Marcel Lehner
Chief Security Officer (CSO), Head of Group Security, Wiener Stadtwerke GmbH

Marcel Lehner is Chief Security Officer and Head of Group Security at Wiener Stadtwerke, one of Austria’s largest infrastructure groups, spanning energy, mobility, and municipal services for the city of Vienna. He leads physical and digital security across critical infrastructure, overseeing NIS2 compliance, a 24/7 Security Operations Center, business continuity, and crisis management. Before joining Wiener Stadtwerke in 2024, he spent a decade building Group Security from the ground up at an international manufacturing company. He holds a BSc and an MSc in Security from the University of Hagenberg and an MBA in General Management from University of Warwick, alongside numerous international certifications, including CGEIT, CRISC, CISM, CISSP-ISSMP, AAISM,CISA, GICSP, CSSLP, CCSP, CBCP and CDPSE. His guiding principle: security as a driver of innovation, not a brake on it.

Recently, in an exclusive interview with CIO Magazine, Marcel shared insights from his journey building Group Security from the ground up across industrial and critical infrastructure environments, and now leading physical and digital security for Wiener Stadtwerke, protecting essential services for 2 million people in Vienna. On AI, Marcel sees it as one of the biggest levers for defensive security, both a threat to manage and a tool to scale detection and response. His advice to the next generation is treat security as a quiet responsibility, build people not just controls, and focus on resilience, because when you do this work well, a city simply gets to live its day uninterrupted. The following excerpts are taken from the interview.

Hi Marcel. What was the pivotal moment or early career choice that first drew you into the world of cybersecurity and critical infrastructure?

Honestly, the fascination started when I was a kid. I got my first computer at eight, and by twelve I’d programmed my first virus, loosely a piece of ransomware, though I wouldn’t have called it that then. The internet was only just arriving, and the hacker films of that era had me completely hooked. What really got to me was realizing what you could actually do from that side of a keyboard back then; that alone told me this was the field I wanted to spend my life in. So I crossed over to the good side and committed myself to protecting IT systems instead of poking holes in them.

What turned that early instinct into a real career was the years I spent working across different industrial and corporate environments, where the same thing kept showing up: the systems keeping a factory running or a network alive were far more fragile than anyone wanted to admit. I noticed the gap between how much we depended on these systems and how little serious attention their security got.

The path to my CISO role opened in 2013 at an international industrial group running more than 70 sites around the world, from Chile to Vietnam. I was handed a blank page and asked to build Group Security from nothing: no SOC, no ISMS, no business continuity plan, none of it. Most people would see that as a burden. I saw it as the rare chance to design something the way it should be designed rather than patching over decisions someone else made a decade earlier. That’s when security stopped being a job for me and became a craft. Building an ISO 27001 program, a Security Operations Center, and a crisis capability from scratch taught me that security isn’t a control you bolt on at the end. It’s a design decision you make at the very beginning, or you pay for it later at a much worse price. Fairly early on I also pulled physical security into my remit, and that’s how I stepped into the CSO role and started treating security as one connected whole rather than a set of separate boxes.

Critical infrastructure came into focus once I understood the stakes properly. When you secure a bank, you protect money. When you secure a paper mill or, now, an energy and mobility group like Wiener Stadtwerke, you protect whether a city keeps its lights on, its trains moving, and its power flowing. That responsibility is what kept me here.

Securing infrastructure means making decisions with real-world consequences. What part of your role today gives you the strongest sense of purpose?

Two million people in Vienna rely on the services my colleagues and I help protect, most of them without ever knowing our team exists. That anonymity is the point. Nobody thinks about the security behind their tram ride or their heating until it fails, and my job is to make sure that day never comes.

The strongest sense of purpose comes from the human side, not the technical one. I lead a central team of around 20 people, and for a dozen security officers across the group, I set the strategic cornerstones they work from. Watching someone on that team grow into a decision they wouldn’t have trusted themselves to make two years ago gives me more satisfaction than any firewall rule ever could. Security is a team sport. My mantra, which my colleagues are probably tired of hearing by now, is “Gemeinsam in eine sichere Zukunft” – together into a secure future. I mean it literally. No single person defends a group this size. You build a culture where a thousand people make slightly better decisions every day, and that compounds into resilience.

