In conversation with Manu Carus, Authorized OffSec Instructor and CEO of ManufakturIT GmbH

Cyberattacks are becoming more professional, legal requirements more demanding, and the responsibility of corporate management is growing rapidly. Yet many companies still treat cybersecurity as a purely IT task. Why this is a dangerous misconception and why further training is now one of the most important building blocks for corporate resilience is what we will discuss in our upcoming interview with Manu Carus, Managing Director of Manufaktur IT GmbH.
As one of the most experienced cybersecurity trainers and consultants in the German-speaking world, Manu Carus has been supporting companies, authorities, and operators of critical infrastructures for many years in sustainably strengthening their information security. In the interview, he explains what impact new regulations such as NIS2, DORA, or TISAX have on managing directors and decision-makers, why classic security awareness training is no longer sufficient, and why companies should increasingly rely on so-called security champions – especially in times of skilled labor shortages.
Look forward to exciting insights from practice, surprising food for thought, and concrete recommendations on how companies can future-proof their cybersecurity strategy. One thing is clear: sustainable information security is not achieved by modern technologies alone, but above all by people who understand security, take responsibility, and continuously develop their knowledge.
An interview that managers, IT managers, and all decision-makers who want to lead their company safely through the digital future should not miss.
Silicon Valley Europe: Mr. Carus, you say: “Cybersecurity is not an IT problem, but a management task.” Why do you think this topic is still so often seen as purely the responsibility of the IT department?
Manu Carus: In the past, information security was primarily seen as a technical issue: firewalls, virus scanners, servers and networks. And therefore located in IT. Today, we know that the biggest risks are organizational in nature. Poor decisions, inadequate processes and a lack of security awareness render even the most modern technology ineffective.
Regulations such as NIS2 make it clear: responsibility lies with senior management. Cybersecurity now determines delivery capability, reputation, company value and, in the worst case, the very survival of a company. That’s why it belongs in the boardroom – and not in the server room.
Silicon Valley Europe: With regulations such as NIS2, DORA, TISAX or KRITIS, the demands on companies are increasing significantly. What specific responsibilities do managing directors and board members have today, and what should they pay particular attention to?
Manu Carus: The days when cybersecurity could be delegated to IT are over. Senior management must understand risks, set priorities and ensure that appropriate protective measures are implemented.
This is not about senior managers getting lost in the details. Their task is to take responsibility, set an example of a security culture and provide adequate resources.
Those who view cybersecurity as a cost factor underestimate its value. Information security is now an essential component of professional corporate management and ultimately makes the difference as to whether customers trust the company or take their business elsewhere.
Silicon Valley Europe: Many companies are already investing in security awareness training. However, they believe that this alone is not enough. What are the limitations of traditional awareness programs?
Manu Carus: Awareness is important, but it’s only the beginning.
Many awareness programs focus on recognizing phishing emails or using secure passwords. While this reduces individual risks, it doesn’t build security competence.
Companies need employees who understand risks, can assess technical contexts, and integrate security aspects into their daily decisions. This is where sustainable cybersecurity begins.
Our company is committed to training executives and managers to prepare them for current challenges, as well as turning IT colleagues into the security experts of the future.
Security is not the responsibility of a single security officer or the IT department. Security concerns every single employee. That’s why training measures are needed at all levels of the company to turn awareness into competence. With NIS2, this task begins at the top of the organization.
Silicon Valley Europe: They refer to so-called Security Champions. What does this concept entail, and what added value do Security Champions offer companies – especially in light of the growing shortage of skilled workers?
Manu Carus: Security Champions are employees from various specialist departments who acquire in-depth security knowledge in addition to their roles and act as multipliers within their teams. I mean Sales, Marketing, Controlling, HR – so not just IT.
While such experts do not replace an IT security department, they do bridge the gap between specialist departments and the security team.
This model is particularly valuable in light of the shortage of skilled workers. Companies build internal expertise, shorten communication channels, and integrate security directly into projects and business processes – where they originate and are implemented, not isolated in another niche of expertise.
I am convinced that almost every larger company will establish a network of Security Champions in the future.
Silicon Valley Europe: Cybersecurity is constantly evolving. What significance does continuous education have compared to one-time training sessions, and how can a sustainable learning culture be established within a company?
