Marco Eggerling, International CISO at UiPath: “The single highest return investment most organisations can make right now is achieving identity hygiene”

You may need to sit down for our interview with Marco Eggerling, International CISO at UiPath, as we cover a lot of ground. Perhaps not surprising when you consider that he has more than 25 years’ experience as a cybersecurity executive, AI and risk expert, including senior security positions at Check Point Software, Cisco and Deloitte.

We cover all the hot topics: deepfakes, ransomware, the talent gap, the growing attack surface that organisations must now defend. Then there’s the topic that gives this interview its quote, the problem of identity hygeine.

“Most successful attacks involve compromised credentials at some point in the kill chain,” said Marco. “Multi-factor authentication, enforced across every user and system without exception, removes a massive proportion of attack surface immediately. Yet, I still encounter large enterprises with MFA gaps. There is no sophisticated threat model that justifies an MFA gap – close them.”

And there is more, so much more. The importance of privileged access management. Supply chain security, an area that crops up more and more from the experts we interview. Security awareness as a whole, particularly at board level.

Our huge thanks to Marco for his time. We hope you heed his advice. But let’s start with a proper introduction…


Could you please introduce yourself to our audience and share how you ended up working in cybersecurity?

I’m Marco Eggerling, CISO at UiPath. My path into cybersecurity wasn’t a straight line, mostly because the field didn’t really exist earlier in my career, at least not by that name.

I started out doing cryptography and forensic work, which in hindsight was great for understanding the technical roots of the security sector. From there, I moved into consulting and presales roles at various organisations, trying to make sense of a rapidly evolving technology landscape. Back then, IT, information security and what we now call cybersecurity were the same thing. Nobody drew a distinction, because nobody needed to.

Over time, I noticed and grew concerned about the significant gap between regulation and technology, with few experts in the industry understanding both sides. Technical people didn’t speak the language of law and policy and legal people didn’t understand architecture or business management. I knew that IT knowledge alone wouldn’t create a well-rounded understanding, so I went to the University of Edinburgh to study IT Law. I wanted to be one of the few people who could genuinely operate across all three disciplines.

That set an early foundation to grow into CISO roles, build and lead global operating teams. Over time I started speaking at international conferences, contributing to media, and advising policymakers, and that part of the work has become something I genuinely value.

That is the through line: someone who grew up with this industry and never stopped being curious about where it is going next.

What are some cases of deepfakes being used that particularly concern you?

The case that reshaped how I frame deepfake risk for executives was the 2024 incident in Hong Kong where a finance employee was manipulated into transferring approximately $25 million after participating in a video call populated almost entirely by deepfake representations of colleagues, including the CFO. No phishing link, no malware, just a fabricated meeting that looked routine.

That case concerns me for a structural reason: it broke the last line of defence most organisations unconsciously rely on — the human voice and face of a trusted colleague. We have spent years training staff to be sceptical of email links and text messages, but not to question someone’s visual identity.

Deepfake-enabled executive impersonation targeting boards and investors also keeps me up at night. Imagine a synthetic video of a CEO announcing a strategic pivot or material acquisition ahead of an earnings call. The market impact before correction could be catastrophic, and the attribution problem is genuinely hard. You are dealing with a crime that produces no physical evidence and can be executed from any jurisdiction.

The third area is more personal, and arguably more dangerous at scale: political and judicial manipulation. Synthetic evidence introduced into legal proceedings is an emerging threat my legal background makes me particularly sensitive to. Chain of custody standards for digital evidence were not designed for a world where convincing video can be fabricated with consumer-grade tools.

Finally, I am deeply concerned about deepfakes in social engineering at scale. Attackers are going beyond craft individual spear-phishing messages; they are generating synthetic voice and video messages and deploying them at volume against enterprise targets. The economics have inverted; high-quality deception used to require significant effort per target, but that constraint no longer exists.

The common thread is the collapse of trust. Every system we have built assumes some baseline of authenticity in human communication— deepfakes are a direct attack on that assumption.

