#JudgesOnFire with Jukka Seppänen, CIO and CISO at UpCloud Judges Judges on Fire On Fire Podcasts Posted by rax lakhani | 11/08/2026 What happens when the person responsible for keeping cloud operations running is also responsible for keeping them secure? In this episode of Judges on Fire, Tech Trailblazers Awards founder and Chief Trailblazer Rose Ross sits down with new judging panel member Jukka Seppänen, CIO and CISO at European cloud infrastructure provider UpCloud (LinkedIn). From balancing operational resilience with cyber risk to securing a new generation of autonomous AI agents, Jukka brings a distinctly practical perspective to technology leadership. He also has some forthright advice for startups hoping to impress the Tech Trailblazers judging panel: forget the buzzwords, show us what your technology actually does and prove that customers genuinely benefit from it. Headquartered in Helsinki, UpCloud operates 15 data centres across 12 countries, including ten data centres in Europe, and positions itself as a European sovereign cloud provider supporting customers across four continents. For Jukka, that makes questions around operational reliability, cybersecurity, AI and European digital sovereignty very real indeed. Wearing two hats: CIO and CISO Jukka holds two roles that are sometimes treated as being on opposing sides of the technology conversation. As CIO, his focus includes ensuring technology can be operated reliably, efficiently and at scale. As CISO, he must look at many of those same systems through the lens of security, risk and governance. Rather than seeing those responsibilities as conflicting, Jukka believes there is considerable value in bringing them together. Security controls do not exist in isolation. They eventually have to operate inside real production environments, alongside customers, developers, operational teams and business requirements. That means the questions asked by a CIO and CISO should ultimately converge. Can we operate it? Can we secure it? Can we recover it? Can we scale it? And can people actually use the controls we are putting in place? It gives Jukka an unusually broad perspective as he joins the Tech Trailblazers judging panel, particularly when evaluating companies working across the Cloud Trailblazers Award and Security Trailblazers Award categories. Security has to work in the real world One of the strongest themes to emerge from Rose and Jukka’s conversation is the difference between a security control that sounds good on paper and one that actually works in production. A theoretically perfect security policy is of little value if it creates so much operational friction that people bypass it, switch it off or cannot reliably maintain it. The challenge for security teams is therefore not simply to identify the strongest possible control. It is to design controls that deliver meaningful risk reduction while still enabling the organisation to function. For a cloud provider, that becomes particularly important. Customers expect infrastructure to be secure, but they also expect it to remain available, responsive and manageable. Security architecture therefore has to account for operational reality from the outset rather than being layered onto services afterwards. It is a perspective that Jukka believes technology startups should understand too. Innovation needs to solve the problem that exists in the customer’s real environment, not merely demonstrate that something can work in a laboratory or proof of concept. AI changes the security equation Artificial intelligence inevitably enters the conversation, but Jukka approaches AI security with considerably less hype than is sometimes seen around the subject. One of the key mistakes organisations can make is assuming that instructions contained within a prompt constitute a meaningful security boundary. They do not. If an AI agent can access an important system, dataset or application, organisations need to think about that access using many of the same fundamental security principles they would apply to a human user or software service. That means identity, authentication and minimum necessary permissions. An AI agent should have its own identifiable access rather than inheriting broad privileges simply because the human using it has those privileges. It should only be able to access the systems and information required to complete its particular task. And organisations need to consider what happens if an agent behaves unexpectedly, misinterprets an instruction or is manipulated through techniques such as prompt injection. For companies entering the AI Trailblazers Award, it is a useful reminder that genuinely innovative AI technology increasingly needs to demonstrate how security and governance have been designed into the proposition as well as what the underlying model can do. When AI finds the bugs Generative AI is changing another corner of cybersecurity too: vulnerability discovery. Jukka discusses how AI-driven automation is already influencing bug bounty programmes by making it dramatically easier to generate and submit potential vulnerability reports at scale. That can have positive consequences. More people can investigate applications, security researchers can automate repetitive work, and previously overlooked vulnerabilities may be identified more quickly. But quantity does not necessarily mean quality. If AI systems begin producing large numbers of low-value, duplicated or poorly understood reports, security teams must still determine which findings represent genuine risks and which simply add noise. The development illustrates a much wider issue surrounding AI. Automation can dramatically increase the speed at which work is produced, but organisations still need systems for determining whether that output is