Roman Rafiq, Co-Founder of Axionis Global, discusses why security and risk transformation must move beyond compliance, how organisations can embed governance into business decisions, and the leadership skills needed to navigate an evolving threat landscape.
Summarize the business model of your enterprise and your job role?
Axionis Global is a technology advisory firm that embeds senior IT leadership into mid-sized organisations that either can’t justify a full-time CIO or need a seasoned hand during periods of transition or growth. My clients are largely ITeS companies background verification, BPO, managed services typically in the 200 to 2,000 employee range. I operate as a Fractional CIO across a portfolio of engagements simultaneously, which means I’m setting IT strategy, governing vendors, driving digital and AI transformation, and increasingly, anchoring cybersecurity governance all without the overhead of a permanent hire. It’s advisory with skin in the game.
Describe the significance of security and risk transformation for your enterprise?
For mid-sized ITeS firms, security isn’t a back-office function anymore it’s existential. Most of my clients handle sensitive third-party data: employee records, financial documents, identity credentials. A single breach doesn’t just cause regulatory exposure; it unravels client trust, which is the entire basis of the ITeS business model.
What I’ve seen consistently is that these organisations have historically treated security as a compliance checkbox annual audits, a firewall, an AV licence. That’s no longer adequate. The threat surface has expanded with remote work, SaaS proliferation, and AI-assisted phishing. Meanwhile, regulatory pressure particularly around India’s DPDPA 2023 is forcing a rethink.
Security and risk transformation, to me, means shifting from reactive to structured: building a risk register that the board actually sees, embedding controls into procurement and vendor onboarding, and making security a conversation that happens in the boardroom, not just the server room. That cultural shift is as important as any technology investment.
Security isn’t a back-office function anymore — it’s existential.
What aspects of your job role drive security and risk transformation?
Because I sit at the intersection of technology and business strategy, I can translate risk into business language which is often the hardest part. I’m not selling fear; I’m helping the CEO or COO understand that a poorly configured cloud environment or an unvetted third-party API is a liability on their balance sheet. I’m also in the room when vendor contracts are signed, when new SaaS tools are onboarded, and when expansion plans are drawn up which gives me natural checkpoints to embed security considerations early rather than retrofitting them later. That positioning is something a standalone CISO often doesn’t have.
Describe the security and risk platforms and technologies being used across your enterprise?
Across my client engagements, the stack varies with maturity, but there are common patterns. Most organisations are on Microsoft 365, so we leverage the built-in security tooling aggressively Defender for Endpoint, Conditional Access via Entra ID, and Purview for data classification. For smaller clients, this alone represents a significant step up.
Beyond Microsoft’s ecosystem, I see adoption of SIEM-lite tools like Microsoft Sentinel for log aggregation, Qualys or Tenable for vulnerability management, and CrowdStrike or SentinelOne for EDR where budget allows. Network perimeter security has largely moved to cloud-delivered ZTNA models Zscaler features in a couple of engagements.
On the GRC side, we use a mix of structured Excel frameworks and tools like OneTrust or ServiceNow GRC for clients with more mature programmes. The honest reality is that at the mid-market level, tooling decisions are heavily budget-constrained, so my job is often to extract maximum security value from what’s already licensed rather than proposing net-new spend. Rationalisation before consolidation, as I put it to clients.
Business becomes an advocate rather than a resistor.
How does the cybersecurity team work with the business?
In most of my client organisations, there isn’t a dedicated SecOps team there’s an IT manager or a small IT team wearing the security hat alongside everything else. So the interaction model is less about SOC-to- business than it is about IT-to-business.
The positive is that in mid-sized firms, decision-making cycles are shorter. When I flag a risk to the CEO or the COO, I typically get a response within days, not weeks. There’s no committee bureaucracy.
The challenge is cultural and bandwidth- driven. Business teams see security controls as friction MFA prompts, access restrictions, approval workflows and in a growth-oriented ITeS environment where speed is everything, that friction breeds workarounds.
I’ve seen shadow IT emerge simply because the procurement process for a new SaaS tool was too slow. What works is framing security as a client assurance conversation rather than an internal IT compliance one. When you tell a sales team that a solid security posture helps win enterprise RFPs, the dynamic changes entirely. The business becomes an advocate rather than a resistor.
Which aspects of your role drive job satisfaction, and which are challenging?
The satisfaction comes from impact velocity. As a Fractional CIO, I can walk into an organisation, identify the three things that actually matter, and move on them within weeks. There’s no political accumulation I’m brought in for outcomes. When a client closes a large enterprise account partly because they passed a security audit for the first time, that’s tangible.
The challenge is context-switching at scale. Managing five or six engagements simultaneously means I’m never able to go as deep as I’d like on any single one. There are days when I’m in a board discussion about cloud strategy in the morning and troubleshooting an incident response process for a different client in the afternoon. Mental load management is a real skill in this model.
What skills are required currently, and how will they change?
Right now the role demands a broad but credible technology literacy cloud architecture, security governance, vendor management, data privacy regulation combined with the ability to communicate strategy to non-technical leadership. Stakeholder influence is probably the most underrated skill in this role.
Going forward, AI literacy will become non-negotiable. Not just knowing AI tools exist, but understanding how AI changes the risk surface deepfake-assisted social engineering, AI-accelerated vulnerability discovery, and the governance challenges around LLMs handling sensitive enterprise data. I’m already having DPDPA and AI governance conversations with clients that didn’t exist two years ago. That’s the direction.
How do you see your career progressing over the next five years?
Honestly, I see Axionis Global evolving into something broader than a one-person advisory practice. The Fractional CIO model has strong demand at the mid-market level in India, and I’m working towards building a small team of senior practitioners operating under the Axionis umbrella. Five years from now, I’d like to be running a firm that advises and builds, rather than just one or the other.




