Twenty-five years in identity and security — building authorization systems, then carrying regulatory accountability for them. Agentic AI is the hardest thing to happen to this discipline in a decade: an opportunity in how identity gets engineered, and a genuine risk in what it grants access to. I want to own that, in both directions, for the enterprise.
Authorization concepts for more than 3,000 users, SOX-audited and PwC-attested. In 2001 I wrote an authorization management tool myself — its users nominated it for the Innovation Award.
Operating modelOne owned outright, one governed through engineering teams and delivery partners without line authority over any of them. Both since 2016.
What comes nextI ship AI-assisted systems myself, and argue publicly where agentic automation belongs — and where it quietly manufactures audit findings.
Why me
From 1998 to 2012 I worked inside identity and access. Authorization concepts for more than 3,000 users at Philip Morris International and Zurich, SOX-audited and PwC-attested, covering segregation of duties, attestation, recertification and the interface to audit. In 2001 I designed and programmed an authorization management tool end to end — the customers who used it nominated it for the Innovation Award, which it won.
Since 2014, as CISO DACH and then EMEA Regional CISO at Zurich Insurance Group, I have been accountable for identity governance in front of FINMA, BaFin and the CBI. Zero Trust and Conditional Access are pillars of a group security strategy I co-developed. Across cloud and move-to-cloud programmes I set the security standards and held internal engineering teams and external delivery partners to them — without line authority over a single one of their engineers.
The two estates
Owning a platform you control is a delivery problem. Owning a standard that other people's engineers have to meet — with a partner contract in between and an auditor at the end of it — is a different discipline, and it fails in different ways. Both have been part of my mandate since 2016.
Owned outright, delivered as code, governed to FINMA standards. This is the estate where my IAM foundation and my governance record meet.
Built by engineering teams and delivery partners. I own the strategy, the standards and the relationships — and carry the risk when it goes wrong.
Where my experience maps directly
Access reviews, segregation of duties, attestation, recertification and least privilege are not a control list I would be learning. I designed them for more than 3,000 users, had them audited under SOX and attested by PwC, and owned the audit interface myself.
Hands-on with Microsoft Entra ID and Privileged Identity Management. Conditional Access and Zero Trust are pillars of a security strategy I co-developed and was accountable for — and as CISO DACH I held governance over identity management and Active Directory directly.
Most recently I worked directly with our security engineers on a post-quantum cryptography whitepaper, assessing PQC readiness and what the migration means for our cryptographic estate. Not commissioned from a distance and presented back to me — written with the engineers doing the work. That is the working style this role asks for, and it is the one I already have.
I am already the person Risk, Audit and the regulator turn to. I front FINMA, BaFin and CBI engagements and translate their expectations into defensible processes, evidence, policy documentation, KPIs and KRIs. Audit-readiness as routine, not as a project.
I designed and rolled out Zurich's Data Incident Management process globally — recognised with the Group Compliance Award — and was the single point of ownership across Security, Legal, Compliance and Risk. Making identity signals reach the SOC and stand up under a real incident is work I have already done once.
Budget, contract, licensing and third-party risk ownership including escalation. As Head of IT Service Operations I ran incident, change and escalation as a discipline with ITIL-certified processes — the run half of run-versus-change, from the inside.
Monthly reporting to COOs, risk narratives and decision papers in executive committees, and technical challenge in the same week. Defending an identity roadmap to a regulator, a CIO and an engineer on the same day is a description of my current job.
I lead BISO teams across EMEA — different countries, different regulators, no shared office. Set a clear standard, give people the mandate to own their market, stay accountable for the outcome myself. Two of my former direct reports describe a decade of mentoring below.
AI-enabled and non-human identity
I work extensively on agentic AI and am a regular voice at CISO roundtables on agentic AI and non-human identity — including the need for micro- and nano-segmentation of access that follows from it. My position: once AI agents become first-class identities, least privilege has to be enforced at a granularity that classic RBAC models can no longer deliver.
An identity architecture that treats AI agents, workload identities and service accounts as a first-class identity type from day one — with least-privilege scoping, credential management and guardrails that hold up in front of FINMA.
You asked for demonstrated use of AI tooling to increase engineering output, with a considered view of its risks and limits. Mine is not a slide. Outside my day job I design and ship working systems with AI-assisted engineering:
That is the same engineering discipline this role wants applied to identity — and it is why I can say honestly that I know both what AI-assisted delivery accelerates and where it quietly produces work that will not survive an audit.
