blog

Beyond Data: conversation with Sabika Ishaq, Chief Information Security Officer

Beyond Data: conversation with Sabika Ishaq, Chief Information Security Officer

As organizations move from internal platforms into shared data spaces, cybersecurity no longer ends at the boundary of the company network. It must extend across ecosystems, participants, technologies and jurisdictions, with trust verified through identity, governance, policy enforcement and auditability.

Alexandru Dan from TVL Tech, a member of Ocean Enterprise Collective, is leading a series of conversations with experts across Europe to explore how data spaces are evolving and why they matter for the future of trusted data sharing, cybersecurity, AI and digital sovereignty. Through these interviews, he brings together practical perspectives from professionals working at the intersection of technology, governance and innovation.

In this interview, Sabika Ishaq, a cybersecurity specialist with almost 16 years of experience, explains how data spaces change the security model, what Chief Information Security Officers (CISO) need in order to allow controlled data access, and why misplaced third-party trust may be one of the biggest risks. The conversation also explores the rise of AI agents inside data spaces, the need for intent verification and “digital driving licenses”, and Luxembourg’s opportunity to become a European trust hub for AI-ready digital ecosystems.

I am trying to help people understand what data spaces are, how they work, and what the challenges are. As you are a cybersecurity specialist with very good experience in this area, could you please briefly introduce yourself, your work, and how you became involved with data spaces? It would help us understand your background and how it relates to data spaces.

I would be happy to share my experience. I have been part of cybersecurity for almost 16 years, working in various industries, but largely in the financial regulatory industry space.

Given my experience and my current scope in helping organizations stay abreast of technological changes, data spaces and data management are key aspects of that. One of the things I really emphasize is not only having strong governance in terms of shared data across organizational boundaries, but also building trust and accountability within the governance structure that an organization is looking to implement.

In my opinion, when I talk about data spaces, data spaces show that the perimeter of your defined organizational infrastructure and boundary is disappearing. But if you have accountability and trust in place, accountability cannot disappear.

It has to be there at every level in order for your organization to operate confidently, especially because for most organizations, and specifically in the financial sector, data is your golden asset.

How do you see cybersecurity risks changing when organizations move from internal data platforms to shared data spaces?

Traditionally, cybersecurity has focused on protecting systems within a clearly defined organizational boundary or infrastructure. But data spaces fundamentally change that model. Data is no longer static and confined within an organization. It becomes very dynamic. It is shared across platforms and reused across multiple platforms, jurisdictions and technologies.

The challenge is that trust can no longer be based on ownership of that specific infrastructure within an organization. Instead, trust must be continuously verified through identity and access management, policy enforcement, monitoring mechanisms and strong governance. Strong governance is the key element here, because protecting your trust and accountability requires several layers.

Every participant in that ecosystem, whether it is a human, an application or an AI system, must have a verifiable identity, and access decisions must be tied to very clear business purposes. They should be enforced consistently across the ecosystem of your organization and beyond it.

What concerns me the most is that many organizations are trying to apply yesterday’s security models to tomorrow’s ecosystems. In a data space, the question is not simply whether someone can access your data. The question is whether they are using it in the manner that was originally intended and whether that usage can be proven. Cybersecurity has shifted from just protecting assets to protecting accountability itself.

It needs to create confidence not only between the participants I listed, but also with regulators, clients and society as a whole. I do believe that in a data space, trust is created through transparency and accountability. That accountability comes through the evidence you bring, in terms of immutable audit trails and records of who accessed your data.

What would make a CISO comfortable allowing controlled data access across organizational boundaries and participating in a data space?

For a CISO, the question is trust in terms of making that decision. Trust is not just a feeling; it comes with evidence. The backbone of data sharing across organizational boundaries is a trust framework built on various elements. It is based on identity, transparency, governance, policy enforcement and accountability.

For a CISO, that trust cannot come blindly. A CISO needs verifiable trust. Technology alone is not enough to provide that trust. Organizations must also agree on common principles for data ownership, liability, acceptable use, incident response and regulatory compliance. Without that shared governance layer, even the most sophisticated security technologies will struggle to create confidence for the CISO to take that decision.

From a cybersecurity perspective, or from a CISO perspective, I believe that trust is established when organizations can answer four key questions: Who is requesting that access? What are they allowed to do? Can we verify that they complied with the agreed conditions under which they were provided access? And can we intervene if something goes wrong?

When these capabilities exist, CISOs become far more comfortable allowing data sharing, because they are extending trust in a controlled and measurable way rather than relinquishing control. So, the real backbone of a data space is not just data exchange; it is digital trust. That gives CISOs, or any senior management, the confidence to enable data sharing across organizations.

In a data space, where do you see the biggest risk? We discussed identity, access control, data leakage, third-party risk, supply chain risk, auditability and operational governance. Or, if you see another risk as the biggest one, please share it with us.

Yes. I would say that all of the risks you listed matter. But if I had to choose one, I would say third-party trust. The biggest risk is not technology; it is misplaced trust. I will tell you why.

