For Tamoor Sarfraz, cybersecurity is not simply about protecting data or keeping attackers out. As CISO at Adbri and a Governing Body Member with Evanta, a Gartner company, his work sits at the intersection of enterprise IT, operational technology, industrial environments, and the business systems that keep essential operations running. With more than 18 years of experience spanning critical infrastructure, government, financial services, and consulting, Sarfraz has led cybersecurity transformation across complex environments, covering everything from governance and risk to security operations, incident response, cloud, identity, and third-party assurance.
That experience makes his perspective particularly valuable for CISO Diaries, a series exploring the decisions, habits, and challenges that shape the everyday lives of security leaders. Sarfraz brings a perspective rooted in the reality that security controls must work within the environments they are designed to protect, especially when production, safety, and operational continuity are at stake. In this conversation, he discusses the mental challenge of securing IT and OT without disrupting operations, why accountability is one of his most important security habits, and how AI agents, software actors, and connected machines will force security teams to rethink identity, authority, digital provenance, and trust.
How do you usually explain what you do to someone outside of cybersecurity?
I describe a modern organization as a system made up of people, digital services and, in my field, industrial operations. I identify where a cyber incident could disrupt that system, explain the potential consequences in business terms and coordinate the safeguards required to keep it resilient.
The role combines strategy, communication and crisis leadership. Success means the organization understands its exposure, makes informed choices and remains capable of delivering its essential services when technology is under pressure.
What does a “routine” workday look like for you, if such a thing exists?
My day generally moves across three time horizons. The first is the immediate operational picture: material alerts, emerging exposures and anything that could affect production or safety. The second is program delivery, including architecture, supplier risk, security initiatives and risk decisions. The third is longer-term strategy, compliance, capability development and executive reporting.
I also make time for the security team because sound judgment and leadership depth cannot be developed through dashboards alone. During an incident, every other priority gives way to protecting people and operations, establishing reliable facts and coordinating decisions.
What part of your role takes the most mental energy right now?
The most demanding decisions occur at the boundary between enterprise IT and operational technology.
A technically attractive security control may still be unsuitable if it interrupts a plant, introduces a safety concern or fails to account for the life cycle of industrial equipment. I must combine threat evidence, engineering constraints, regulatory expectations and business priorities into a course of action that leaders can support. The objective is a proportionate improvement that strengthens security without compromising the operation it is intended to protect.
What’s one security habit or routine you personally never skip?
After a material risk discussion, I make sure three things are clear: who owns the decision, what evidence will demonstrate progress, and when the matter will be reviewed again.
Risks without ownership can remain unresolved until they become urgent problems. This small discipline converts discussion into accountable action and prevents important security concerns from disappearing into meeting minutes or crowded inboxes.
What does your own personal security setup look like?
My personal security setup is intentionally straightforward. I avoid credential reuse by using unique passwords generated and stored in a secure password manager. I also enable the strongest form of multi-factor authentication available on important accounts.
My devices are encrypted, lock automatically, and receive updates promptly. I maintain secure backups of important data and periodically test the recovery process. I also use an on-device firewall and DNS filter. I have a very robust home network. I also avoid disclosing unnecessary details about the technology I use. I prefer to explain the security principles rather than publish brands or detailed configurations that could provide useful reconnaissance.
What book, podcast, or resource has influenced how you think about leadership or security?
NIST and COBIT have significantly influenced my approach to security leadership because it treats technology and security as governance responsibilities rather than isolated technical activities.
It reinforced the importance of decision authority, accountability and alignment with enterprise objectives. Before recommending a control, I consider the outcome it supports, who will be accountable for it, what evidence will demonstrate its effectiveness, and how the organization will assess the value of the investment. This creates more productive conversations with executives and boards.
What’s a lesson you learned the hard way in your career?
An excellent security design can still be a poor organizational solution.
Earlier in my career, I sometimes focused on the quality of a control before fully understanding the environment and the people expected to sustain it. A control that cannot be operated, maintained or clearly explained will eventually deteriorate. I now involve operational stakeholders earlier, test assumptions in their environment, and design for lasting adoption rather than simply securing approval.
What keeps you up at night right now, from a security perspective?
The declining reliability of digital context concerns me. Compromised identities, manipulated information, deepfakes, and misuse of third-party access can make a fraudulent instruction appear legitimate or cause a genuine warning to be dismissed as routine.
In environments spanning IT and operational technology, decisions based on false information can have consequences beyond data loss, affecting production, safety, and supply. Establishing confidence in identity, data provenance, and authorized command paths is becoming as important as detecting malware.
Also, the open-weight AI models are catching up fast with Frontier models (US). No one is talking about the power capabilities that anyone can download and deploy locally without provider-level safeguards, monitoring, or recall. The risk is no longer defined by who built the model, but by what it can access, what authority it has, and whether its actions can be observed, constrained, and stopped. Speed will be the deciding factor between offenders and defenders.
How do you measure whether your security program is actually working?
I use several layers of evidence. Operationally, I examine how long serious exposures remain unresolved, visibility and control coverage across critical assets, detection effectiveness, containment performance, and recovery outcomes. From a governance perspective, I assess whether major risks have clearly owned treatment plans, whether security exceptions are aging and whether assurance findings are recurring.
No single metric demonstrates effectiveness. A program is progressing when independent evidence shows that credible attacks are harder to execute, incidents are detected earlier and containment and recovery are faster and less disruptive.
What advice would you give to someone stepping into their first CISO role today?
Spend the opening months understanding the organization rather than demonstrating your knowledge of security products. Learn which services cannot stop, where decision authority sits, what previous incidents revealed, and where colleagues already experience security-related friction.
Agree on a small number of outcomes with the executive team, establish consistent risk language and deliver a few visible improvements while developing a sequenced roadmap. Have the confidence to say, “I do not know yet,” and return with evidence. Credibility comes from dependable judgment, not instant certainty.
What do you think will matter less in security five to ten years from now?
The reflex to add another standalone security product whenever a problem emerges will matter less. Fragmented controls frequently create additional integration effort, inconsistent information and unclear accountability.
Routine investigation and evidence collection will also become increasingly automated. Architecture, governance and assurance will remain valuable, as will people who can assess consequences across technology and operations. Organizations will care less about how many products or alerts a security function manages and more about the quality and timeliness of the decisions it supports.
Looking ahead 10 years, what do you believe security teams will spend most of their time on that they don’t today?
Security teams will increasingly govern large populations of software actors, AI agents, service identities, automated workflows, and connected machines. Each will require an accountable owner, defined authority, reliable data, observable behavior, and a dependable way to constrain or stop it.
Teams will spend more time validating digital provenance, modeling cascading failures, and creating policies that technology can enforce dynamically. In industrial settings, security, engineering, and safety assurance will converge further. The work will shift from examining isolated events towards supervising interconnected decisions occurring at machine speed.

