The CISO Who Started With Economics, Not Code

Andreas Gaetje runs cybersecurity for a 13,000-person German manufacturing giant. He has never been, in his own words, 'a deep bit-crawler'. That turns out to be beside the point.

ThreatVectr Newsdesk· 3 min read
A sleek, modern corporate security operations room photographed from a low angle looking toward a large curved desk with multiple dark monitors displaying abstr
Share

Key points

  • Körber AG, a German technology and manufacturing group with around 13,000 employees across 100 locations worldwide, employs Andreas Gaetje as its chief information security officer (CISO, the executive responsible for protecting a company's digital systems).
  • Gaetje began his career in the mid-1990s drawn by economics and business politics, not computers, joining a consulting firm before moving into the finance sector.
  • The global shortage of trained cybersecurity workers was estimated at between 2.8 million and 4.8 million people in 2025.
  • Gaetje's single non-negotiable hiring requirement is a genuine desire to keep learning, ranked above formal qualifications or years of experience.
  • He draws a firm line between ethical hackers, who probe systems with permission to find weaknesses, and criminal hackers: the first group he would hire, the second he would not.

Körber AG makes the industrial machines that sit behind products most people never think about. Andreas Gaetje, Körber's chief information security officer, puts it simply: probably every vaccine you have ever had passed through one of the company's machines. Körber supplies the suppliers. Nobody outside the industry knows the name, which is common for the companies that quietly hold a lot of critical infrastructure together.

Gaetje's route to the top of cybersecurity at a company like that is, as reported by SecurityWeek, genuinely unusual. He did not start with a computer obsession. He started with economics.

How does someone end up running cybersecurity without a technical background?

Practice, mostly. Gaetje entered the workforce in the mid-1990s, when email was replacing the fax machine as the default way businesses communicated. He needed a job. He spotted that information technology was becoming the engine of commerce, and looked for a role where business thinking and IT could overlap. A consulting firm gave him that, and then an insurance company gave him something more valuable: a seat in the audit department, where he learned how organisations actually function and where they break.

At the time, information security (protecting a company's data and systems from attack or misuse) was mostly a compliance exercise. Think boxes to tick on a regulator's checklist. That changed fast.

The 2010s brought WannaCry and NotPetya, two global cyberattacks, in which malicious software (programs written to cause damage) spread across entire corporate networks and caused billions of dollars in losses. Suddenly security was not a compliance question. It was a survival question. Gaetje was already positioned to bridge the gap between business leadership and the security team. By 2018 he was CISO at Körber IT Solutions. By 2019 he held the same title at the parent group.

The failure mode for most security programmes is the one Gaetje's career accidentally avoided: a security leader who speaks only to engineers and not to the board. Business literacy is not a nice-to-have.

The best career advice he received was blunt: do not stay too long in one company or one sector. Different industries carry different risk profiles. A mind stuck in one environment stops adapting, and attackers adapt constantly.

On hiring, he is equally direct. The global cybersecurity talent shortage is real, and the wish list of skills rarely matches the available candidates. His solution is to treat curiosity as a hard requirement, not a soft trait. Experience is welcome. Enthusiasm to learn is mandatory.

For ordinary people, the takeaway from a company like Körber is indirect but real. The machines that make medicines, package food, and process goods across global supply chains all depend on security teams like his keeping criminals out.

One operational takeaway: breadth of experience beats depth in a single silo, for security leaders and for the programmes they build.

© 2026 Threat Vectr