useful, accurate and actionable. For cybersecurity teams, AI therefore potentially strengthens both sides of the equation. Attackers gain new automation capabilities. Defenders gain them too. The competitive advantage comes from how intelligently organisations deploy them. What does European digital sovereignty really mean? UpCloud’s position as a Helsinki-headquartered European infrastructure provider also gives Jukka a particularly interesting perspective on digital sovereignty. UpCloud describes itself as a European sovereign cloud provider and currently operates 15 data centres in 12 countries, with facilities spanning Europe, North America, Asia and Australia. But sovereignty, in Jukka’s view, should not mean building isolated digital fortresses. Finland offers an interesting perspective. It is a relatively small country with a highly digital economy and society. That means resilience cannot realistically depend on doing everything independently. Instead, genuine sovereignty can come from having dependable choices, strong domestic and European capabilities, trusted partners and the ability to work collaboratively across friendly nations. It is less about isolation and more about avoiding dependencies that an organisation, business or country cannot control. That conversation has become increasingly important as governments and enterprises examine where their data resides, which jurisdictions ultimately govern their technology suppliers and how resilient critical digital infrastructure would be during a geopolitical or commercial disruption. UpCloud has itself increasingly emphasised European sovereignty as a core part of its infrastructure proposition. So, what will Jukka be looking for from Tech Trailblazers entrants? For any startup preparing its Tech Trailblazers submission, this may be the most important part of the podcast. Jukka isn’t looking for the greatest number of fashionable technology phrases. In fact, overusing them may have precisely the opposite effect. Terms such as: AI-powered. Next-generation. Built for the cloud. …mean very little unless an entrant can explain what the technology actually achieves. Instead, Jukka wants to understand the outcome. What problem are you solving? Who has that problem? How does your technology solve it differently or better? And what evidence can you provide that it works? That evidence could come from real deployments, measurable performance improvements, customer results, reductions in cost or risk, increased productivity or another demonstrable business outcome. The message is simple: don’t make the judges decode your marketing copy to discover why your company matters. Tell them. And then prove it. Technology first. Buzzwords second. There is a wider lesson here for startups. In highly competitive technology markets, founders understandably want to position their products alongside the biggest emerging trends. AI. Cloud. Cybersecurity. Automation. Sovereignty. All may be entirely relevant. But the technology needs to stand up without the labels. Jukka’s advice echoes something that comes up repeatedly in conversations with the Tech Trailblazers judging community: clarity is powerful. A straightforward explanation of a genuine customer problem, an innovative solution and measurable evidence is likely to tell an experienced technology judge considerably more than a paragraph filled with fashionable terminology. And as somebody responsible for cloud operations, IT and security in a live global infrastructure business, Jukka is particularly interested in the point where innovation meets reality. Does it work? Does it scale? Does it make something demonstrably better? That is where a Trailblazer begins to stand out. Tune in to hear Jukka Seppänen discuss what it really means to combine the roles of CIO and CISO, why security controls have to survive contact with operational reality, how organisations should rethink access controls for AI agents, and what European digital sovereignty looks like from the perspective of a Finnish cloud provider. And, if you’re preparing a Tech Trailblazers entry, listen carefully to his advice on what separates meaningful innovation from marketing noise. Listen to Judges on Fire with Jukka Seppänen WATCH ON YOUTUBE – https://youtu.be/nZH7FBqLQco?si=LkMZTspKjcm6Pyr6 LISTEN ON SPOTIFY – https://open.spotify.com/episode/0PsHfHRCf262iOjS4cByrx?si=5257d0717c6f4d86 Could your technology impress Jukka and the Tech Trailblazers judges? Jukka joins an international Tech Trailblazers judging panel bringing together experienced CIOs, CISOs, CTOs, analysts, investors, journalists, entrepreneurs and other senior technology specialists. Jukka is currently listed as a judge representing UpCloud on the Tech Trailblazers website. If you’re building innovative enterprise technology, explore the categories most closely connected with the themes covered in this episode: Cloud Trailblazers AwardFor innovative startups developing cloud technologies, services and infrastructure for enterprise customers. Security Trailblazers AwardFor startups developing innovative technologies that help enterprises tackle cybersecurity challenges. AI Trailblazers AwardFor startups applying artificial intelligence in innovative enterprise products and services. Whether you are transforming cloud infrastructure, developing new approaches to cybersecurity, applying AI to a difficult enterprise problem or creating something the market has not seen before, show the judges the problem, the innovation and the evidence. Explore all Tech Trailblazers Awards categories Stay in touch with Tech Trailblazers Email us at innovate@techtrailblazers.com Meet the Tech Trailblazers judges Follow Tech Trailblazers on LinkedIn Visit UpCloud Follow UpCloud on LinkedIn Connect with Jukka Seppänen on LinkedIn