group. Schaupp has been Group CISO of BAWAG since May 2019. He lectured at Danube University Krems for 21 years and now teaches at FH Campus Wien. His certifications include CCIE, CISSP, CISA, and Certified Ethical Hacker.
Lukas Kulmitzer – (Former) CISO, eurofunk Kappacher
Lukas Kulmitzer started as an IT advisory consultant at EY, auditing IT systems and helping clients build internal control systems. At Infineon Technologies he performed ISO 27001 and TISAX audits for the company’s global entities and served as information security officer for Infineon Austria. He then ran business continuity and information security management at cloud provider Anexia and built a global IT security team as head of IT security at the education startup GoStudent. From 2023 to 2026 Kulmitzer was CISO and head of information security at eurofunk Kappacher, where he built the corporate security team and maintained its management systems under ISO 27001 and Germany’s BSI IT-Grundschutz. He also taught system security as an external lecturer at the University of Klagenfurt for seven years.
José Torre – CISO & Data Privacy and Compliance Officer, A1 Digital
José Torre began with internships at Microsoft and the law firm Red Legal in Mexico City. He worked as a product manager at Visor ADL and co-founded El Buen Coyote, a social enterprise supporting coffee producers in Mexico. In 2022 he joined fiskaly in Vienna as information security and privacy manager, building an integrated management system and handling GDPR compliance for three years. Torre became CISO and Data Privacy and Compliance Officer at A1 Digital in November 2025.
Many Roads to the Same Seat
Few countries produce security leaders from such different starting points. Brandstetter came out of competitive martial arts and defense intelligence, Torre out of product management and social entrepreneurship, and Rusch out of web architecture and blockchain at IBM. Kalcher and Schaupp represent the other end of the spectrum, with decades as CISOs in oil and gas and banking. Several of them also teach, at FH Technikum Wien, FH St. Pölten, FH Campus Wien, Klagenfurt, and Krems, passing on what they learned along the way. In a country of interconnected industries and institutions, that mix of backgrounds gives Austria’s security bench unusual depth.
Discover more CISOs securing their organizations:
- From the Carabinieri to the Grid: Italy’s Cybersecurity Leaders to Watch
- Beyond the Silicon Docks: Ireland’s Cybersecurity Leaders to Watch
- The Nokia Generation: Finland’s Cybersecurity Leaders to Watch
- Precision and Trust: Switzerland’s Cybersecurity Leaders to Watch
- Small Country, Big Mandates: Denmark’s Cybersecurity Leaders to Watch
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

