Skip to content

Founder Story

Chris Müller: Taking a Wrong Turn into Cybersecurity

From aspiring social worker to Big Four consulting to CEO of KaitoSec: Chris Müller on why he wants to make information security easier and what resilience means to him.

By · Published 9 October 2026 · 9 min read

I actually wanted to become a social worker, or a teacher. Then I took a wrong turn and ended up in cybersecurity. My thinking was: I can do something for people there too. Inwardly, within the team, and outwardly, with clients I help become more resilient.

Today I'm the CEO of KaitoSec, and honestly, what we're building here ties right back to that old idea. But let me start at the beginning.

Who I am

I'm Chris Müller, 35, married, one child. I've been working in information security for more than ten years. Today I'm co-founder and managing director (CEO) of KaitoSec, a platform that brings information security, business continuity management, data protection, AI governance and supplier management together in a single data model. KaitoSec has been live since the end of August 2026.

Security has been with me since I was a teenager

When I look back, security runs through my whole life, just in different forms. Sometimes through sports, sometimes with a military background, in physical security, and, as my academic path went on, more and more in the context of digitalization.

One thing has always stayed the same. In the end, it's about people, even when we're working at a technical level. In information security you deal with very different profiles. If you meet people where they are and explain things in a way they can actually follow, you gain an enormous amount. People start helping each other out, and at the end of the day the organization really does become more secure. That formula holds for every step of my career, but also for my everyday life with the people around me.

What my father has to do with my career choice

My father trained as something like an electrical engineer in the GDR. After reunification, the technology in the West was completely different and far more advanced. He practically couldn't use anything he had learned and had to reorient himself.

That shaped me. I want to stay as close as possible to technological change, help shape it and create value with it, not just for myself but for others too. That's exactly why I ended up in information security, and exactly why I'm at KaitoSec today.

Learning the craft, hard times included

What always drew me to information security was the craft: learning and mastering what organizations need to protect themselves and become resilient. To get there, I went through several roles, including internal consultant at a global digital agency and Big Four consulting with a focus on the public sector. At the Big Four in particular, as is classic in consulting, I marched through some rough times. But I picked up a lot of conceptual knowledge there and met a few great guys here and there who you could really talk these topics through with.

In terms of content, I worked on ISMS, data protection, business continuity management and the use of AI. I write about BCM today too, most recently a guest article for BCM News on recovery testing. For all of these topics there are standards, requirements and structural frameworks. All great and helpful. But orchestrating them takes a lot: not just time, but the ability to really think your way into these topics.

As a junior consultant, I always found it hard to keep track of everything. I had to teach myself a lot and build my own overviews. And some of it was monotonous, sometimes downright dull. Let me exaggerate a bit: as a consultant, I sometimes felt like a piston in a machine, redirecting energy somewhere over and over again. Creating security is great. But the work it takes to get there is exhausting and clunky. It doesn't have to be that way.

The turning point: three interests that don't fit together

A real turning point came for me in consulting. I wanted to learn the craft and work in a good team. But that doesn't have to be what my manager wants. He has to hit his numbers. The client has to be happy. And the employee contributing somewhere in the team should be happy too. In that triangle, you can't satisfy everyone, even if that would be the ideal world.

That's where my wish came from to build an organization of my own, one that takes everyone's goals into account as best it can, always for the good of the client. Because that's what it's about in the end: that an organization actually becomes secure and doesn't fall victim to an attack. Not individual sensitivities. When things go well, really protecting the client is the shared interest of employees and management anyway. That's the goal I want to deliver on with our team at KaitoSec.

Why KaitoSec and not something else

KaitoSec also grew out of friendship. We've known each other for a long time, right now we're unfortunately all guys, and each of us brings a completely different background. These are very smart people with a lot of experience. What we throw into this melting pot actually works in the end, and it delivers scalable value for people who aren't as deep into these topics as we are or simply don't have the time.

The second reason is the craft itself. We've translated the pain you know as a junior consultant, or as a senior consultant, into concrete measures, and those are now built into our solution. The overview I used to painstakingly build for myself comes with KaitoSec out of the box.

I like to compare it to industry. First, monotonous assembly-line work was automated, then Industry 4.0 and connectivity took things to a whole new level. That's exactly what we're doing now with the core processes of information security that I used to work through by hand as a consultant. We automate them, connect them with each other, and of course use new technologies to do it, AI included. That lets organizations and the people responsible for them establish demonstrable security, especially in times as wild as these, with AI-powered attacks. Being right up front and bringing in my experience is the biggest motivator there is for me. I've also written about why this drives me in Resilience made easy.

What I do today

As CEO, I bring my expertise from more than ten years in information security into the conceptual development of KaitoSec. My focus is on the professional quality of our solution, the evolution of our concepts, and the question of how complex requirements from information security, BCM and resilience can be mapped sensibly in one platform.

Along the way, I regularly exchange ideas with subject-matter experts and with people from my professional network. That exchange is what I enjoy most about my work: bringing different perspectives together and turning them into solutions that make information security easier for organizations to understand and manage.

In 2025 I was on the main stage at the Cybersecurity Summit, where we discussed women in cybersecurity and strategies against the skills shortage.

My advice to anyone still hesitating

At first, information security feels like an ocean. But you can get the thing under control. The basic work steps and conceptual foundations are, in the end, pretty similar across the standards. Realizing that makes the topic more manageable and hopefully takes some of the fear out of it when you're just getting started.

So: don't let it overwhelm you. Talk to people and ask questions. I used to retreat into my shell, and that was a mistake I wouldn't recommend to anyone. And don't let yourself be intimidated by someone who supposedly knows more. In the end, everyone puts their pants on one leg at a time. Some people act as if they're holding a great hand of cards, and at some point it turns out there are no cards at all.

It's completely fine to say: this is too complex for me right now, I need help here. And it's worth staying in touch with the people who are willing to help.

A nice side effect, by the way: if you learn to think strategically, tactically and operationally and to build governance processes, you understand how organizations are fundamentally steered. To put it bluntly: states are steered with similar techniques too. That can become an occupational hazard when you automatically think in these structures. But it helps enormously to navigate your way through topics, in everyday life too.

What resilience means to me

For me, resilience starts with yourself. You need intrinsic motivation and have to go through the uncomfortable parts to build knowledge. That first takes individual resilience. And you have to be good to yourself and to others along the way. Only then are you able to make that resilience available to others: first on an individual level, then at the organizational level.

There, it's about getting to the core. Where is the potential point of entry? What is the concrete countermeasure to secure the system in a way that's demonstrable and traceable? There are thousands of methods. In the end, we have to identify the critical processes and assets and apply targeted measures there.

I like to speak in historical images. Information security is the wall around the castle, so nobody gets in. Business continuity management is the ability to react really fast when someone does get through the wall. The sum of both is resilience: the ability to withstand and the ability to recover. And just as securing a castle takes many other disciplines, we have further obligations too: managing suppliers, data protection, AI management and quite a bit more.

Helping organizations pull all of that off is, for me, exactly the kind of social commitment I set out to make back then. And I'm genuinely fired up about it.

If you'd like to talk about information security, BCM or resilience, feel free to message me on LinkedIn.

  • Founder Story
  • Resilienz
  • Informationssicherheit
  • Business Continuity Management

Back to the blog