Manu Carus: Cybersecurity changes every day. New attack methods, new technologies, and new legal requirements cause knowledge to quickly become outdated. Just consider the disruptions surrounding artificial intelligence!
That’s why continuing education can never be a one-time project. A week of “course and done” simply doesn’t work. You only remain a Security Champion through ongoing engagement.
Successful companies establish a learning culture. They continuously invest in the development of their employees and view further education as a strategic process—similar to quality management or innovation management.
This not only enhances security but also makes companies more adaptable and resilient overall.
For this reason, we have developed our coaching model, which supports companies over a long period in building their security capabilities.
Silicon Valley Europe: Die Manufaktur IT GmbH deliberately focuses on small learning groups, intensive support, and practical training. What sets your training approach apart from traditional providers?
Manu Carus: We see ourselves not as a short-term seminar provider, but as a long-term learning partner.
Our participants should not only pass an exam but be able to apply what they have learned in their daily professional lives on a lasting basis.
That’s why we work with small groups, plenty of practical exercises, intensive personal support, and long-term coaching.
We often support our participants for several months and are available to them as contact persons even between training days.
Especially with demanding certifications like CISSP or OSCP, this continuous support makes all the difference.
As a result, our participants learn to live cybersecurity in their daily work: managing risks, taking the right measures, and implementing sustainable solutions. Across departments.
Our focus is less on the one-time certificate, which is certainly valuable for professional development. What matters most to us is the internalization of security awareness, the everyday application of processes, standards, technologies, and best practices, as well as the company-wide implementation of business resilience.
In a constantly evolving environment, this is only possible through extensive and regularly held training measures.
Silicon Valley Europe: You are an official trainer for ISC2 and OffSec and combine management topics with in-depth technical expertise. How important is it for strategic decision-makers and technical specialists to develop a shared understanding of cybersecurity?
Manu Carus: Extremely important. Many misunderstandings arise precisely because management and technical teams speak different languages.
Senior management thinks in terms of risks, investments, and corporate goals.
Technical specialists think in terms of vulnerabilities, protocols, and attack scenarios.
Both perspectives are correct—but they need to be aligned.
Only when both sides develop a shared understanding can sustainable security strategies emerge.
I work as a security consultant for CEOs and senior management. At the same time, I test IT systems for vulnerabilities and engage with developers and admins. Such a bridge must be established in every company between experts and leadership to successfully detect and prevent attacks. Our training model is specifically designed to enable employees to do exactly that.
Silicon Valley Europe: What typical mistakes do you repeatedly observe in companies when it comes to building a sustainable security strategy?
Manu Carus: The most common mistake is to regard cybersecurity as a project.
Security is not a state that you reach at some point.
It is a continuous improvement process.
Other typical mistakes include:
- an excessive focus on technology,
- lack of support from senior management,
- inadequate employee training.
- missing exercises for security incidents,
- as well as a security strategy that is not aligned with corporate objectives.
Silicon Valley Europe: If you could give a CEO just three concrete recommendations today to strengthen their company’s cyber resilience, what would they be?
Manu Carus: First: Make cybersecurity a top priority for management.
Second: Consistently invest in training your employees. Technology can be purchased – competence must be developed.
Third: Think in terms of resilience rather than perfection. Attacks can never be completely prevented. What matters is how quickly and professionally a company can respond.
Silicon Valley Europe: Finally, let’s take a look into the future: Which developments will particularly shape the cybersecurity landscape in the next three to five years, and what should companies prepare for today?
Manu Carus: Artificial intelligence will change both attacks and defense alike.
At the same time, regulatory requirements will continue to increase. Companies will need to demonstrate their security measures far more rigorously than they do today.
Moreover, the skills shortage will persist. As a result, companies will increasingly focus on internal competence development, security champions, and continuous training.
I believe that in the future, successful companies will not be distinguished by the technology they use, but by how well their people are prepared.
Ultimately, it is not the software that determines security—it is the people who use it responsibly.
In this spirit, our company stands as a thought leader for security champions, management enablement, and sustainable cybersecurity expertise.
Silicon Valley Europe: Mr. Carus, thank you very much for the interesting conversation.