Erich Barlow CITP FBCS
Erich Barlow, MIS, CITP, FBCS, Head of Information Security - Americas, BSI, talks to Grant Powell MBCS about leadership, AI governance, cybersecurity, mentoring and the value of professional recognition. He also reflects on a career dedicated not just to technology, but to advancing the wider IT profession.
From cybersecurity leader to Chartered Fellow: Why professional impact matters
Erich Barlow, MIS, CITP, FBCS, Head of Information Security - Americas, BSI, talks to Grant Powell MBCS about leadership, AI governance, cybersecurity, mentoring and the value of professional recognition. He also reflects on a career dedicated not just to technology, but to advancing the wider IT profession.
For Erich Barlow, Fellowship of BCS represents far more than another credential. As a cybersecurity leader, AI governance specialist, author, mentor and postgraduate researcher, he sees Fellowship as recognition of sustained contribution to the profession and evidence that his work has helped move the IT industry forward. Here, Erich reflects on the role of leadership in a rapidly changing technology landscape, the importance of professionalism and ethics, and why experienced practitioners should never underestimate the impact of their contributions.
Achieving Fellowship of BCS recognises sustained excellence, leadership, and contribution to the profession. What aspects of your career and professional contribution do you feel most strongly demonstrate the standards expected of a Fellow?
Achieving Fellowship is much more than a technical achievement for me. It reflects my commitment to advancing the profession of IT over the course of an 18-year career. I've had the opportunity to lead cybersecurity and digital transformation initiatives across some of the world's largest organisations, helping improve resilience, governance and trust while supporting business objectives. What I'm most proud of, however, extends beyond the workplace.
I've invested heavily in mentoring and professional development, particularly supporting women in technology and cybersecurity. I've also shared knowledge through white papers, books, articles and broader community engagement. One of the most rewarding achievements has been my involvement in developing a master’s degree in AI programme at a U.S. university, helping to create a solid foundation for future AI professionals.
For me, Fellowship is not simply about demonstrating what you've achieved personally. It's about showing how you've influenced the profession itself, how you've helped other practitioners grow, and how you've contributed to advancing the wider IT community.
Your work sits at the intersection of cybersecurity, AI governance, and enterprise transformation. How has that experience shaped your view of leadership in today's technology landscape?
Modern technology leadership is fundamentally about managing change and uncertainty. The pace of innovation, particularly in AI, means leaders can no longer focus solely on technology. We have to understand risk, governance, ethics, regulation and organisational culture, and how those elements interact with one another. Leaders today need to be adaptable. The regulatory environment changes constantly, especially in global organisations where different regions have different requirements and expectations. It's not enough to establish a process and assume it will remain relevant indefinitely.
One lesson I've learned from senior leaders I greatly respect is that nobody can be an expert in everything. Effective leaders rely on specialists, listen to expertise and encourage collaboration. Leadership is increasingly about bringing together different perspectives and helping teams navigate complexity rather than trying to have all the answers yourself.
You also have to think ahead. We're already discussing quantum computing and preparing for challenges that may emerge in the future. Organisations that wait until change arrives are already behind.
You are also a Chartered IT Professional. What does this mean to you, and why is professionalism so important within the IT and security industries?
Becoming a Chartered IT Professional represents validation of both technical competence and professional accountability. It shows that I've met a recognised standard and that I remain committed to continued professional development and ethical practice. It isn't simply about passing a test. It demonstrates that somebody has evaluated my work and the way I’ve applied knowledge in practice.
Professionalism has become even more important as AI becomes increasingly embedded in business processes and decision-making. Questions around data use, privacy, ethics and governance arise constantly.
I've been involved in conversations where we've had to ask difficult questions about data usage, permissions and ethical responsibility. Having a strong professional foundation helps guide those decisions. As technology becomes more powerful and more influential, society needs professionals who understand not only what can be done, but what should be done.
You are recognised for helping organisations adopt AI securely and responsibly. How do you approach balancing innovation with risk management?
I don't see innovation and risk management as competing priorities. In fact, effective risk management is often what enables innovation. When organisations have confidence that appropriate controls, governance and oversight are in place, they become more willing to embrace new technologies.
My approach always begins with the intended business outcome rather than the technology itself. From there, I work with stakeholders to identify risks, establish governance controls, assess the trustworthiness of AI systems and ensure transparency and accountability throughout the development lifecycle.
