From Audit Rooms to Smart Cards: France’s CISOs to Watch

Related

Share

France’s CISOs reached the role from directions that rarely overlap. One of the six below started in cryptography at the French defense procurement agency in 1992. Another spent more than a decade making SIM cards and smart card production lines run before he ever led a security team. A third built his career in IT audit, a fourth in business continuity and crisis management, and a fifth began with an internship at France’s permanent delegation to the OECD. They now protect two of the country’s largest banks, an energy technology group, a retail giant, a defense and technology group, and the national postal group.

Sylvain Thiry – Global CISO & Head of IT Risk Management, Société Générale

Sylvain Thiry has spent 30 years in cybersecurity. He started in IT and security integration projects at Aenix and managed security projects for SFR and Crédit Agricole at Apogée Communications. At Sinclair & Partners he created and ran a cybersecurity department of 15 consultants, then spent more than seven years as a senior consultant at Solucom, now Wavestone. In 2008 he became Group CISO of SNCF, the national railway, and later led its IT governance, strategy, and architecture before directing application integration for its group IT shared services. Thiry joined Société Générale in 2017 as Group IT Infrastructure CISO and has served as Global CISO and Head of IT Risk Management since July 2020. He leads a worldwide team of 1,600 cybersecurity specialists on a €270 million budget, with priorities including Zero Trust, identity and access management, AI-driven security, and compliance with DORA and NIS2.

Christophe Blassiau – SVP, Global CISO & CPSO, Schneider Electric

Christophe Blassiau began in information security and cryptography at France’s defense procurement agency, the DGA, in 1992. He joined Schneider Electric later that year as an IT project manager and went on to build its electronic catalogue, covering 100,000 products in 30 languages. In 2000 he left to found 3c-evolution, an IT services company he grew to 50 employees and €3 million in annual revenue over 11 years. Blassiau returned to Schneider in 2011 to lead global CRM programs serving 25,000 Salesforce users, and later ran customer experience and CRM as senior vice president. He became SVP of Cybersecurity and Global CISO in January 2018 and added Chief Product Security Officer in March 2023, taking responsibility for the security of Schneider’s products as well as its enterprise.

Alain Rogulski – Group CISO, Carrefour

Alain Rogulski spent the first two decades of his career in audit. He started as an auditor at Ernst & Young in Paris, became a manager at PricewaterhouseCoopers, and worked as a senior consultant at Ernst & Young in New York. He then led IT audit at Alcatel and later served as IT audit director at Alcatel-Lucent. Rogulski joined Sodexo in 2011 as head of IT audit and became its Group CISO in 2015, a role he held for nearly ten years. He was appointed Group CISO of Carrefour in June 2025.

François Baverel – CISO, Thales

François Baverel trained as a general engineer specializing in computer science and spent his early career in smart cards. At Schlumberger he developed smart card personalization applications, trained developers and customers in the United States and India, supported GSM operators as a sales engineer, and managed the SIM card product line. He went on to run smart card test and personalization in volume production at Pont-Audemer, implementing security standards for GSM cards. At Gemalto he managed IT production for the plant, then led corporate IT security as IT security manager and later IT security officer, covering network segregation, encryption, GDPR, and third-party security. Baverel has been CISO of Thales SA since June 2019. He holds a CISSP.

Caroline Le Donche – CISO, La Poste Groupe

Caroline Le Donche built her career in business continuity and crisis management. She spent six years as a consultant for clients including Société Générale, Natixis, and LVMH, then worked as a senior consultant at Almond. At LCH in Paris she managed business continuity and physical security for five years, then served as head of resilience, CISO, and crisis manager. She moved to La Banque Postale in 2021 as head of sovereign activities and then head of cyber risk. Le Donche became CISO of La Poste Groupe in December 2025, with responsibility for governance, risk, and compliance.

Sébastien Braillon – CISO, BNP Paribas RISK

Sébastien Braillon started with an internship at France’s permanent representation to the OECD, drafting briefing notes and summarizing debates. He joined BNP Paribas in 2014 as a CISO assistant in the compliance function, then worked as a governance, risk, and compliance consultant for Harmonie Technologie, embedded in the security team at GE Money Bank. Returning to BNP Paribas in 2017, he steered the cybersecurity progress of more than 20 group entities as part of the Group Cybersecurity Program and later monitored IT and cyber risk for BNP Paribas USA, Switzerland, and Wealth Management. Braillon has been CISO of BNP Paribas RISK since February 2022.

Many Paths to the Same Seat

What sets France’s CISOs apart is how differently they arrived. Rogulski audited companies for two decades, and Baverel built smart card production lines. Blassiau founded and ran his own company before returning to lead security at the company where he started. Le Donche came through crisis management and resilience, and Braillon through the banking risk function. Thiry is the closest to a traditional security career, and even he moved through IT governance and shared services along the way. In a country that puts heavy emphasis on sovereignty, regulation, and continuity, that breadth of experience is exactly what these organizations need.

Discover more CISOs securing their organizations:

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.