What do you think are the best approaches to combating deepfakes?

The honest answer is there is no single countermeasure that addresses this problem. The approach that does work is a layered architecture of technical, procedural, and cultural controls.

On the technical side, content provenance standards are the most promising structural response. Organisations should be pushing their vendors to adopt a C2PA compliance framework, which embeds cryptographic metadata into media at the point of creation and creates an auditable chain of origin. Camera manufacturers, major platforms, and enterprise software vendors are beginning to adopt it. It’s not entirely deepfake proof, but it does create a meaningful authenticity signal for content that originates from verified sources. 

Detection tools exist and can be used within a broader assessment, but I counsel executives not to treat them as their primary defence measure. Detection accuracy is improving, but so is generation quality, and the arms race consistently favours the offense.

Procedurally, the most impactful thing organisations can do immediately is implement out-of-band verification for high-value transactions and decisions. If someone calls or appears on video requesting a wire transfer, strategic announcement, or access credentials, verify through a secondary channel before acting. This is a simple, inexpensive step and would have prevented the Hong Kong incident entirely.

There is also a cultural shift required to address what I call, structured scepticism. Employees must feel empowered to pause, question, and verify even when a request appears to come from a senior person in a trusted context. That is a cultural problem as much as a training problem. If your organisation punishes people for questioning authority, no deepfake training programme will overcome that.

At policy level, organisations should engage legal teams on synthetic media policies, update incident response playbooks to include deepfake scenarios, and review cyber insurance coverage considering this threat class.

The ransomware landscape has become so sophisticated, that it still surprises execs I speak with. We are talking about vertically integrated criminal enterprises with HR functions, customer service portals, and affiliate programmes recognisable to any MBA — not just opportunistic criminals. 

One shift every professional needs to understand is the rise of double and triple extortion. Encryption alone is no longer the primary lever. Attackers exfiltrate data before encrypting it, then threaten publication on leak sites. Increasingly, they contact customers, regulators, or media directly to amplify pressure. A strong backup posture now only addresses part of the problem.

Another major development is the targeting of critical infrastructure and operational technology environments. Attacks on manufacturing, healthcare, logistics, and utilities have increased because downtime creates immediate physical-world consequences that compress payment timelines, and attackers understand this calculus precisely.

Equally concerning is the exploitation of identity infrastructure. Rather than deploying novel malware, sophisticated groups are living off the land, using legitimate credentials and tools to move laterally. They compromise identity providers, abuse service accounts, and establish persistent access that can survive perimeter defences and endpoint detection. This makes detection difficult because the activity resembles normal administrative behaviour.

Directly relevant to the automation space where UiPath operates, attackers are also beginning to target RPA bots and automation workflows. A compromised bot with elevated privileges and access to enterprise systems is an extraordinarily valuable pivot point. Most organisations are yet to extend identity governance and privileged access management frameworks to cover their automation estate.

Ransom payment decisions also carry serious legal risk given OFAC sanctions exposure and evolving regulatory postures in multiple jurisdictions. It’s crucial that legal and security departments are aligned before an incident, not in response to one.

What are the biggest cybersecurity challenges those in leadership roles are facing?

A challenge I consistently hear from peers is around translating security concerns to be understood by the wider business. Security leaders understand the risk landscape with precision, but the board wants to understand it in terms of financial exposure, regulatory liability, and strategic consequence. Building that translation layer fluently and in both directions, is as difficult as it is important.

Most boards lack the technological context to judge which risks are existential, manageable and which are already effectively mitigated. The CISO’s job is to provide that calibration honestly, without catastrophising the situation to capture budget or minimising it to avoid uncomfortable conversations.

The second major challenge is the speed at which the attack surface is expanding. Cloud adoption, AI integration, third-party automation, remote working infrastructure and shadow IT have made the traditional perimeter largely theoretical. You cannot defend a boundary that no longer exists, yet many leaders still think in perimeter terms and are systematically underestimating their exposure.

