WOODLANDS ADVISORY
All articles
Strategy· 4 min

In conversation with ADAC — the four topics that truly occupy large security organizations in 2026

23 million members. 37 companies. One CISO. Woodlands Advisory spoke with Ümit Kuşdoğan, CISO of ADAC, about the topics that actually move enterprise security in 2026 — AI in security operations, third-party risk with regulated suppliers, regulation arriving in the audit, and AI sovereignty. The common thread: security has arrived in the business. The scarce resource is no longer budget. It is judgment.

The ADAC wordmark in black on a yellow background — the ADAC logo.

23 million members. 37 companies. One CISO.

This week we spoke with Ümit Kuşdoğan, CISO of ADAC, about the topics that truly occupy large security organizations in 2026. Not a meeting about tools, but an exchange about the questions on the table at group level — and those are exactly the questions we work on every day with institutional investors, M&A advisors and growing portfolio companies.

Four points stayed with me. The fourth has the longest half life.

1. AI in security operations

The question is no longer whether AI belongs in vulnerability management. The question is who controls the AI that sets the priorities. This is exactly where pilot separates from paper right now: the difference between an AI that sorts findings and an organization that understands the logic behind the sorting is the difference between acceleration and blind trust.

2. Third-party risk, especially regulated suppliers

A completed questionnaire is not proof of security. Anyone with regulated suppliers in the chain needs assessment by business impact, not by response rate. The question is not "how many assessments came back?" but "which supplier can bring which business process to a standstill?".

3. Regulation has arrived in the audit

External auditors now actively test cyber compliance. That puts the topic firmly where governing bodies carry personal liability, no longer only inside IT. It moves the urgency out of the technology function and into the boardroom.

4. AI sovereignty

The uncomfortable reality: between US providers and China there is currently no third option on equal footing. Whoever adopts AI today decides the data flows of tomorrow. Contracts, policies and documented data flows are the only sovereignty available right now — not the choice of the "right" provider.

The common thread

Security has arrived in the business. The scarce resource is no longer budget. It is judgment — the ability to translate technical risk into robust business and financial impact, and to derive from it the three decisions that actually matter.

That is exactly the difference between a group with millions of members and a portfolio company just before closing: not the "what", but the context, the speed and the consequence of the decision.

This is precisely the intersection Woodlands works at

Cyber due diligence for institutional capital in the DACH region. Private equity, venture capital, family offices and M&A advisors who want to know what they are buying before the transaction — and how to protect it afterwards. Delivered by a curated team of senior practitioners with cloud, identity, AppSec and compliance focus and a structured partner network (including Vanta, Kertos, Aikido) — no outsourcing, no junior substitution.

If you have a specific transaction in mind, or a portfolio mandate where the cyber workstream does not fit the standard DD setup: book a 20-minute intro call. Confidential, on equal footing.

For the deeper argument: The €4M question — how cyber due diligence moves the purchase price.


Thank you for the open conversation, Ümit. More to follow.

Share this article

LinkedInX · Twitter
Woodlands Advisory

Let us discuss your specific situation.

20 minutes. Confidential. Non-binding.

Schedule initial consultation →← Back to all articles