From dismantling an AM radio at age two to discovering “where that voice came from,” Rui Shantilal, new VP of Devoteam Cyber Trust, has always been driven by a need to understand how things work. This early curiosity bloomed into a career in cybersecurity, leading to key roles in major Portuguese telecommunications and IT organisations before co-founding Integrity in 2009. A technology enthusiast and entrepreneur thrilled by challenges, Rui brings over 25 years of experience, multiple industry certifications (CISSP, CISA, ISO 27001 LA), and an MSc in Information Security to his new role.
He has been appointed the new VP of Devoteam Cyber Trust, Devoteam’s specialised cybersecurity unit. With a focus on resilience-driven cybersecurity, leveraging AI and cloud security, he will position Devoteam as an industry leader. His client-focused approach ensures innovative solutions that align with business goals. In this interview, Rui Shantilal shares his vision for Devoteam’s future, strategies for using AI effectively, and insights on navigating an evolving threat landscape. Join us as we explore the mind of a cybersecurity pioneer committed to building a safer digital world.
What is your vision for the future of cybersecurity at Devoteam, and how do you plan to align it with the new Amplify strategy?
My vision is to position Devoteam as a leader in resilience-driven cybersecurity, ensuring our clients can navigate an increasingly complex digital landscape. Cybersecurity today is not just about protection; it is a business enabler that fosters trust, compliance, and growth. Additionally, I envision Devoteam as a global partner capable of supporting our clients across all our geographies, ensuring seamless cybersecurity services wherever they operate.
To align with the Amplify strategy, we will:
- Scale strategic offers such as GRC, Digital Identity, Offensive and Cloud Security reinforce our existing Security Operations Center (SOC) capabilities and strategically strengthen our Incident Response services to provide even greater resilience and support for our clients.
- To provide a truly seamless experience for our clients, no matter where they are in the world. We’ll achieve this by using consistent methods across all our locations, ensuring everyone gets the same high-quality service. We’re also investing in AI to help us make better decisions about delivering our services, managing our operations, and staying ahead of cyber threats. This will allow us to continuously improve and provide the best possible service to our clients.
- Drive thought leadership through the Alert Readiness Framework (ARF), positioning it as a global standard for resilience.
- Develop scalable talent academies to ensure we have the right skills and expertise to support our growth and market expansion.
Innovation must be purpose-driven. My vision is that there is no progress without risk.

Rui Shantilal
Devoteam Cyber Trust Vice President
AI in Cybersecurity
What strategies will you implement to leverage AI to enhance our cybersecurity offerings while mitigating potential risks, such as AI-driven threats?
AI is a double-edged sword in cybersecurity. While it enhances threat detection, automation, compliance, training, and other key areas, it also introduces new risks, such as AI-powered attacks. Our strategy includes:
- Leveraging AI for cybersecurity defence: Implementing AI-driven threat intelligence, anomaly detection, and compliance automation. For example, we have been actively testing chatbots, including social engineering attacks targeting AI models, to evaluate and enhance their resilience to assess their security posture within Offensive Security engagements.
- Mitigating AI-driven threats: Developing AI security frameworks that ensure model integrity and resilience against adversarial attacks.
- AI Governance & Compliance: Helping clients navigate AI-related regulations like the EU AI Act, ensuring ethical and secure AI implementations.
How can Devoteam help clients navigate the ethical and regulatory challenges associated with AI in cybersecurity?
With the EU AI Act, ISO 42001, and other regulatory frameworks emerging, we will assist clients by:
- Implementing AI risk management models that align with compliance requirements.
- Offering AI governance consulting to ensure transparency, accountability, and explainability.
- Embedding security-by-design principles in AI-driven cybersecurity solutions.
A Client-Centric Approach
How will you balance innovation in cybersecurity with the need to provide practical, actionable solutions for clients?
Innovation must be purpose-driven. My vision is that there is no progress without risk. The key is effective risk management—evaluating cost vs. benefit while maintaining momentum. We must drive cybersecurity innovation at a strong pace, while ensuring solutions remain practical and beneficial.
I have applied this throughout my career, launching notable and innovative services like Keep-it-Secure-24 in 2013, the first persistent PenTesting service, and, more recently, the Alert Readiness Framework (ARF).
Our approach follows three key pillars:
- Business Alignment: Ensuring cybersecurity solutions support business objectives rather than becoming barriers.
- Scalability and Modularity: Structuring our cybersecurity services to be adaptable and progressive, allowing clients to integrate new security capabilities at their own pace.
- Global Expertise, Local Adaptation: Leveraging cross-border collaboration to provide best-in-class, yet locally relevant, cybersecurity solutions. Additionally, we believe that true innovation comes from deeply understanding market needs—listening to our clients, identifying their pain points, and tailoring solutions that address real-world challenges.
Risk Management and Resilience
How will you approach risk management in cybersecurity, especially with the increasing sophistication of cyberattacks?
Risk management must be proactive and dynamic, moving beyond traditional periodic assessments. While integrating security by design is a substantial risk management approach, it is not enough. My mindset is to leverage our approach with our innovative Alert Readiness Framework (ARF), ensuring that organisations continuously evaluate risk in real-time rather than relying on static controls or annual risk reviews.
