Andreas Gaetje: From Auditor to CISO at Körber AG

Andreas Gaetje, with a background in economics and audit, became Körber AG chief information security officer in 2019 after leading security at Körber IT Solutions.

Andreas Gaetje became chief information security officer at Körber AG in 2019 after serving as CISO at Körber IT Solutions. Körber AG is a German technology and manufacturing holding with about 13,000 employees across 100 locations that supplies industrial and pharmaceutical customers worldwide.

Gaetje began his career in the mid-1990s in the computer business as email and the internet became central to enterprises. He moved from consulting into the finance sector and worked as an auditor in insurance, focusing on how IT and business processes connect.

He moved into information security as the role shifted from compliance to a direct business threat in the 2010s. Large incidents such as WannaCry and NotPetya changed priorities across industry. By 2018 he led security at Körber IT Solutions and in 2019 took on the group-wide CISO role at Körber AG.

Gaetje described leadership as a learned skill rather than an innate trait. “A leader is someone who provides direction to others, or a vision of what and how something can be achieved,” he said, and he emphasized reliability and trust as necessary qualities.

Recruiting and team development are central to his work. He highlighted an estimated global cybersecurity skills shortfall of between 2.8 million and 4.8 million in 2025. He looks for curiosity and a willingness to learn in candidates. “I need people who want to learn,” he said, adding that he favors candidates who can think beyond scripts and pursue deeper understanding of incidents.

On hiring people with hacking experience, he draws a clear ethical line. He would consider employing white-hat hackers for their curiosity and problem-solving, but he excludes individuals with a history of malicious activity.

Gaetje identified the fast pace of new technologies as a primary concern. He pointed to artificial intelligence as a dual-use tool adopted by both attackers and defenders, and warned that new capabilities can appear faster than security teams can evaluate them. He also raised risks from unapproved AI deployments within businesses, sometimes called shadow AI, which can expose sensitive data and products to unexpected risk.

He expects the CISO role to grow in importance even as tools change. Protecting AI-driven products and services will require collaboration across teams, including product developers and software engineers, rather than relying solely on the security organization.

Gaetje discussed workforce effects of AI tools: coding assistants and automated triage could shift the skills needed for programmers and analysts toward architecture and prompt design. He cautioned that over-reliance on automation might reduce opportunities for junior staff to learn deeper analysis skills needed to spot subtle consequences in incidents.

On career planning, he advised moving across companies and sectors to broaden perspective. He left insurance for manufacturing and machine building to learn different risk profiles and attack patterns. He noted Körber’s work with companies that supply consumer sectors, including equipment used in vaccine production.

Articles by this author