Sicra Header Logo
  • Careers
  • About us
  • People
EnglishNorsk
Talk to us
  1. Home
  2. Team
  3. Lars Reidar Vold-Andersen
<span id="hs_cos_wrapper_name" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="text" >Lars Reidar Vold-Andersen</span>

Lars Reidar Vold-Andersen

Head of IT GRC and Security Management

For Lars Reidar Vold-Andersen, effective security management is about ensuring that technology, risk and business governance all pull in the same direction. At Sicra, he draws on his broad experience to bridge the gap between management and technical security.

Lars Reidar Vold-Andersen leads Sicra’s focus on IT GRC and security management. He has more than 20 years of experience at the intersection of technology, risk, governance and business management, and has worked across areas ranging from strategic risk assessments and management systems to establishing GRC functions, implementing GRC technology, IT audits and the practical implementation of security measures.

Before joining Sicra, Lars Reidar was Head of Modern GRC and CEO of Solidify Norway. He founded Transcendent Group Norway in 2013 and built up the Norwegian business before moving into international leadership roles and ultimately becoming Group CEO of Transcendent Group. Earlier in his career, he also worked with IT GRC at PwC.

At Sicra, Lars Reidar will build a leading professional environment within security management and IT GRC, while helping to connect business governance more closely with Sicra’s technical expertise in areas such as cybersecurity, OT, identity, networking and Security Operations.

What made you want to join Sicra?

What motivated me most was the opportunity to build a leading environment within security management and IT GRC, closely integrated with some of Norway’s most skilled experts in technical cybersecurity and OT security.

Many organizations want a single partner that both understands business governance and can translate strategic decisions into practical security measures. I believe Sicra is uniquely positioned to deliver that combination.

What is the ambition for the security management and IT GRC practice?

The ambition is to build a professional environment that helps organizations turn security into a strategic competitive advantage and an integral part of business governance.

This means that security should not be the responsibility of the IT or security department alone. It needs to be connected all the way from the board and executive management through to risk management, IT, OT, architecture, projects and development teams.

We will help our customers translate strategy, risk and regulatory requirements into priorities and measures that actually reduce risk.

Why is it so important to bridge the gap between management and technical security?

Because there is still a gap in many organizations. Boards and executive management have been given clearer responsibility for cyber risk, while security itself quickly becomes highly technical.

Management does not need to know how to configure a firewall or analyze a security incident. But it does need to understand the risks the organization faces, the potential consequences and the priorities that need to be set.

At the same time, security teams need to understand the organization’s objectives and operating conditions. Good security management is achieved when these perspectives come together.

With an increasing number of regulatory requirements, is there a risk that organizations become more focused on compliance than on actual security?

Absolutely. Threat actors do not care whether an organization complies with regulations. They exploit weaknesses in its actual security.

That is why effective security management needs to be about more than documentation and reporting. It is about understanding risk, prioritizing the right measures and making sure they are actually implemented.

When governance, management and technical security work together, the organization becomes both more secure and better equipped to document its security efforts to customers, owners and authorities.

What do NIS2, DORA and the AI Act mean for the management of Norwegian organizations?

First and foremost, they mean that security and technology risk become an even clearer management responsibility. The requirements affect, among other things, how organizations approach governance, risk assessments, suppliers, documentation and follow up.

However, I believe it is important not to start with the regulations and stop there. The goal should be to build an organization that is genuinely resilient. When this is done properly, compliance becomes, to a greater extent, a result of effective security work.

What characterizes effective security management?

Effective security management enables better decision making.

It is about understanding which assets the organization depends on, which threats and vulnerabilities are relevant, and where it makes sense to invest time and money. This then needs to be translated into concrete measures, with proper follow up to ensure they have the intended effect.

GRC has little value if it ends up as documentation in a spreadsheet that no one uses. It needs to be connected to how the organization is actually governed and developed.

You have worked with GRC for many years. How has the field evolved?

GRC has traditionally involved a great deal of manual work, documentation and cumbersome processes. We are now seeing far greater opportunities to use technology, automation and AI to make this work more dynamic and efficient.

I find it particularly interesting how we can integrate security and compliance more closely into existing workflows and technology platforms. The goal should be less administration and better decision support, not more bureaucracy.

GRC has also evolved from being a relatively inward looking or standalone support function into a much more integrated part of an organization’s governance, priorities and core activities.

You have both a technical background and extensive leadership experience. What does that combination mean in practice?

It means that I am very comfortable working at the intersection of technology, processes, people and business governance.

I think that is valuable because security challenges are rarely either technical or business related. They are interconnected. To provide good advice to executive management, you need to understand both sides and be able to translate between them.

You previously built up Transcendent Group in Norway. What do you take with you from that experience?

I have learned a great deal about building professional environments and culture. Knowledge based businesses are first and foremost about people.

I want to build an environment where talented people can develop, learn from one another and help shape how we work. The best security environments are not created through technology and methodology alone, but through people who thrive, challenge one another and succeed as a team.

What characterizes a strong professional environment for security management?

Professional expertise is, of course, fundamental, but it is not enough. We need people who are curious, who share knowledge and who are able to collaborate across disciplines.

One of the most exciting things about Sicra is precisely this breadth of expertise. Security management professionals can work closely with specialists in areas such as SOC, networking, identity and OT. This means that strategic recommendations can be connected directly to the customer’s technical reality.

What do you want customers to experience when they work with Sicra?

That we understand both the boardroom and the technology.

We should be able to discuss cyber risk and regulatory requirements with management, while also having the technical expertise to help the customer implement the necessary measures in practice.

For me, that is where the real value lies. We should not just tell customers what they should do. We should be able to help them get it done.

Stay updated
Receive the latest news

Links
SustainabilityFAQPartnersCertifications and awardsCareerPress & brand
Contact
Tel: +47 648 08 488
E-mail: firmapost@sicra.no

Drammensveien 151, 0277 Oslo

Follow us on Instagram

Follow us on LinkedIn
Certifications
iso27001-white
ISO 27001 compliance
miljofyrtarnlogo-hvit-rgb
Eco-Lighthouse
iso9001-white-removebg-preview
ISO 9001 compliance
Sicra Footer Logo
Sicra © 2025
Privacy Policy