Title: Securing the World´s biggest HR Firm | Martijn Nykerk, CISO at Randstad | Cyber Security District
Episode Description:
What does it take to secure a company that manages the careers of millions of people across the globe?
In this episode of Cyber Security District, we sit down with Martijn Nykerk, CISO at Randstad, one of the world’s largest HR and recruitment firms, with over 6,000 branches across 38 countries. Martijn has spent 20 years inside Randstad, growing from running the Dutch telco infrastructure to becoming its first global CISO, building security from the ground up as the company transformed from a federation of local operators into a true multinational.
With an engineering background forged on North Sea gas platforms, Martijn brings a rare perspective to the CISO role: the ability to zoom in and out across technical, process, organizational, and business layers simultaneously. In this conversation, he breaks down what that actually looks like in practice, why social skills matter more than most security professionals think and how to build a security function that people want to work with.
In this episode, we explore:
- How Martijn’s career started on a North Sea gas production platform and why safety systems are the original cybersecurity
- What it took to build Randstad’s first global security function from scratch
- The CISO dilemma: centralize or embed?
- How to build a security team people actually want to engage with
- Managing vulnerability backlogs, budget battles, and the patching problem
- The real-world incident that moved cybersecurity from priority 43 to priority 1 overnight
- How AI is lowering the barrier for attackers including 16-year-olds running perfect phishing campaigns
- Why CISO community-building and information sharing matter more than ever
Timestamps:
(00:00) – Introduction
(01:15) – Starting on a North Sea gas platform
(05:30) – Joining Randstad and running the Dutch telco infrastructure
(09:00) – Becoming Randstad’s first global CISO
(14:20) – The “zoom in and zoom out” CISO mindset
(19:45) – What would surprise someone shadowing a CISO for a week
(24:10) – Compliance-heavy vs. risk-driven CISO profiles
(28:30) – Embed vs. centralize: the security team structure debate
(33:00) – How to make security a team people want
(37:15) – Patching, vulnerability backlogs, and the budget war
(42:30) – Building a security narrative that lands with leadership
(46:00) – The incident that changed everything: data breach and crisis response
(53:20) – What makes a great security professional (hint: it’s social skills)
(58:00) – The CISO hiring interview: starting with “What questions do you have for me?”
(01:02:10) – Community building and the 80% overlap problem
(01:07:30) – AI as an attacker accelerant
(01:12:00) – Final message to CISOs: trust each other and share more
Connect with the guest:
Martijn Nykerk: https://www.linkedin.com/in/martijnnykerk/
Follow Cyber Security District: Laurens Jagt on LinkedIn: https://www.linkedin.com/in/laurensjagt/ Website: https://www.cybersecuritydistrict.com/ All channels & newsletter: https://beacons.ai/cybersecuritydistrict