In this episode of The New CISO, host Steve Moore speaks with Manuel "Manu" Ressel, CISO at SAUTER Group, about his unconventional journey from classroom teacher to cybersecurity leader—and why the "Four Cs" of modern education provide a powerful framework for building effective security programs. Drawing from years as both a teacher and school principal in Germany, Manu introduces Critical Thinking, Communication, Collaboration, and Creativity as essential leadership skills that fundamentally challenge how the industry approaches awareness training and incident response.
After growing frustrated with Germany's outdated education system that prioritized memorization over critical thinking, Manu left his position as principal and reinvented himself as a digital transformation consultant. Working with schools and mid-sized companies to adopt cloud technologies, he eventually landed the CISO role at SAUTER, an international building automation company with 4,000 employees across multiple countries.
The conversation tackles security's most persistent failure: awareness training that doesn't work. Manu reveals that 37% of security incidents in Germany could be prevented if users made better decisions, yet most organizations rely on boring click-through programs. He advocates for scenario-based, role-specific training—an approach now mandated by Europe's NIS 2 regulation—that treats people as the biggest opportunity in cybersecurity rather than the weakest link.
One of the episode's most practical frameworks is Manu's Observation-Description-Interpretation method for analyzing security incidents. He explains how humans naturally jump from observation directly to interpretation, skipping the crucial middle step of accurately describing what actually happened. This leads to finger-pointing, misdiagnosis, and hasty decisions. By training security analysts to pause and describe incidents factually first, teams make better decisions and build trust with the business.
Manu challenges the punitive approach many organizations take toward security failures, particularly companies that fire employees for repeatedly clicking phishing simulations. He champions building positive fault cultures where employees feel safe reporting mistakes. His three crisis questions—Is anyone dying? Major financial impact? Will someone be hurt?—provide a simple framework for staying calm and deciding when immediate action is necessary versus taking time to think strategically.
Key Topics Discussed:
- Why the "Four Cs" (Critical Thinking, Communication, Collaboration, Creativity) define effective security leadership
- The Observation-Description-Interpretation framework for incident analysis without bias
- Transforming ineffective awareness training into engaging, scenario-based programs
- Building positive security cultures where employees report issues without fear
- NIS 2's mandate for role-specific cybersecurity training across organizational levels
- Why Germany and European mid-market companies lag in cloud adoption
- Three critical crisis questions: Is anyone dying? Financial impact? Risk of harm?
- Why punitive phishing training destroys trust and cultural engagement
- Applying teacher skills to security leadership and de-escalation techniques
- Staying calm as a CISO's most important superpower during incidents
LEARN MORE:
👉 Guest LinkedIn: https://www.linkedin.com/in/manuel-ressel-9279b997/
Company website: https://www.sauter-controls.com/
GET A DEMO:
👉 Get a hands-on demo of the Exabeam products: https://www.exabeam.com/demo
🔔 Subscribe for more product demos and cybersecurity insights!
ABOUT EXABEAM:
Exabeam is a leader in intelligence and automation that powers security operations for the world’s smartest companies. As a global cybersecurity innovator, Exabeam provides industry-proven, security-focused, and flexible solutions for faster, more accurate threat detection, investigation, and response (TDIR). Cutting-edge technology enhances security operations center performance, optimizing workflows and accelerating time to resolution. With consistent leadership in AI innovation and a proven track record in security information and event management (SIEM) and user behavior analytics, Exabeam empowers global security teams to combat cyberthreats, mitigate risk, and streamline operations.
Real Intelligence. Real Security. Real Fast. Learn more at: https://www.exabeam.com/
CONNECT WITH US:
X/Twitter: https://x.com/exabeam
Instagram: https://www.instagram.com/exabeam/
LinkedIn: https://www.linkedin.com/company/exabeam/
Facebook: https://www.facebook.com/Exabeam/
Blog: https://www.exabeam.com/blog/