For decades, Europe has talked about digital sovereignty and cyber resilience. But talking isn’t building.
And according to Petri Kuivala — a veteran CISO who helped secure Nokia, Microsoft, and NXP, and now advises European cybersecurity startups including HoxHunt — the problem isn’t just political. It’s cultural, strategic, and deeply rooted in how European CISOs approach security itself.
In this episode of Scaling Cyber, Petri doesn’t hold back. He challenges the regulation-first mindset that dominates European cybersecurity, explains why most CISOs drown in noise instead of focusing on real risk, and lays out exactly what Europe needs to do if it wants to stop being a follower in the digital age.
Petri’s career spans three decades and some of the biggest technology companies in the world. But about 10 years ago, he made a deliberate shift: instead of just defending organizations, he started helping European cybersecurity startups scale.
The reason? Simple: “If I stay still, I will become an old fart, and I don’t want to be one.”
That shift gave him a unique vantage point. He’s seen what works at enterprise scale. He’s watched 20+ European startups try to grow — some succeeding, most failing. And he’s identified the patterns that separate winners from those that never make it.
One of those patterns? Diverse founding teams with honest, challenging conversations about strategy and vision. Solo founders can be Steve Jobs for a while, but very few can sustain that for long.
Another? Access to market… and CISOs willing to work with startups. Without that early validation and support, even the best technology stays lonely in its corner.
Europe loves to talk about cyber sovereignty. But Petri sees a uncomfortable gap between rhetoric and reality:
“We are not willing to seek the real European solutions and believe in them. Every time we use a US-based solution, we build competence in some other country or region.”
Europe remains industrially focused while the US leads in digital innovation. That structural difference shapes everything—including how CISOs are perceived. In digitally-driven companies, security is central. In industrial companies, it’s often an afterthought.
But the bigger issue? European CISOs are afraid to work with European startups. They see vendors as upselling machines, not partners. That distrust kills the innovation pipeline before it even starts.
Petri’s call to action is clear: CISOs need to give European startups a seat at the table. Not because they’re European, but because competition drives quality—and Europe won’t build world-class cybersecurity vendors without access to European customers.
If there’s one theme that runs through Petri’s entire career, it’s this: Most CISOs are drowning because they’re trying to do everything at once.
He’s seen it everywhere: CISOs overwhelmed by alerts, stakeholders pulling them in a hundred directions, and security teams spread so thin they can’t execute on anything meaningful.
His solution? Prioritize ruthlessly. Focus on the red corner — the highest-impact, highest-risk area — and stay there until it’s nearly perfect. Then move downstream.
“I needed to bring the COO and CTO into the room and have the conversation: which one of you will be the priority? Because I cannot serve both of you at the same time.”
That level of clarity is rare. But it’s also what separates effective security leaders from those who burn out trying to please everyone.
Process and execution matter more than tools. And the ability to say “no” until you’re ready is a superpower.
One of the most underestimated security capabilities? Your own employees.
Petri makes a compelling case: if 60% of a 60,000-person organization actively reports suspicious activity, you can detect intrusion attempts in less than two minutes, with high accuracy.
But most CISOs don’t believe it’s possible. They’re technology-driven, not psychology-driven. They underestimate the power of positive reinforcement and gamification.
At HoxHunt, Petri has seen this play out firsthand. When you treat security awareness as a behavioral challenge - not a compliance checkbox - people engage. They become an active defense layer.
“If you’re capable of taking 20% out of your breach likelihood, that is a huge thing.”
It’s not a silver bullet. But it’s a massively underutilized capability sitting right in front of most organizations.
🔹 Strategy means saying no. Focus on high-impact areas and stay there until you’ve truly addressed the risk. Spreading thin kills execution.
🔹 Regulation-first security makes you an obstacle, not a partner. Lead with business risk, not compliance checklists.
🔹 Europe won’t build cyber sovereignty by talking about it. CISOs must actively support European startups—not because they’re local, but because competition drives quality.
🔹 Crowdsourced intelligence is a 20% advantage most ignore. Engage employees with positive psychology, and they become your fastest threat detection layer.
🔹 Winning startups have diverse teams with honest, challenging conversations. Solo founders rarely sustain long-term success.
🔹 CISOs can make or break startups. When CISOs open doors for each other, European vendors finally get access to the market they need to scale.
Petri Kuivala is a veteran CISO with 30 years of experience defending global organizations including Nokia, Microsoft, and NXP. For the past decade, he has been advising European cybersecurity startups, helping them navigate go-to-market challenges and scale globally. He currently serves as CISO Advisor at HoxHunt, a leading security awareness platform.
Scaling Cyber brings you authentic stories from cybersecurity founders and leaders building global companies outside the US and Israel. Hosted by Ignacio Sbampato—cybersecurity executive, former Chief Business Officer at ESET, and founder of BridgerWise—the show explores tactical growth lessons, strategic insights, and the real challenges of scaling in cybersecurity.
Subscribe: Substack | Spotify | Apple Podcasts | YouTube

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.