We Go Phishing with Michelle Tolmay, Chief Information Security Officer at Kaluza to find out why she pursued a career in technology – and her team management strategy
What would you describe as your most memorable achievement?
From a leadership perspective, mentoring others, especially women and underrepresented groups, and seeing them step into leadership roles has been incredibly fulfilling. From a technology standpoint, leading the full separation of Kaluza’s tech stack from our former parent company was a significant milestone. It’s empowered us to move faster and more efficiently as a business.

What first made you think of a career in technology?
I’ve always been curious about how things work – one of my earliest memories is taking apart the family VCR (and successfully putting it back together!). Once I started working in tech, I realised how much I loved helping people shift their view of technology, from something intimidating to something empowering.
What style of management philosophy do you employ in your current position?
I tailor my approach depending on the person and where they are in their career. I believe people do their best work when they feel safe, valued, and supported. I also lean into transformational leadership, encouraging continuous growth, curiosity and improvement for both the team and the business.
What do you think is the current hot talking point within the data centre space?
The impact of AI is front and centre. AI workloads, especially LLMs, are driving huge demand for power and advanced infrastructure, pushing data centres to evolve rapidly. There’s mounting pressure to reduce environmental impact, improve energy efficiency, and adopt smart, sustainable practices. Regulation is catching up too, adding urgency for operators to act.
How do you deal with stress and unwind outside the office?
My allotment is my outdoor sanctuary. It’s a place where I can disconnect and recharge by being close to nature. When the weather doesn’t cooperate, I turn to Lego. Whether following detailed instructions or creating my own designs, it’s a mindful and absorbing way to reset.
What do you currently identify as the major areas of investment in your industry?
Operational Technology (OT) security is a major area of investment, especially in critical sectors like energy, as IT and OT systems become more connected. Many OT environments, like SCADA networks and substations, were never designed with cybersecurity in mind, making them vulnerable to attacks with real-world consequences. Organisations are shifting from reactive measures to proactive strategies, investing in visibility tools, network segmentation, virtual patching, and secure remote access. With growing regulatory pressure from frameworks like NIS2 and the UK’s Cyber Assessment Framework, companies are also focusing on compliance, resilience, and integrated OT/IT security operations. As cyber-physical systems play a larger role in energy infrastructure, securing them is no longer optional. It’s essential to business continuity and public trust.
What are the region-specific challenges you encounter in your role?
In the UK, navigating a fast-moving regulatory landscape, while also aligning with evolving EU directives, is a constant challenge. There’s also rising cyber risk to critical infrastructure, talent shortages in key areas like OT security, and the need to communicate cyber risk clearly at board level. Supply chain threats and ransomware tactics like double extortion remain top concerns.
What changes to your job role have you seen in the last year and how do you see these developing in the coming months?
The CISO role has broadened well beyond traditional cybersecurity. We’re increasingly involved in business resilience, tech strategy, and risk governance. There’s a stronger recognition now that cyber risk is business risk, and we need to help shape strategy, not just protect it.


