Paris runs on brands the whole world recognises, and behind each of them sits a security chief whose work rarely makes the news by design. The seven CISOs below protect beauty empires, champagne houses, railway stations, and broadcasters reaching hundreds of millions. What most of them share is a formation that began in the audit room or the penetration test, then moved into governance, then into the chair.
Jean-Jacques Mallet – Group CISO, L’Oréal
More than two decades in IT security, almost twelve of them inside L’Oréal, and Jean-Jacques Mallet now runs security for the world’s largest beauty company. Group CISO since September 2022 after nearly six years as EMEA CISO and two as information system security manager, he has effectively grown up with the company’s digital transformation, from data centre modernisation to the current cloud and e-commerce estate. The credentials match the scale: ISO 27001 Lead Auditor, ISO 27005 Risk Manager, PCI QSA, and ITIL Foundation. Before L’Oréal he spent four and a half years as group CISO at Webhelp, standing up a SOC and certifying the outsourcer to PCI DSS and ISO 27001 across entities in France, Morocco, Romania, Belgium, and Algeria. Six years at Symantec preceded that, first as a principal security consultant running network and application security assessments, then building the advisory services practice for France, Belux, and North Africa. Earlier still came consulting at Solucom and nearly three years at Intrinsec conducting penetration tests for large financial institutions. Governance, SOC and CERT operations, and security audits remain his declared specialities.
Rodolphe Robert – CISO, Moët Hennessy
Protecting Dom Pérignon and Hennessy means protecting factories, not just data centres. Rodolphe Robert has served as CISO of Moët Hennessy, LVMH’s wines and spirits house, since April 2018. His stated specialities read like the brief for a producer with vineyards, distilleries, and a global supply chain: industrial system cybersecurity, connected objects, and the OIV critical-activity obligations France imposes on vital operators, alongside PCI DSS certification programmes, secure development via OpenSAMM, and crisis management. The role followed two and a half years as CISO at Allianz Partners and nearly seven years at AREVA, first supervising IT audit and then managing transversal quality and security. The foundation is audit: five years as a senior IT audit manager at Office Depot and nearly three years at PwC, after starting as a developer at Sopra and a project manager at Alcatel-Lucent.
Nicolas Vielliard – Group CISO, Danone
Danone’s security operations used to report to Nicolas Vielliard; now everything does. Promoted to Group CISO in November 2024 after three and a half years as the food group’s cybersecurity operations director, he knows the SOC floor as well as the boardroom. The decade before Danone ran through ENGIE, where he spent five years as corporate CISO and then two and a half building and leading the global security operations centre, and through Banque de France, where he managed information system risk for the central bank itself. Before that came four years in international audit at Crédit Agricole Consumer Finance, rising from internal auditor to audit mission lead, and earlier IT engineering and project management at LCL. His industry footprint is unusually deep: a steering committee seat at Les Assises de la Sécurité since 2018 and five and a half years on the board of CLUSIF, France’s storied security professionals’ association. Few group CISOs carry credentials from both a central bank and an energy giant into a dairy and waters empire.
Ugo Vaucel – CISO, SNCF Retail & Connexions
France’s railway group grew its newest CISO from inside its own audit function. Ugo Vaucel became RSSI of SNCF Retail & Connexions in July 2026 after ten months as deputy, a posting that began as a quarter-time secondment from the group’s cybersecurity directorate to raise the subsidiary’s maturity. He held that deputy role alongside his day job in the group directorate’s consulting and expertise branch, where from January 2025 he ran cyber maturity audits across SNCF subsidiaries against ISO 27001, NIST CSF 2.0, and NIS 2. Both followed nearly three years consulting on cyber risk and resilience for CAC 40 clients in banking, defence, transport, and real estate at HeadMind Partners, where the evaluation committee marked his annual contribution exceptional and advanced his grade. He splits his week between Paris and Rennes. At a group where stations, ticketing, and retail converge, his audit-first formation is the point.
Sébastien Olaïzola – CISO, France Médias Monde
When your products are France 24, RFI, MCD, and CFI, security is partly about keeping journalism on air. Sébastien Olaïzola has been CISO of France Médias Monde since July 2023, leading security transformation programmes across cloud, identity, and SOC while aligning risk management to ISO 27001 across the group’s multi-country, multi-entity estate. He arrived from Insee, the national statistics institute, where he headed the security and risk division, and before that spent three and a half years as the Interior Ministry’s head of SSI policy at the CSN. The depth behind those postings is unusual: nineteen years as a technical cyber manager with the Ministry of the Armed Forces working in signals and communications intelligence, followed by three years in a comparable role at the Interior Ministry. He also sat on the engineering recruitment examination jury for five years. His ecosystem work is extensive, including expert membership of CESIN and membership of the European Broadcasting Union since 2024. Public service media faces public service threats, and Olaïzola’s whole career has been preparation.
Wassim Youssef – CISO, AXA XL
Eighteen years into cybersecurity, Wassim Youssef runs a multi-million-euro security programme and a global team spanning Europe, the Americas, and Asia as CISO of AXA XL, AXA’s commercial property and casualty and specialty risk division, a seat he has held since October 2019. He had spent the previous four years as CISO of AXA Corporate Solutions, giving him more than a decade of continuous CISO tenure inside one of the world’s largest insurers. The formation was five and a half years managing IT and network security projects at Orange and three years consulting at Devoteam. His stated mission is alignment: security as a business enabler rather than a blocker, with risk governance wired into digital transformation. For a division that underwrites the world’s largest corporate risks, that framing is the job description.
Walif El Hitti – CISO, Comgest
Asset managers sell trust, so their security chiefs sell assurance. Walif El Hitti has been CISO of Comgest, the Paris-based international asset manager, since September 2017, piloting cyber risk management, GDPR compliance, DORA implementation, penetration testing, and staff awareness for a firm whose clients expect institutional-grade discipline. The groundwork was nearly a decade at Société Générale: CISO and global security account manager for equipment finance across twenty countries and 3,500 staff, deputy CISO of the securities services arm, and three years in the IT audit practice leading complex assignments. A Télécom Paris engineer with CISA, CISM, ISO 27001, and ISO 27005 certifications, he represents the classic French RSSI formation, technical schooling plus audit years plus international governance, applied to a boutique that competes with giants.
What Paris Gets Right About Security Leadership
The pattern across these seven careers is formation before elevation: audit years, central bank years, consultancy years, then the chair. Paris produces CISOs who can defend a programme to a regulator as fluently as to a board, because most of them have been the auditor. In a city where brand equity is measured in centuries, that conservatism is not caution. It is the business model.
Related reading:
- CISOs to Watch in France’s Entertainment Industry
- CISOs to Watch in France’s Aviation & Aerospace Industry
- CISOs to Watch in France’s Financial Services Industry
- CISOs to Watch in France’s Software Industry
- CISOs to Watch in France’s Real Estate Industry
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