Organizations typically invest very heavily in securing their own environments. But the moment data enters an ecosystem or supply chain, security becomes dependent on the weakest participant in that supply chain. It becomes dependent on the least mature governance process within that supply chain, and it also becomes dependent on the least transparent technology stack in that supply chain.

As CISOs and cybersecurity professionals, we can correct identity failures and we can update access questions, but when trust failures occur, they have a domino effect. They spread across that ecosystem and can undermine confidence in the entire data-sharing model. That becomes the biggest risk.

That is why governance and assurance frameworks are becoming as important as technical controls. In these interoperable systems and ecosystems that we are establishing through data spaces, the future belongs to ecosystems where participants can independently verify that third-party trust is there, rather than simply assuming it.

So, as I said, the biggest risk is misplaced trust within the ecosystem of your third-party supply chain.

As agents become able to search, negotiate, access and process data in data spaces, what new security risks appear when you allow agents to enter and participate in the data space?

AI introduces huge opportunities, but it also introduces an entirely new category of risk. As you said, AI agents are no longer passive tools. They are becoming active participants in the digital ecosystem and within the decision-making process.

An AI agent may search for data, combine data sets, negotiate access rights and trigger actions, even without direct human intervention in many cases. This creates risks around something that we have spoken about and that the EU AI Act also talks about: risks around manipulation and unintended data disclosure.

What makes this particularly challenging, in my opinion, is the scale at which the risk can affect and have an impact. A human might make one mistake, but when an AI agent makes a mistake in the digital ecosystem where it is operating, it can make the same mistake a thousand times within minutes.

Therefore, we need to move beyond traditional system-behavior assurance and towards intent verification. Rather than only access control, we need intent verification. (…) Imagine an AI agent working in a healthcare data space. Traditional access controls would confirm whether the agent is authentic, whether the agent has permission to access patient records, and whether the request it is making complies with role-based access rules.

But how does it change with the intent verification I spoke about? That raises questions such as: Is the agent accessing the data to support patient treatment or to train another model? Is it combining these data sets in a way that could reveal sensitive information and lead to data leakage? Is the action consistent with the original consent of the patients? And is that request aligned with your regulatory or contractual obligations?

It completely changes the dynamic. The agent may have legitimate access to your data space, but the intended use may not be legitimate. That is why I am saying that the security challenge with bringing in AI agents is evolving from access control to intent verification. Access tells us who can enter the room, but intent tells us what they plan to do once they are inside the room.

What kind of controls will be needed before autonomous or semi-autonomous agents can safely operate in the shared ecosystem? How do we implement this intent verification, access control and identity control for autonomous systems?

I really believe, and I will stand by this phrase, that every AI agent needs a digital driving license. Why do I say that? Because before we grant AI agents meaningful autonomy, we need to have the same safeguards that we would require for humans operating in high-risk environments.

First, agents need not only strong digital identities; every action should also be attributable and auditable. We also need permissions that are granular and dynamic. (…) We will need independent oversight mechanisms, just as we have in healthcare systems and financial systems, where we have controls and approvals.

In the same way, within the AI ecosystem, we would require guardrails that prevent agents from acting outside their mandate. The goal is not to slow down innovation at all. The goal is to ensure that autonomy is earned through accountability and trustworthiness.

This is a challenge for organizations to achieve. I feel that organizations can unlock this challenge through progressive assurance rather than progressive autonomy. (…) They should start with low-risk use cases. They need to establish strong governance through these use cases, establish monitoring mechanisms, and then expand these capabilities incrementally by surrounding them with controls, oversight mechanisms and decision-making processes that work together to make the operation more effective. That is why I am saying they need to earn that license progressively rather than immediately.

What do you think Luxembourg should prioritize if it wants to build trusted data spaces that are also ready for AI and agentic systems, and compliant with European regulation?

Luxembourg has a very unique opportunity because trust is already embedded in its DNA: because of its work in the financial sector, its regulation, its emphasis on building strong governance and resilient operational structures, and its international collaboration.

It has a very unique opportunity. And Luxembourg, I believe, is already leading in this space because it is focusing on the key priorities required to succeed in that space. If I have to choose the top ones, I would say Luxembourg is already working on them.

First, it is developing interoperable trust frameworks that combine cybersecurity, privacy, digital identity and, as I said, governance. Second, it encourages collaboration. I have been part of those working groups where collaboration is encouraged between industry, academia, regulators and technology providers to test emerging AI-enabled data sharing.

So Luxembourg is already on that path. Third, and most importantly, it is investing in skills and talent development, because trusted ecosystems require trusted professionals. Luxembourg can become a trust hub rather than just a data hub, because the next generation of digital competitiveness will not be determined by who has the most data in terms of data spaces.

It will actually be determined by who can create the most trusted environment for sharing and using data responsibly within data spaces. So if Luxembourg gets it right, and it is already on the path to achieving that, it can position itself as a European leader in securing AI-ready digital ecosystems rather than simply being a participant in that ecosystem. So Luxembourg has all the ingredients to succeed in the data spaces ecosystem.