Third is the talent gap, which is structural rather than cyclical. The solution is not to hire your way out of it, but to embed security into engineering processes so that developers, product managers and automation builders make security-informed decisions by default. Security cannot scale as a specialist function reviewing output at the end of a process; it must be built into the process itself.

Fourth is third-party risk. Many of the most significant breaches in recent years have involved a supplier, partner or software vendor as the initial access vector. An organisation’s security posture is only as strong as the weakest link in its supply chain, yet most businesses still lack adequate visibility across that chain.

A final challenge, underscoring the sectors, is that the regulatory environment is fragmenting rapidly across jurisdictions. Global organisations must now navigate NIS2, DORA, SEC cyber disclosure rules, state-level privacy laws and sector-specific mandates simultaneously. This compliance burden is consuming capacity within security teams, that would otherwise be focused on reducing actual risk.

What is your take on ethical hackers and their role in cybersecurity?

My view on ethical hackers is that they are one of the most cost-effective investments a security program can make, and organisations that treat them as a peripheral or optional activity are missing out on a significant risk reduction opportunity.

The core value proposition is asymmetric. An attacker needs to find one exploitable path and a defender needs to secure every path. Ethical hackers, particularly those engaged through mature bug bounty programs or structured red team exercises, bring an adversarial mindset that internal teams rarely sustain consistently. You cannot think like an external attacker by reviewing your own architecture all day.

Over my 25 years in the industry, I’ve noticed organisations go through a predictable maturity cycle with ethical hacking. Initially there is resistance, often from engineering teams who feel criticised and legal teams who worry about liability.

Then there is compliance-driven adoption where penetration tests become checkbox exercises conducted annually by the same firm using the same methodology. In the final phase, organisations reach a point where they run continuous adversary simulation, operate public bug bounty programs with meaningful rewards, and treat findings as a direct input to engineering priorities rather than a compliance artifact. UiPath operates in the final phase, and the intelligence we get from that program is genuinely irreplaceable.

I also want to address the legal dimension because it is often misunderstood. Clarity on scope is everything in ethical hacking engagements. The moment an ethical hacker operates outside an agreed scope, they are in legally ambiguous or illegal territory regardless of intent. Organisations need proper engagement agreements, and ethical hackers need to understand that their legal protection depends entirely on the quality of the authorisation framework they operate within.

The best ethical hackers I have worked with combine deep technical skill with the ability to explain findings to a non-technical executive audience. That combination is rare and worth paying for.

What are some prevention strategies you believe every business should adopt?

The single highest return investment most organisations can make right now is achieving identity hygiene. Most successful attacks involve compromised credentials at some point in the kill chain. Multi-factor authentication, enforced across every user and system without exception, removes a massive proportion of attack surface immediately. Yet, I still encounter large enterprises with MFA gaps. There is no sophisticated threat model that justifies an MFA gap – close them.

Privileged access management is equally important. Not every account needs administrative rights. Lateral movement in a breach is almost always enabled by over-provisioned accounts. Applying least privilege consistently, reviewing it regularly, and extending that discipline to service accounts and automation bots is foundational work that makes the attacker’s job materially harder.

Supply chain security is another area where organisations remain exposed. You need a current inventory of every third-party component in your technology stack, the access each vendor has to your environment, and the security standards you require contractually. Most organisations have one of these three and very few have all three.

Security awareness also needs to be genuinely effective. I am not talking about annual compliance videos, think simulation-based learning, regular phishing exercises with immediate feedback, and building a culture where reporting a suspected incident is rewarded rather than stigmatised. The human layer is attacked relentlessly because it is often the softest.

Just as important is having and testing an incident response plan. Having a plan that has never been exercised isn’t that different from having no plan. Tabletop exercises, that run at executive level including legal and communications, convert a theoretical plan into organisational muscle memory.

Finally, data classification underpins every other control decision. You cannot protect everything equally. Knowing where your most sensitive data lives, who has access to it, and how it flows through your environment is the prerequisite to every other control decision.

