CISO search for critical infrastructure: OT expertise as dealbreaker
About the organisation
International energy company with 8,500 employees and operations in the Netherlands, Belgium and Germany. Manages 3 power plants, 12,000 km of gas pipeline and 200+ SCADA systems. Designated as an essential entity under NIS2.
The Challenge
The previous CISO departed after a reorganisation and the position had been open for 5 months. The profile was extremely complex: the CISO needed experience with both IT and OT/ICS security, NIS2 compliance for critical infrastructure, board-level communication in Dutch and German, and at least 10 years of leadership experience in a regulated environment.
Three traditional executive search firms had each searched for 8-12 weeks without finding a suitable candidate. The problem: they had no network in the niche where IT security leadership and OT/ICS expertise converge. The Board of Directors demanded that the position be filled within 2 months, as the NIS2 deadline was approaching and the organisation lacked adequate governance without a CISO.
Our Solution
MVPermanent conducted a targeted executive search, specifically focused on the intersection of IT security leadership and OT/ICS. We approached 23 potential candidates from our network of senior security leaders with experience in energy, water and industrial sectors. Each candidate was evaluated against a scorecard with 14 criteria, from SCADA security to board reporting.
The difference lay in our sector expertise: we understood that a CISO in the energy sector must not only be a security strategist, but also someone who understands the operational reality of a control room. We organised an assessment with a case study based on a realistic OT incident scenario. The final candidate scored in the top 3 of all CISO profiles we have ever assessed.
Results
- CISO appointed within 7 weeks (after 5 months without result via other firms)
- Security strategy presented to the Board of Directors within 90 days
- OT security roadmap delivered with 3-year investment plan
- Board-level reporting structure implemented (monthly CISO dashboard)
- First TIBER-NL test successfully completed within 8 months of appointment
“MVPeople's sector expertise made the difference. They understood that our CISO needs to know more than just ISO 27001 — they also need to know what happens when a PLC controller fails in a power plant. You won't find that combination at a generalist firm.”
What the team says
“The assessment with the OT incident scenario was brilliant. It immediately filtered candidates who only had IT experience from those who truly understand how critical infrastructure works.”