Francesco Chiarini

Global VP, Cyber Resilience @ Rubrik | CXO Transformation | Board Advisor | ISSA Community Chairman | WEF and CR-CMM Author | Founder @ High Value Target | Instructor @ Cyber Resilience Academy

Italy

About

Designing resilience to outplay adversity, one blueprint at a time. On a mission to ensure cyber resilience is adopted globally as a core enterprise discipline, I build and operationalize resilient architectures that ensure continuity, safety, and rapid recoverability against advanced cyber threats. With 20+ years of security and technology leadership across organizations including PepsiCo, Standard Chartered Bank, and Sandoz, the focus has been translating risk into executable strategies that matter to CXOs, Boards, and institutional stakeholders. Practical innovation has shaped much of this work: the creation of the Cyber Resilience Capability Maturity Model (CR-CMM) to embed resilience into operating models, and the development of the High Value Target concept to prioritize assets from an adversarial perspective. This approach included implementing NIST SP 800-160 principles alongside members of US CISA and building one of the earliest global Cyber Fusion Centers, integrating incident response, red teaming, and cyber resilience at scale. The ecosystem dimension has been equally central - founding Cyber Resilience Awareness Day, chairing the largest ISSA Cyber Resilience community of 2,500 professionals, and creating the Cyber Resilience Academy. In collaboration with NIST, this led to the definition of a dedicated competency area for cyber resilience skills and the professional figure of the Cyber Resilience Officer. The Cyber Resilience Manifesto further provides a foundational toolkit to turn resilience into repeatable capability. This work connects cybersecurity strategy, data recoverability, and adversary disruption into outcomes that shift organizations from reactive defense to proactive, evidence-based resilience. Hundreds of security professionals have been hired and developed along this journey, recognized through the ISSA Volunteer of the Year Award and the US Consumer Brands Association Global Innovation Award. I leverage and help advance global best practices (NIST, MITRE, WEF, OASIS, FIRST), specializing in cyber resilience, incident response, digital investigations, red teaming, infrastructure protection, crisis leadership, and enterprise risk in highly complex organizations. Main certifications: SABSA, TOGAF, GCED, GRTP, CCRO, ISO 22301, ISO 27001/27000, EnCase, CISM, CGEIT, CEH, CCSK, MoR, ITIL, Lean Six Sigma.

Experience

  • VP, CISO in Residence at Rubrik
    May 2026 - Present · 3 mos

    Strategic Advisory - Advise top CISOs, CIOs, boards, and executive teams on cyber resilience readiness, maturity, and transformation. - Sponsor cyber resilience assessments and help translate findings into practical actions and business outcomes. - Enable field and customer-facing teams with executive narratives, advisory content, and resilience frameworks. Cyber Resilience Transformation and Frameworks - Lead cyber resilience transformation strategy, governance, and operating model design for Clients. - Translate board-level resilience goals into measurable roadmaps, KPIs, and investment priorities. - Align resilience practices with frameworks and regulations such as NIST SP 800-160, MITRE CREF, NIST CSF 2.0, DORA, and NIS2. Industry Outreach, Research and Education - Represent the organization in cyber resilience communities, standards bodies, research initiatives, and industry forums. - Lead thought leadership on cyber resilience, including whitepapers, playbooks, executive workshops, and community initiatives. - Support internal and external education on cyber resilience, including training programs and executive masterclasses.

  • AI Resilience - Founding Member at CSAI Foundation
    May 2026 - Present · 3 mos

    Lead the development of pioneering AI frameworks and methodologies to secure complex, autonomous system environments. Serve as a trusted advisor to CXOs, empowering them to adopt best-in-class practices that safeguard model integrity, data trustworthiness, and operational continuity. Help organizations scale their AI initiatives while ensuring failures remain manageable incidents rather than business crises.

  • Founder & Chairman - Cyber Resilience Community at Information Systems Security Association (ISSA)
    Dec 2018 - Present · 7 yrs 8 mos

    Chairman of the Cyber Resilience Special Interest Group (SIG) founded in 2021, with over 2500+ members across the globe - focused on gathering subject matter experts within ISSA members around NIST 800-160 guidelines and more. In charge of setting up the global charter and framework for the SIG to be productive and successful.

  • Founding Member & Chairman of Advisory Board at CR-CMM (Cyber Resilience Capability Maturity Model)
    Jan 2025 - Present · 1 yr 7 mos

    Helping organizations enhance their ability to anticipate, withstand, recover from, and adapt to adverse cyber events. Its primary goal is to provide a structured approach for assessing an organization’s current cyber resilience maturity and identifying priority areas for improvement. CR-CMM is owned by High Value Target.

  • Founder & Instructor at Cyber Resilience Academy
    Oct 2024 - Present · 1 yr 10 mos

    The Cyber Resilience Academy offers live, hands-on training to equip you with the skills to design and ensure cyber-resilient organizations and complex systems-of-systems. Our courses teach you how to effectively leverage authoritative frameworks that can be easily implemented in any organization. We ensure personalized attention and high-quality learning experiences for each attendee.