The ARF has already been presented to over 250 CISOs, including during the Gartner conference in London last year, and is actively being implemented in key organisations. It is our strategic bet for gaining traction in the market. The framework is designed to engage all relevant stakeholders and dynamically represent an organisation’s risk posture using a combined quantitative and qualitative approach.
Instead of a rigid, checklist-driven security approach, ARF ensures that controls remain adaptive and context-aware. This means organisations can adjust their security measures in response to evolving threats and business needs.
For example, in moments of heightened risk, we implement RTP (Reduce the Probability) and RTI (Reduce the Impact) controls to minimise exposure. However, in times of lower risk, security controls can be optimised to reduce operational inefficiencies. Imagine if a house locked with FIVE locks every day—this would be inefficient during typical day to day but essential during high-threat periods. ARF brings this adaptability into cybersecurity, enabling businesses to balance resilience and flexibility.
This mindset shift is crucial because security today must align with business agility. We cannot afford static defences in a dynamic threat landscape—our goal is to provide cybersecurity that supports, rather than hinders, business growth and operational efficiency.
How will you address the growing challenge of securing hybrid and multi-cloud environments?
Cloud security is non-negotiable in today’s landscape. Our approach involves:
- Cloud-native security strategies, ensuring compliance with industry frameworks like NIST, CIS, and ISO27001.
- AI-powered monitoring for real-time detection of misconfigurations and threats across hybrid environments.
- Identity Threat Detection & Response (ITDR) to secure non-human identities in cloud and DevSecOps ecosystems.
- Leveraging our strong partnerships with the three largest cloud providers, where we bring deep expertise not only in cloud operations but also in security best practices, ensuring that we maximise the use of native cloud security features while maintaining robust protection across environments.
Thought Leadership and Market Positioning
What trends or technologies in cybersecurity do you believe are currently underhyped but will have a significant impact in the near future?
I believe that as defensive technologies continue to evolve by leveraging AI, the human attack vector will become even more critical. Attackers will increasingly shift towards exploiting human vulnerabilities—such as social engineering, phishing, and insider threats—since automated defences will be harder to bypass. Therefore, the focus on human-centric security strategies, behavioural analytics, and adaptive awareness programs will be essential.
Several cybersecurity trends are currently underappreciated but will have a significant impact in the coming years:
- Non-Human Identity (NHI) Security: As automation increases, securing machine identities and service accounts is becoming critical.
- AI-driven Cyber Risk Quantification: Moving from qualitative assessments to data-driven risk scoring will enhance decision-making.
- Security of AI Models: Ensuring AI models themselves are secure against adversarial attacks and data poisoning.
- Regulatory-driven Cybersecurity: Compliance automation will be a game-changer as frameworks like NIS2, DORA, and the EU AI Act take effect.
Personal Leadership Style
What was the most challenging security crisis you’ve managed? What key lessons did you learn from that experience?
One of the most challenging security crises I managed was during the Nimda attack, which impacted a major bank with hundreds of branches, ultimately affecting several thousands of customers.
The key lesson I learned in that moment was that there is a lot of noise during a crisis, and the ability to cut through the noise and focus on the core issue is crucial. When I arrived at the incident response scenario, I found dozens of people in a meeting discussing the problem. Yet, no one had taken the critical step of capturing network traffic for diagnosis. My immediate action was to visit the nearest branch to the bank’s headquarters, where I could analyse what was happening firsthand. By understanding how the attack was propagating, we could design an effective recovery plan and bring the bank back to operational status.
This experience reinforced the fundamentals of crisis management: maintaining focus, following structured processes, and ensuring proper preparation—including public relations, communication, incident response processes, and technical readiness.
What excites you most about this new role, and what do you hope to achieve in your first year as VP of the Cyber Trust Business Unit at Devoteam?
What excites me most is that I am deeply passionate about cybersecurity and entrepreneurship, and now I can practice both on a much larger scale than ever before. Having founded and led Integrity, which was acquired by Devoteam in 2021, I now have the platform to expand that impact across multiple regions.
I have always believed that doing the right thing, the right way, with the right people leads to excellent results over time. Now, being able to apply this philosophy at a larger scale is truly exciting. More than anything, I look forward to working with talented, passionate professionals, driving excellence, and creating tangible value for our clients. Contributing to a safer digital world is a noble mission that I fully embrace.
My first-year priorities include:
- Strengthening Devoteam’s leadership in EMEA by scaling key offerings like GRC, Digital Identity, Offensive and Cloud Security
- Provide a truly seamless experience for our clients, no matter where they are in the world, ensuring we operate as a unified force rather than isolated regional units.
- Elevating Devoteam’s thought leadership in cybersecurity, making ARF and AI-driven cybersecurity solutions industry benchmarks.
- Expanding talent pipelines through academies that build the next generation of cybersecurity professionals.
Secure AI, Sustainable Value: Your CISO’s Guide to AI Risk Management

Get your free Whitepaper if you want to:
- Learn to identify and manage unique AI security challenges
- Implement Devoteam’s AI Cyber Trust Cube – our framework for trusted and secure AI deployments
- Align AI with your organisation’s sustainability goals
- Gain insights from Devoteam’s leading AI security experts.

