A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the CIOReview Advisory Board.

METRO AG

Guarding the Future with Strategic Cyber Risk Management

Ange Ferrari

Ange Ferrari is Senior Vice President and Chief Information Security Officer at METRO AG. With over two decades of experience in cybersecurity and IT architecture, he leads global programs focused on organisational resilience, digital risk and compliance management. His leadership blends zero-trust principles, agile transformation and business alignment to secure operations across METRO’s global and multi-channel wholesale landscape.

I n this interview, Ange Ferrari shares how a resiliencefirst mindset, risk-informed innovation, and strategic alignment redefine cybersecurity at METRO AG. By integrating zero trust architecture, regulatory foresight, and business continuity planning, he illustrates how cybersecurity can move beyond defense to become a core growth enabler. His approach demonstrates how security leadership must evolve to protect, empower, and scale global organisations in an increasingly decentralised, AI-driven world.

Shaping Cyber Defense into Holistic Business Continuity

I began my cybersecurity career straight out of high school as a security auditor and penetration tester. Those early offensive roles sharpened my technical instincts. Still, I quickly pivoted to the defensive side—working as a developer, architect, and system administrator—to understand how resilient information systems truly support business operations. My first CISO post came at a major French e-commerce platform, where the security program I introduced dramatically reduced recurring incidents. That success propelled me into senior roles at Carrefour and other large retailers, including transformative assignments in Latin America. Today, I serve as Senior Vice President and Chief Information Security Officer at METRO AG.

At METRO, my mandate stretches well beyond traditional cyber defense. I am responsible for building holistic organisational resilience that fuses cybersecurity, business continuity and IT service continuity management. My goal is to embed the competencies, processes, and technologies that keep METRO operating, even during ransomware attacks, supplier outages, or other disruptive events. Zerotrust architecture anchors this strategy, safeguarding our infrastructure, networks, and data at the enterprise scale.

AT A GLANCE

•Securing Business Resilience – Integrated cybersecurity, service management, and business continuity into a unified resilience framework to ensure METRO AG operates securely during crises.

•Building Cyber Culture – Developed a global network of “Security Champions” to embed security expertise in every business unit and elevate incident-response capabilities across teams.

•Navigating Complex Regulations – Deployed a real-time regulatory heat map to proactively anticipate compliance needs across global markets and adapt controls.

•Securing AI and Cloud Frontiers – Pioneered AI risk governance frameworks and advanced monitoring systems to address decentralised data, agentic AI and third-party cloud risks.

Advancing Access Management and Crisis Preparedness

One flagship initiative under my leadership re-imagines access management. We ensure colleagues receive the correct data and system permissions from day one and lose those rights when they no longer need them. This protects sensitive information while accelerating METRO’s digital transformation. In parallel, I spearhead the “minimum viable enterprise” program, identifying the core processes necessary to keep the business running during extreme crises—natural disasters or systemic failures. By aligning every control with our risk appetite, I enable the organisation to innovate boldly while managing risk through compensating safeguards or explicit acceptance rather than blocking progress.

“Regular dialogue with executive leadership help prioritise resilience, while a talent development program brings in fresh and diverse talent and creates pathways for underrepresented groups to enter the profession”

Beyond technology, I invest heavily in culture and talent. My team builds an internal “Security Champions” network that embeds cyber expertise in every business unit, and we track success with metrics tied to incident-response speed, privilege hygiene, and recovery time. Regular tabletop exercises with executive leadership help prioritise resilience, while a rotating internship program brings in fresh talent and creates pathways for underrepresented groups to enter the profession.

Evolving Regulations, Decentralised Threats, and Guidance for Fellow CISOS

During my two decades in security, the regulatory landscape has expanded from a handful of national data-protection rules to comprehensive frameworks like GDPR—now intertwined with emerging laws on non-personal data, digital products, and algorithms. Because METRO operates across many jurisdictions, I must understand the letter and the intent of each regulation, translate requirements locally, and anticipate further tightening as Europe sets new global precedents. To stay ahead, my team maintains a living “regulatory heat map” that scores upcoming rules by impact and readiness, allowing us to prioritise resources proactively instead of reactively.

Concurrently, our technology estate has become highly decentralised. Cloud platforms, SaaS solutions, and partner networks now host workloads once kept on-premises, rendering traditional perimeter defenses insufficient. My roadmap, therefore, emphasises shared responsibility models, rigorous vendor diligence, and dynamic, risk-based controls to protect data flowing freely across distributed systems. We conduct continuous assurance reviews with critical suppliers and use automated evidence collection to validate their compliance with our requirements.

Securing AI Workflows And Shaping Policy Strategy

Generative and agentic AI adds another layer of complexity. External models and autonomous agents can process sensitive information outside our direct control, challenging traceability and oversight. I invest in next-generation monitoring technologies, model-risk management playbooks, and an AI ethics board to ensure secure, transparent, and predictable AI-driven workflows.

For peers managing compliance and risks across both mature and emerging jurisdictions, my advice is straightforward: first, decide whether compliance is an end goal or a milestone on the path to broader security maturity, be clear on the risks you can afford and those you cannot. Then, each requirement should be linked to business objectives so that security is viewed as an enabler, not a brake. Cultivate open dialogue with the board, translate technical risk into business impact, and contribute to industry threat-intelligence communities—because no organisation defends alone. Ultimately, success hinges on understanding executive priorities, aligning cyber programs with growth ambitions, and helping the organisation “run fast, scale safely, and take manageable risks”.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
Top