The other part is sitting at board level and being able to frame security as something other than a cost or a brake. When I can show the executive board that a security decision opened a door commercially instead of closing one, that’s the day the whole discipline earns its seat at the table. And there are really two things I’m arguing for at once: security as a genuine competitive advantage, and security as the guarantee that Vienna’s supply holds, that the power stays on and the trams keep running for two million people. When the board sees both at the same time, security stops being a line item and becomes strategy.

Critical infrastructure is becoming digital by default, not by exception. Where do you see the line between IT, OT, and physical operations blurring most dramatically in the next five years?

The line is already gone in practice; we just haven’t finished admitting it organizationally. The old comfort of an air gap between the operational technology running a substation and the corporate IT network was mostly a story we told ourselves. Remote maintenance, predictive analytics, and cloud-connected sensors erased it years ago.

Where it gets sharp over the next five years is in the convergence of physical and cyber into a single attack surface. Someone who compromises a building management system can unlock a door. Someone who unlocks a door can walk to a terminal that controls something operational. The attacker doesn’t respect the org chart that separates my physical security colleagues from my SOC analysts, so we can’t afford to respect it either. At Wiener Stadtwerke I deliberately sit across both physical and digital security for exactly this reason. Splitting them made sense when they were separate problems. They stopped being separate problems.

The second blur is identity. In a converged world the most valuable thing isn’t a network boundary, because that boundary barely exists anymore. It’s knowing, with certainty, who or what is allowed to do a specific thing to a specific asset at a specific moment, whether that actor is a human engineer, a contractor’s laptop, or a machine talking to another machine. Identity becomes the real perimeter, and most organizations are nowhere near ready for how much rigor that demands.

Supply chain risk now extends to software, hardware, and human dependencies. What emerging supply chain vulnerability worries you most for essential services?

Concentration risk in the layers nobody can see. Everyone learned the word “software bill of materials” after the incidents of the past few years, and that’s genuine progress. But my real concern sits underneath that: the handful of components, libraries, and service providers that half the world quietly depends on without knowing it. When a single widely-embedded library has a flaw, the blast radius isn’t one company. It’s every essential service that unknowingly built on top of it. There’s a second layer that worries me more each year: how much of the software running essential services now comes from a small set of very large, mostly non-European vendors. When a city’s core systems sit on platforms we neither control nor could swap out quickly, that stops being a procurement question and becomes one of digital sovereignty. Keeping Vienna running shouldn’t hinge on the goodwill or the product roadmap of a company on another continent, and winning back real options there is one of the harder problems in front of us.

Hardware worries me more than software, because you can patch software. You cannot patch a chip with a design weakness baked in at the foundry, and the semiconductor supply chain for critical systems runs through a geography and a set of vendors that’s alarmingly narrow. If geopolitics tightens around that chokepoint, security becomes the least of anyone’s problems, and it becomes everyone’s problem at once.

The dependency people talk about least is the human one. So much specialized knowledge about how a specific piece of operational technology actually works lives in the heads of a shrinking number of ageing engineers and a couple of vendor firms. When those people retire and that knowledge isn’t captured, you inherit a system you can no longer fully understand, let alone defend. That’s a supply chain vulnerability too, and it doesn’t show up on any bill of materials.

The workforce gap in cyber-physical security is widening. What skill or role will be most scarce and most critical in securing infrastructure by 2030?

The translator. By 2030 the scarcest and most valuable person won’t be the deepest technical specialist, though we’ll still badly need those. It’ll be the person who can stand in a room with an OT engineer who’s spent thirty years around turbines, a cloud security architect, and a board member who controls the budget, and make all three understand each other well enough to make one good decision together.

We’ve overproduced narrow specialists and underproduced people who can span domains. The genuinely hard problems in critical infrastructure now sit precisely in the seams: between IT and OT, between the technical reality and the business consequence, between the regulation and the operational truth on the ground. NIS2 is a good example. It’s not solved by a firewall, it’s solved by someone who understands the legal obligation, the engineering constraint, and the executive’s risk appetite simultaneously.

The role I’d fight hardest to hire is what I’d call a resilience engineer: someone who assumes the breach will happen and designs the system to keep the tram running and the grid stable anyway. Prevention will always matter, but a mature program spends at least as much energy on the question of how gracefully things fail. The people who can architect for graceful failure across cyber and physical systems at once are rare today. In four years they’ll be the ones everyone’s chasing.

Leaders are sustained by what they read and learn outside the office. What book, fiction or non-fiction, has influenced how you think about responsibility, and why does it stay with you?