What is it about generative AI that makes it so prone to exploitation by threat actors? Conversely, how can it be used for good?

Generative AI is exploitable because its core properties — fluency, scalability, adaptability, and low barrier to access — are precisely what attackers need and historically had to work hard to obtain.

Social engineering at scale used to be constrained by the cost of human labour. Crafting a convincing spear-phishing email requires research, language skill, and time. Generative AI removes those constraints simultaneously. Attackers can now produce highly personalised, grammatically perfect, contextually appropriate malicious content at volume. The old heuristic of looking for poor grammar and strange phrasing as an indicator of phishing is dead. Training users on it is now actively counterproductive.

Generative AI also accelerates vulnerability research. Models trained on code can assist in identifying exploitable patterns in software. This does not require state-level capability. It is accessible to modestly resourced criminal groups. The asymmetry of offence versus defence, already a structural problem in cybersecurity, widens further.

There is also the jailbreaking problem specific to AI systems themselves. As organisations deploy AI assistants with access to internal data, those systems become targets. Prompt injection, where malicious instructions are embedded in content the AI is asked to process, is a genuinely novel attack class that most security programmes have not yet operationalised a response to.

On the defensive side, the picture is genuinely positive. AI improves threat detection by identifying anomalous behaviour patterns across data volumes that no human team alone could process. Alert fatigue, which has historically caused security teams to miss critical signals buried in noise, is addressable through AI-assisted triage and prioritisation.

AI also accelerates defensive research, helps security teams understand attacker tooling faster, and enables more sophisticated simulation for red team exercises. It is unquestionably a force multiplier that can help bridge the security talent gap. The question for executives is whether their security programme is using it faster than their adversaries are.

Which cybersecurity best practices are being adopted with the most success by companies?

Based on what I’ve observed across the industry and in peer CISO conversations, the practices seeing the most genuine adoption and measurable impact are clustered around identity, detection and organisational culture.

Zero trust architecture adoption has accelerated significantly. The principle of never trust, always verify, applied consistently across network, application and data access, is producing measurable reductions in lateral movement post-breach. Organisations that implemented zero trust before an incident consistently report better containment outcomes. The implementation journey is long and complex, but the directional commitment to zero trust is now mainstream among security-mature organisations.

Endpoint detection and response has largely replaced traditional antivirus as the enterprise endpoint standard, and the combination of EDR with security information and event management platforms is enabling detection capabilities that did not exist a decade ago. The challenge is not the technology but the analyst capacity to act on what it surfaces, which brings us back to the talent and AI augmentation point.

Security Champions programmes, where organisations embed security-aware individuals within engineering and product teams, are producing meaningful cultural change. These are developers and product managers with additional security training who serve as the first point of contact for security questions within their teams. At scale, this model multiplies the reach of the security function significantly.

Vendor risk management programmes have matured, driven partly by regulation and partly by high-profile supply chain incidents. More organisations are now conducting meaningful security assessments of critical vendors rather than relying on self-certification questionnaires.

Cyber incident simulation at executive level is also gaining adoption. Boards and C-suites are participating in tabletop exercises covering breach scenarios, media response, regulatory notification, and operational decision-making under uncertainty. Organisations that do this consistently are faster and more coherent in their actual incident responses.

What role do you think governments play when it comes to cybersecurity?

Governments play three distinct roles in cybersecurity, and their effectiveness varies across all three.

The first is standard-setting and regulation. This is where governments have the most leverage and where I have the most mixed feelings. Well-designed frameworks, like DORA in EU financial services, create a rising baseline that lifts security posture across entire sectors. They force organisations to make investments market incentives alone would not produce. The NIS2 directive is similarly structured to address chronic underinvestment in critical infrastructure security.

The failure mode of regulation is when it prioritises compliance activity over actual risk reduction. If an organisation can satisfy requirements through documentation and box-ticking without materially improving its security posture, the regulation has produced overhead without outcome. I have seen both versions in practice.

