Ontinue’s CISO Gareth Lindahl-Wise on Why Security Must Enable Speed

Across cloud, AI, and hybrid environments, complexity is increasing rapidly. At the same time, CIOs are expected to deliver speed, resilience, and scalable digital operations.
That changes the role of Security Operations fundamentally.
For Gareth Lindahl-Wise, CISO at Ontinue, modern SecOps is no longer just a technical control function. It is a business capability designed to reduce uncertainty, support decision-making, and create confidence across the organization.
The goal is not to overwhelm leadership teams with alerts, dashboards, or vulnerability counts. CIOs need clarity around which risks could materially impact operations, growth, or regulatory obligations — and they need governance models that allow teams to move faster without losing control.
As a recurring partner of the Confare CIOSUMMITs, Ontinue continues to contribute practical perspectives on modern cybersecurity operations, governance, and resilience. CIOs and IT decision-makers attending the Confare CIOSUMMITs regularly have the opportunity to experience the company’s experts live on stage and discuss the operational realities behind modern SecOps strategies.
In the interview, Gareth Lindahl-Wise explains:
- why the best security operations are often “invisible” in day-to-day business,
- how mature SecOps enables speed through governance and automation,
- why continuous compliance is replacing periodic audit preparation,
- and what CIOs should expect from a trusted security partner today.
What should a CIO expect from a modern Security Operations capability?
A CIO isn’t looking for a check box exercise that security controls exist, they’re looking for confidence the controls are effective and that risk won’t become a blocker to growth. At its best, Security Operations (SecOps) is a business capability that quietly and consistently reduces uncertainty. It allows leaders to focus on integrating acquisitions, launching platforms, improving reliability, or entering new markets without constantly wondering what risks might be lurking beneath the surface.
When SecOps does its job well, it doesn’t demand attention. It creates confidence.
What does it mean for security to speak “business,” not just technology?
Speaking business means translating technical findings into material risks. CIOs don’t need to hear that there are 1,500 vulnerabilities or thousands of alerts, they need to understand which risks could realistically disrupt revenue, operations, or regulatory obligations.
Effective Security Operations narrows the conversation. Instead of overwhelming leaders with activity, it surfaces a small number of decision‑relevant points related to risks and explains why they matter. That shift – from volume to insight – is what turns security reporting into something executives can actually use.
Subscribe to the Confare conText newsletter for exclusive IT & Security insights.
CIOs often say the best security is “invisible.” What does that actually look like?
“Invisible” doesn’t mean absent, it means governed and embedded. CIOs value security that is designed into everyday operations through clear decision rights, guardrails, and accountability, rather than introduced after the fact through escalations and exceptions.
When Security Operations operates with strong governance, decisions happen earlier and more predictably. Risk thresholds are understood, escalation paths are defined, response authority is clear and teams know when the system can act autonomously versus when human judgment is required. That governance allows security to fade into the background during normal operations, while still ensuring oversight, auditability, and accountability when it matters. Security becomes part of how the organization runs, not a separate function that surfaces only when something breaks.
How should SecOps enable speed without increasing risk?
Speed comes from confidence, not from bypassing controls. When guardrails are clear, what decisions can be automated, what requires human judgment, and what risk is acceptable – teams can deploy faster without hesitation. A mature SecOps capability provides those guardrails, allowing CIOs to move quickly while knowing that risk is being actively governed, not ignored.
What does ‘scaling security without scaling headcount’ really mean?
At some point, hiring more people stops being a viable strategy. CIOs need security operations that scale through better focus, decision‑making, automation, and orchestration, not linear growth in people. The goal isn’t fewer humans, but smarter use of human expertise, where automation handles routine decisions and people focus on judgment, oversight, and accountability. That’s how SecOps keeps pace with the business as it grows.
From a CIO’s point of view, Security Operations isn’t a collection of tools, it’s a business capability. When done well, it enables informed risk decisions, supports faster execution, and scales sustainably alongside the organization.
Mastered NIS2, DORA, or continuous compliance? Don’t keep your success invisible. Inspire the community and submit your project for the Confare LivinIT Trophy.
How do regulations like NIS2 and DORAchange what CIOs should expect from Security Operations?
Regulations such as NIS2 and DORA reinforce something many CIOs already understand, which is that compliance is no longer a periodic exercise, it’s an ongoing operational requirement. CIOs aren’t looking for Security Operations that simply produce evidence at audit time; they need capabilities that demonstrate continuous risk management, clear decision ownership, and traceability as part of everyday operations.
Effective Security Operations support compliance by making governance explicit, defining who can make which decisions, what controls are enforced automatically, and how incidents, risks, and responses are documented over time. When security is governed this way, compliance becomes a byproduct of how the organization operates, rather than a parallel process that slows the business down or surfaces only when regulators come knocking.
How should CIOs think about audit readiness without slowing the business down?
CIOs need continuous compliance – where the audit isn’t the trigger to check that everything is working OK.
That means security decisions, incidents, and risk treatments are continuously documented, governed, and traceable as work happens, not reconstructed later.
When Security Operations are designed this way, audits become verification exercises instead of fire drills. CIOs gain confidence that they can explain what happened, who decided what, and why – without pulling teams off their day‑to‑day responsibilities or slowing the business to prepare evidence. Effective SecOps teams are automating compliance processes and evidence gathering – a key step to enabling continuous compliance and control confidence.
How does a CIO know when a security partner can be trusted?
Trust isn’t about outsourcing responsibility, it’s about retaining control while extending capability. The right security partner like Ontinue operates transparently, aligns to the organization’s governance model, and makes decisions within clearly defined boundaries rather than acting as a black box.
When decision rights, escalation paths, and accountability are explicit, CIOs can trust that security outcomes remain consistent, even as operations scale. That trust allows leaders to depend on a partner without losing visibility, ownership, or confidence in how risk is managed. With those outcomes secured, the CIO can then focus on helping grow the business.


