

– The core of cybersecurity is establishing resilience. Few people notice this work, but it is critical to preventing things from going wrong, says Lien.
As part of Sicra's 10th anniversary, we interviewed our CEO, Gaute Lien, about what it takes to build digital resilience against increasingly complex cyber threats. Lien has worked in cybersecurity for almost three decades and has developed several unique frameworks related to security.
When people talk about cybersecurity, they usually focus on three areas:
Lien highlights an underlying area that he believes deserves just as much attention: How to build digital resilience into organizations. Especially when companies launch transformation programs or major IT projects, they often lack sufficiently structured security governance.
Since its founding in 2016, Sicra has delivered tailored technology and cybersecurity services designed to make organizations resilient in an increasingly complex and unpredictable digital world. Sicra's approach to security is rooted in Sicra's security triangle, a model that combines security management, deep technical expertise, and continuous monitoring. This helps secure organizations across their entire technology platform.
After 10 years as a technology and IT security company, Sicra has developed a deep understanding of what actually makes organizations secure. This also includes the costs faced by organizations affected by cybercrime, both financial and intangible, such as reputational damage. Security also has an upside through increased trust in technology and greater user adoption.
– There is a lot to gain on the technology side, but when things fail, the reason is often a lack of security management or insufficient governance of security activities. That is why we are investing more in our dedicated security management practice, says Lien.
– A lack of security management is also the main reason major transformation programs and IT projects fail or are stopped. I could list 12 to 15 major modernization projects that have been halted or significantly delayed because critical shortcomings were identified in areas such as privacy, GDPR, patient data, or the use of cloud services. The cause is a lack of operating models and governance related to security management, he continues.
The paradox is striking: Security typically accounts for 10–20% of the budget in major projects, yet there are hardly any governance frameworks for this part of the budget. Even Digdir's Project Wizard is unclear and incomplete in parts of this area.
Lien uses a fitting analogy: A construction site has far stricter safety requirements than the finished building: Restricted areas, access control, protective equipment, and secured elevator shafts. The same principle should apply to IT projects.
– The security foundation has to be built into a project as it progresses. Without experienced security professionals involved throughout the process, you lose critical expertise and overlook digital weaknesses. Basic penetration testing is not enough. Failed projects result in billions in wasted spending and CIOs losing their jobs, says Lien.
The consequences are not only financial. Security shortcomings are often used politically to obstruct transformation projects. And when users lose trust in digital solutions, whether public or commercial, they stop using them. Security therefore directly affects a project's ROI or an organization's top line through user adoption.
Lien quotes the French philosopher Paul Virilio, who said: "When you invent the ship, you also invent the shipwreck; when you invent electricity, you invent electrocution. Every technology carries its own negativity, which is invented at the same time as technical progress."
– This does not mean that you should avoid adopting new technology, but that you need to rethink security. If you build a boat but are used to building cars, seat belts and bumper guards will not stop the boat from sinking. A boat needs different security mechanisms. The same applies to new technology, Lien emphasizes.
This applies to IT/OT convergence, where machines and control systems are connected to IT networks. It applies to millions of customer identities, which require a fundamentally different approach from employee identities. And it applies to identities for the rapidly growing number of Agentic AI systems, which Lien believes must be subject to the same security principles as human actors, including background checks, authorization, and behavioral monitoring.
– AI is trained to please you. That does not necessarily make it reliable. AI agents also need a four-eyes principle, he says.
Sicra's strength lies in combining several perspectives at the same time: Technical experts who understand solutions from the inside, together with experience from some of the most demanding security incidents.
Sicra has security management as a dedicated area of expertise: Across network security, OT security, application security, and Microsoft solutions. This means integrating security expertise directly into program and project management as well as executive management.
– Conducting one risk assessment and one data protection impact assessment and calling it security governance is not enough. You need both security architecture and ownership of the development or integration of critical security capabilities throughout the entire process, Lien explains.
Strong security management creates predictability in terms of time, cost, and quality, while preventing security-related problems from returning like a boomerang in the final stages of a project. Strong security management is also necessary to build resilience and digital robustness. This helps ensure that the value the project is intended to create is actually realized. In addition, the resulting digital resilience delivers real value to the organization.



.jpg?width=292&height=365&name=Sicra_office_3076%20(1).jpg)