Governments also play an important role in threat intelligence sharing. Agencies, particularly in the Five Eyes community, have access to intelligence the private sector cannot generate independently. The challenge is classification. By the time intelligence is declassified and shared with industry, the relevant threat actor has often already moved on. There is progress on the speed and breadth of information sharing, but the gap between what government knows and what industry receives remains significant.

The third role is offensive capability and norms. Nation-state cyber operations are now a permanent feature of the geopolitical environment. The international norms around acceptable state behaviour in cyberspace are still being contested, and that ambiguity creates risk for private sector organisations caught in the crossfire.

My recommendation to security leaders is to engage actively with government programmes, use the resources available, contribute to industry working groups, and maintain independent threat intelligence capabilities rather than relying on government sharing as a primary source.

What’s something that has drastically changed about cybersecurity since you first got started in the field?

When I started in the field, the adversary was primarily an individual, usually technically sophisticated and often motivated by curiosity or notoriety rather than financial return. Their target was typically the technology itself and the goal was to demonstrate capability.

What has changed most fundamentally is that cybercrime became an industry. This happened gradually through the 2000s and accelerated sharply in the 2010s with the professionalisation of ransomware and the emergence of cybercrime-as-a-service ecosystems. Today, you don’t need to be a skilled attacker to conduct a sophisticated attack. You need to be a paying customer of someone who is.

This shift has several consequences. The volume of attacks is orders of magnitude higher than anything I would have predicted twenty years ago because the barrier to entry has collapsed. The financial returns are large enough to attract serious investment from criminal groups. The attack surface has also expanded from technology systems to human beings, business processes, and supply chains in ways that make the security problem qualitatively different.

Another major change is the collapse of the perimeter as an organising concept. When I started, enterprises operated more like castles with defined walls. Data lived on premises, users worked in offices, and systems were largely air-gapped from the public internet. The CISO’s job was to defend a boundary.

That model is now obsolete as data lives across multiple cloud environments simultaneously. Users are everywhere. Third-party systems are deeply integrated into core processes. The attack surface is now a complex, dynamic ecosystem.

The security philosophy required for that environment, built around identity, continuous verification, data-centric controls, and behavioural detection, is fundamentally different from perimeter defence. Organisations that have made that transition are genuinely better positioned.

What advice do you have for aspiring professionals wanting to work in cybersecurity?

The most important thing I can tell someone starting in this field is to develop intellectual breadth alongside technical depth. The security problems that matter most are not purely technical. They sit at the intersection of technology, human behaviour, organisational design, legal frameworks, and geopolitics. The professionals who can navigate all of those dimensions are consistently more effective than those who can only navigate one.

On the technical side, get your fundamentals right. Networking, operating systems, identity and access management, cryptography. Not at a certification surface level but at a level where you genuinely understand what is happening beneath the abstraction. The threat landscape changes constantly but the fundamentals do not.

On the non-technical side, develop your communication skills deliberately. This is the capability gap I see most consistently in technically talented security professionals. If you cannot explain a risk clearly to a non-technical executive, you will not get the resources to address it. If you cannot explain a control clearly to a developer, they will not implement it correctly. Communication in this field is not a soft skill. It is a core professional competency.

My recommendation for early career professionals is to pursue breadth before specialisation. Spend time in operations, engineering, incident response, and if possible legal or compliance. Understand how the organisation you are protecting actually works. Security built in isolation from business context will consistently fail at the edges.

Build a professional network and maintain it. The security community is genuinely collaborative in a way that is unusual for a competitive industry. The threat intelligence, peer support during incidents, and career development that flows through that network is professionally irreplaceable.

Finally, develop a tolerance for ambiguity. You will rarely have all the information, and decisions will often need to be made under pressure with imperfect data. The professionals who thrive are those comfortable acting decisively, despite uncertainty while remaining intellectually honest about what they do not know.

About The Author

Rowan Campbell TechFinitive
Rowan Campbell

Rowan is a writer for TechFinitive focusing on technology companies doing interesting things all around the globe. He is currently studying philosophy at university.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.