AI development can be challenging because you're often assessing risk while the technology itself is still evolving. It requires careful consideration and ongoing evaluation. The goal is not to eliminate risk entirely. The goal is to manage it in a way that enables organisations to innovate safely and responsibly.
Throughout your career you have led significant transformation projects. What lessons have you learned about building resilient organisations?
One of the biggest lessons I've learned is that technology professionals need to speak the language of business. Cybersecurity and technology teams often understand the technical issues perfectly, but success depends on translating those issues into business outcomes and business value. Earlier in my career, technology often sat in the background. Today, organisations depend on technology to deliver services, drive innovation and enable growth. That's reflected in the rise of CIOs, CTOs and CISOs at the executive level.
Building resilience is ultimately about relationships, communication and trust. Technical controls are important, but organisations become resilient when people understand why those controls matter and how they support broader business goals.
Technology has become a catalyst for organisational change. We're not simply implementing tools anymore. We're helping organisations rethink how they operate, how employees work and how they prepare for the future.
Your role requires engagement with both highly technical specialists and senior executives. How do you bridge those different worlds?
The technical conversations are often the easier ones because we share a common language and similar perspectives. The challenge comes when translating technical concepts into business terms that support decision making. Senior executives don't necessarily need every technical detail. They need information presented in a way that helps them understand implications, opportunities and risks.
My role is to provide decision-makers with the information they need while remaining objective. I need to explain the options, answer difficult questions and ensure leaders understand the potential outcomes of their choices.
It's a skill that develops over time. Sometimes you get it right; sometimes you get it wrong. But when you explain a complex issue in a way that suddenly makes sense to an executive audience, you can actually see the moment of understanding. That's when real progress happens.
Fellows are often viewed as role models within the profession. How do you believe experienced practitioners should contribute to the future of cybersecurity and AI governance?
Experienced professionals have a responsibility to share knowledge, mentor others and uphold professional standards. When I became a Fellow, I immediately found that more people were reaching out for advice, mentorship and sponsorship. That visibility brings responsibility. People begin looking to you as a role model, whether through your writing, professional engagements or public presence. You have to think carefully about how you represent yourself and the profession.
In cybersecurity and AI governance, this is especially important because the technologies are evolving so rapidly. We need experienced practitioners who are willing to have conversations, support newer professionals and help shape best practice. The future of these disciplines will be determined not only by technology, but by the people who guide its responsible adoption.
Reflecting on your own journey, what advice would you offer experienced professionals who may be considering BCS Fellowship but underestimate the significance of their contribution?
I think many experienced professionals suffer from imposter syndrome. I certainly did. When I first considered Fellowship, I thought it was something achieved by other people, not me. It took time to recognise the true scale of my own contributions.
One of the most important things I learned is that Fellowship is not simply about listing accomplishments. It's about understanding your impact. Many applicants can point to excellent work delivered as part of a team. Fellowship asks a different question: what have you personally done that has advanced the profession?
For me, that included developing an AI master's programme, mentoring professionals, writing books and publishing white papers. Those activities created impact beyond my employer and beyond my immediate role.
My advice is simple: take the time to reflect on your career. Look beyond your job description and consider how you've influenced people, projects and the profession itself. You may discover that your contributions are far more significant than you realise.
Fellowship changed the way I view my own career. It gave me confidence, opened new opportunities and connected me with a wider professional community. If you've made a meaningful contribution to the profession, don't assume you're not ready. You may be closer than you think.
Become a BCS Fellow
Join the tech industry's most influential professionals in shaping a diverse, ethical, safe and innovative future.
TESTIMONIALS
What our members say
Being a fellow of the BCS is all about giving back, whether through thought leadership to influence and help shape the digital world or by helping nurture the next generation of IT digital professionals.
Rubi Kaur FBCS
I believe that the more diverse the voices within BCS and the IT sector the better for all of society. As a BCS Fellow I have the opportunity to raise the profile of our policy work and ensure that all voices are represented.
Rachel Steenson FBCS
The hallmark of professionalism is responsibility with accountability underpinned by competence and strong ethical disposition. These, invariably, are the intrinsic values exceptionally nurtured and exemplified by BCS.
Richard Amafonye FBCS
Honoured and chuffed to have been accepted as a BCS Fellow! Thank you for the warm welcome BCS, excited about getting involved and helping to ‘pay forward’...
Hema Purohit FBCS