Made in Germany: The Country’s Cybersecurity Leaders to Watch

Related

Share

Germany’s largest companies tend to grow their cybersecurity leaders slowly, and the six below show it. One joined his employer in 1986 and has never left. Another has spent nearly 18 years at the same software company and came to security by way of business intelligence consulting and operations. Between them they protect enterprise software, a national telecom network, the world’s largest reinsurer, a global logistics group, the national railway, and the engineering platforms of an industrial conglomerate. Several of them built their security careers inside organizations whose products other companies depend on to run.

Marielle Ehrmann – CSO, SAP

Marielle Ehrmann did not start in security. She joined SAP in 2009 as a senior business intelligence consultant after three years as an SAP BW consultant at Freudenberg IT. She then spent more than a decade in operations and strategy roles, working on the HANA taskforce, directing strategy and operations for product development, and serving as chief of staff for S/4HANA Cloud solution management. That operational grounding led her into security in October 2023, when she became SVP and Chief Security Compliance and Risk Officer. There she ran company-wide security governance, certifications, customer trust programs, and risk management. She became Chief Security Officer in July 2026. Since January 2026 she has also served on SAP’s Supervisory Board.

Thomas Tschersich – CSO, Deutsche Telekom, and CEO, Telekom Security

Thomas Tschersich began at Deutsche Telekom in 1986 and has built his entire career there. He worked as a network security engineer in the 1990s, then spent six years as Vice President for Security Strategy and Politics and more than five as Senior Vice President for Group IT Security. As SVP for Internal Security and Cyber Defense, he also served as CTO of Telekom Security. Tschersich became Deutsche Telekom’s Chief Security Officer in July 2020. Since November 2022 he has also led Telekom Security as its chief executive, turning the group’s security expertise into services for other companies under the principle that “security is for sharing.” He describes his role as mediating between cybersecurity and general management, translating each side’s concerns for the other.

Philipp Südmeyer – Group CISO & Global Head of Non-Financial Risk Management, Munich Re

Philipp Südmeyer served as a lieutenant in the German Navy before starting in financial services as a graduate trainee and security analyst at Deutsche Bank. He worked as a security architect in London and then as a vice president for security architecture and project management. In 2013 he became Group CISO and head of information security management at DZ BANK, a role he held for more than six years. Südmeyer joined Munich Re as Group CISO in December 2019. In August 2022 he added the role of Global Head of Non-Financial Risk Management, bringing operational risk and business continuity under the same leadership as information security at the world’s largest reinsurer.

Frank Fischer – Group CISO, DHL Group

Frank Fischer spent the first part of his career on the vendor side. He was a senior project manager at Gillette and a business development manager at BMC Software, then spent close to a decade at Tivoli and IBM, eventually leading IBM Germany’s security practice. As a partner at Accenture he ran a team of more than 30 focused on security and data center transformation. Fischer moved into the CISO chair at Deutsche Börse in 2014, serving as EVP and head of information security for more than four years, then led cybersecurity at Deutsche Bahn for nearly five. He became Group CISO of DHL Group in September 2023. His work spans IT and OT security, insider threat, and cloud security across AWS and Azure. He has more than 15 years of SAP experience.

Michael Löttner – CISO, Deutsche Bahn

Michael Löttner is a telecommunications engineer by training, with a Diplom-Ingenieur in electrical engineering from RWTH Aachen. He started as a development engineer at Arcor and spent more than six years at DB Telematik before moving to DB Systel, the railway’s IT subsidiary. There he headed IP network planning, then unified communications and collaboration, and then network services as SVP. He left for four years to lead Deutsche Telekom’s southwest technical branch in Karlsruhe, then returned to Deutsche Bahn as CISO in February 2024. Since August 2026 he has also held the CISO role for several DB group companies, including DB JobService, Usedomer Bäderbahn, and the Deutsche Bahn Foundation. He previously sat on the supervisory board of Hit Rail, a European railway IT consortium.

Paul El Khoury – Chief Cybersecurity Officer & CISO, Foundational Technologies, Siemens

Paul El Khoury was the governor of SAP’s Security Patch Day from its pilot until SAP announced it to customers in September 2010. He had joined SAP as a security researcher, working on security patterns and an EU-funded eHealth project, and has since filed more than 15 patents across Europe, the United States, and China. He co-owned SAP’s product security standard for nine years. From 2017 to 2019 he served as SAP’s first CISO for China, covering six locations and working with Chinese government authorities on cybersecurity regulation. After leading SAP’s agile secure development program and product security for its SaaS portfolio, he joined Siemens Digital Industries Software as Chief Product and Solution Security Officer. Since May 2025 he has been Chief Cybersecurity Officer and CISO for Siemens Foundational Technologies and a member of the Siemens Cybersecurity Board. He holds a Ph.D. in security engineering and a CISSP.

Security Grown From Within

Germany’s industrial giants appear to prefer security leaders who understand the business from the inside. Tschersich has spent four decades at Deutsche Telekom. Ehrmann ran operations and strategy at SAP before taking charge of its security. Löttner built railway networks for more than a decade before becoming Deutsche Bahn’s CISO. El Khoury wrote the product security standards that SAP developers still follow before he took his expertise to Siemens. Fischer and Südmeyer came up through consulting and banking, but both have since spent years protecting companies whose systems move goods, money, and risk across the world. The common pattern is depth: leaders who know how their organizations actually work, often because they helped build them.

Discover more CISOs securing their organizations:

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.