Notes from someone who ran security for a living, what the job actually teaches you, written plainly.
I’m Andrey Gubarev. For 17+ years I led security as a CISO across EU fintech and other regulated industries: ICT risk, outsourcing oversight, evidence, and the part most people underestimate: getting a board to actually decide.
fromCISO is the broad version of that experience. Not a DORA blog, not company marketing, one practitioner thinking out loud: how security functions get built and led, how risk is judged (not just complied with), how careers in this role really go, and what incidents quietly reveal about an organisation.
Why subscribe: one or two essays a month, in the first person, from someone who has made these calls under real pressure, not a vendor, not a framework summary. If that’s the kind of signal you want in your inbox, subscribe.
I run an independent advisory practice, CyAdviso, focused on DORA and ICT risk for EU-licensed fintechs. If that’s relevant to you, you’ll find it at cyadviso.com, but that’s not what this newsletter is for.