"If you give AI agents access without rethinking identity, you haven't built automation — you've built an audit finding."Marko Hartwig, CISO roundtable on agentic AI & non-human identity
Against your essential criteria
You will check this list anyway. I would rather be the one who brings it up — including the parts where the honest answer is "adjacent, not equivalent". A candidate who cannot tell you what he still has to learn is not a candidate you want owning identity risk.
Track record
Identity relevance: co-developed Zero Trust and Conditional Access as strategy pillars; set security standards for cloud and move-to-cloud programmes and held internal engineering teams and external delivery partners to them without line authority; owned vendor contracts, budget and escalation; fronted FINMA, BaFin and CBI on control questions. Alongside that: regional implementation of the global security strategy, leadership of distributed BISO teams and Board reporting.
Identity relevance: direct governance over identity management, Active Directory and device access control, plus SOX and internal controls. The role where my hands-on IAM background became an accountable governance mandate.
Identity relevance: ownership of access and identity management, and SAP GRC 10.0 as Corporate Head of Audit & Security. As Head of IT Service Operations I ran incident, change and escalation with ITIL-certified processes — the service-management half of this mandate.
This is the foundation the rest is built on. Authorization concepts for more than 3,000 users, SOX-compliant and PwC-reviewed, covering segregation of duties, attestation, recertification and the interface to audit. Innovation Award (2001) for an authorization management tool at Philip Morris International that I designed and programmed end to end — nominated by the customers who used it, which is the endorsement I still value most. Later led SAP BI platform teams with ITIL-certified processes.
What the people who worked with me say
LinkedIn recommendations from people who reported directly to me, from peers, and from a senior colleague outside my reporting line. The themes they return to unprompted: calm judgment under pressure, a team built to be accountable, and mentoring that lasted a decade. One of them also confirms the ISO 27001, NIST CSF and regulator record without being asked to.
"Marko is a highly experienced security leader who defines and leads Information Security strategy across complex, regulated environments, with teams spanning all of Europe and the Middle East. He built a strong and accountable team and fostered a culture of continuous improvement and development. His skill in leadership was especially notable during the pandemic lockdowns, when the team always felt together despite being geographically dispersed. […] He operates with authority at Board and C-suite level and has extensive experience working with regulators and audit functions, including FINMA, BaFin and the CBI, consistently delivering strong outcomes. […] I would strongly recommend him to any organisation seeking a CISO with proven leadership, deep technical expertise and the ability to deliver in highly regulated environments."
"Marko is a one-of-a-kind executive leader who understands putting people where their strengths are and creates great team spirit, while being approachable, empathetic and empowering at the same time. With his wealth of skills and knowledge, security is not only a profession for him but also a passion. He sparks curiosity to learn and a willingness to go the extra mile for what is right instead of what is convenient. I am deeply thankful for having had the opportunity to get to know him and to learn from one of the best. He was a fantastic mentor to me over the course of 10 years."
"I really enjoyed working with Marko and have huge respect for the way he leads. He brings calm, clarity and strong judgment to complex information security and cyber topics, making discussions both productive and reassuring. Marko is also a generous mentor: he consistently takes the time to explain context, challenge thinking constructively, and support others in building confidence when navigating senior or complex discussions. It has been a pleasure working with him, and I would gladly recommend him as a thoughtful and impactful cyber security leader."
"It has been a privilege working with Marko over the past decade. He is a thoughtful leader who focuses on leveraging team strengths to achieve security goals while maintaining a supportive and accessible management style. I have particularly appreciated his dedication to ethical, thorough work and his consistent commitment to mentoring, which has had a meaningful impact on my professional development."
"Marko and I worked closely together to deliver a consistent security service to the Group Functions, Corporate Center and the Swiss Business Unit within the Zurich Insurance Group. His collaborative focus, leadership and approach to people made this journey enjoyable, and he was able to support a broad range of business challenges. I can highly recommend him."
"I had the pleasure of working with Marko at both PMI and Triumph, and I highly value and appreciate his open spirit, his willingness to drive change, and his leadership."
Why this role, why now
Agentic AI is the most consequential thing to happen to this discipline in a decade, and it arrives as both halves at once: a genuine multiplier in how identity is engineered and governed, and a genuine risk once agents become identities that hold access in their own right. Most organisations will meet that as a problem after the fact. I want to own it before it arrives, and shape it deliberately — for the enterprise, not just for the control. This mandate puts the control plane, the engineering resource and the accountability in one pair of hands, which is the only configuration in which that is actually possible.
Someone who has already been the person the regulator turns to when a control is questioned, who has built the identity governance you need before it was called that, and who will not need to be taught what audit-readiness costs.
I want this mandate, and I will carry the accountability that comes with it.