Viktor Frankl’s Man’s Search for Meaning. It’s an unusual answer for a security executive, and it has nothing to do with technology, which is exactly why it stays with me. Frankl, an Austrian like me, wrote about surviving the concentration camps and arrived at a conclusion that reshaped how I think about my job: you don’t get to choose what happens to you, but you always keep the freedom to choose your response, and that response is where your real responsibility lives.

In security we spend enormous energy trying to control what happens. Frankl’s insight is that control is mostly an illusion; the incident, the breach, the crisis will eventually arrive no matter how good you are. What defines you as a leader is the response you’re capable of when it does. That reframing pulled me away from a prevention-obsessed mindset and toward resilience and crisis leadership, which is where I’ve focused for years now.

It stays with me for a harder reason too. Responsibility isn’t the same thing as blame. When something goes wrong on my watch, the useful question is never who to point at. It’s what we do next, and whether the people around me are steady enough to do it well. Frankl taught me that responsibility is forward-looking or it’s worthless.

Music, art, or sport can teach lessons that boardrooms cannot. What non-technical discipline inspires your approach to problem-solving under pressure?

Endurance sport, and I’ll be honest about why: it’s the closest civilian analogue I’ve found to managing a security crisis. When you’re deep into something long and physically hard and your body is telling you to stop, you learn that panic is a decision and pacing is a skill. Those are the two things that separate a manageable incident from a catastrophic one.

I follow a plant-based lifestyle and pay real attention to physical and mental conditioning, and that isn’t a side hobby I keep away from work. A crisis at 3am doesn’t care how brilliant your architecture is if the person running the response is exhausted, reactive, and burning through adrenaline. Composure under load is a physical capability before it’s a leadership one. You can’t fake calm to a team that’s watching you for cues.

My second passion is photography, and it’s the artistic counterweight to the rest of what I do. Security work is loud and relentlessly analytical; photography is slow and quiet, and it asks for a kind of attention nothing else in my week does. You wait and watch until you catch the one detail in a scene that everyone else walked straight past. That habit of really looking carries back into the job, because most security failures hide exactly there, in the detail no one thought worth a second glance. Stepping out of the analytical headspace into something purely visual is also how I refill the tank, so there’s something left to draw on when the pressure comes.

What is your biggest goal? Where do you see yourself in 5 years from now?

I want to be part of moving the whole conversation around critical infrastructure security from reactive to genuinely resilient, and not just inside my own group. Vienna is a serious testbed. If we can prove that an energy, mobility, and municipal services group can be both highly secure and highly innovative at the same time, without security becoming the department that says no, that’s a model worth sharing well beyond one city.

Personally, I spend a lot of my own time on artificial intelligence, and I’m convinced it’s one of the biggest levers we’ll have for security over the next few years: partly as a threat we’ll have to defend against, but mostly for the defensive work it can genuinely do for us once we learn to use it well. I’m also investing more energy into writing and speaking publicly about this field, because the shortage of clear, honest voices on infrastructure security is part of why the workforce gap exists in the first place.

Five years out, I’d like to be doing more of the work that outlasts any single role: shaping how the next generation thinks about this discipline, contributing to European frameworks rather than only implementing them, and hopefully having built a security culture at Wiener Stadtwerke robust enough that it holds up fine whether I’m the one running it or not. The measure of a good security leader is what survives their absence.

If you could leave one message for the next generation of defenders of essential services, what would you tell them about the responsibility and privilege of this work?

You’ve chosen a strange and quiet kind of work: the better you do it, the less anyone notices you did anything at all. There are no headlines for the attack that didn’t happen, no applause for the outage the public never experienced. If you need recognition to feel motivated, this isn’t your field. The reward is knowing that a city you may never fully see went about its ordinary day because you and your colleagues did something extraordinary in the background.

Hold onto the weight of it. When you secure essential services you’re not protecting data or systems in the abstract; you’re protecting the hospital that needs power, the family that needs heat in January, the person who needs the train to get to work. Never let it shrink into a purely technical exercise, because the moment it does, you start making decisions that are technically correct and humanly wrong.

And build people, not just controls. The tools you learn today will be obsolete faster than you expect, but the judgment, the composure, and the culture you help create will outlast every one of them. Take the responsibility seriously and hold the privilege lightly. Defending the things a society quietly depends on is one of the few jobs where doing it well and doing good are the same act.

Content Disclaimer

Related Articles