CIO: 5 Mistakes

that hinder your low-carbon Strategy
insights

We’ve already lived through digital sustainability. It was called cybersecurity.

Data centers already account for nearly half of our IT footprint. AI could drive their energy consumption up by 15% to 50% by 2030. And in none of the executive committees I’ve sat in has anyone actually been accountable for that number.

We are repeating, one by one, the mistakes it took us ten years to correct in cybersecurity. I made them. You are probably making two or three of them yourself. Here are five.

Mistake #1 - We respond with awareness campaigns

I funded awareness workshops. A poster, an e-learning course, a policy signed by everyone and read by no one. It costs nothing and disrupts no one, which is precisely why it doesn’t work.

Cybersecurity wasted years on anti-phishing campaigns before realizing that a trained employee can never compensate for a server that has never been patched.

Carbon has the same problem, only worse: here, it isn’t even a question of individual behavior. It’s a question of architecture that no one has ever asked the teams to change.

It’s a question of architecture that no one has ever asked the teams to change.

Mistake #2 - We set a trajectory without measuring the starting point

We announce a target: 30% less by 2030, for example – without ever measuring where we are starting from.

That isn’t a strategy. It’s wishful thinking dressed up as a target.

I’ve seen it in executive meetings: no one asks the uncomfortable question, “Compared with what?”, because no one wants to hear the answer.

No one asks the question “Compared with what” because no one wants to hear the answer.

Mistake #3 - We pile up best practices without ever quantifying their impact

Eco-design, responsible cloud, more sustainable usage: initiatives are launched, but no one measures what they actually deliver.

A year later, there is zero evidence of progress.

The budget line gets cut at the first round of trade-offs, and frankly, it deserves to be cut: you cannot keep funding something indefinitely if you cannot prove what it delivers.

Mistake #4 - We optimize the run and ignore the build

We fix the consumption of a service in production, but never the architecture that made that consumption necessary.

It’s more comfortable that way: it shows up on a FinOps dashboard and doesn’t call into question any decision made three years ago by someone who probably isn’t even there anymore.

The run can be fixed every year.

The build never gets fixed, it keeps running exactly as we allowed it to drift.

Mistake #5 - We rush into AI without measuring its trajectory

We accelerate AI without a single metric tracking what it is costing us in carbon. Not out of ill will — out of speed.

The innovation pillar moves faster than the governance pillar, as it always does, and no one dares slow the first one down long enough to put the second one in place.

We manage speed, never impact. And in two years, we’ll discover the bill at the same time as everyone else.

What these 5 mistakes have in common: They allow us to say we are doing something about the issue without ever touching what would actually be expensive to change — architecture, governance, budget.

It’s comfortable.
It is also exactly what cybersecurity used to do before it stopped telling itself stories.
An awareness workshop has never prevented a data breach.
It won’t prevent a carbon footprint from doubling either.

Here the five step roadmap.

1. Measure continuously, not once

Get a tool that measures continuously — not an audit you run once and then put in a drawer.

The first output should be an uncomfortable number, presented without filters.

The next ones should make it possible to track the trajectory month after month, without having to repeat the audit exercise at every executive meeting.

The first output should be an uncomfortable number, the next ones should make it possible to track the trajectory over time.

2. Quick wins identified by the tool, not guesswork

Cloud rightsizing, extending the useful life of hardware, decommissioning zombie servers, quantified in euros and tons of CO₂ from day one, identified and prioritized by the same tool used for the initial audit.

These are the kind of wins that sell themselves in the executive committee: they pay for their own budget before you even start tackling the rest.

3. Dedicated governance, not a line item buried somewhere

A named owner. A budget of its own. A direct reporting line to the executive committee — not a line buried inside the CSR budget or the general IT budget.

Without that, it will be the first thing cut when the first difficult quarter comes around.

4. A gate that simulates before it approves

No architecture proposal should be approved without simulating at least 2 scenarios and comparing their carbon impact: cloud region, sizing, data-retention period.

The default region can have ten times the carbon impact of another region available for the exact same service, and no one discovers it because no one compares the options before making the decision.

This gate must be able to say no.

A gate that never blocks anything isn’t a gate. It’s a checkbox.

The default region can have ten times the carbon impact of another region available for the exact same service.

5. Board-level steering, not an annual report

Track KPIs at board level, alongside cybersecurity risk indicators, in the same tool used for the initial audit and for tracking quick wins, not in an annual CSR report rebuilt manually from scratch.

And have a dedicated indicator for the AI trajectory, updated continuously rather than discovered once a year.

How much does it cost?

The cybersecurity budget meant nothing fifteen years ago.

Today, it represents an average of 5.6% of the IT budget, reaching as high as 12% in mature sectors.

No one approved that budget in one go.

It was built line by line, as companies gradually understood what they stood to lose by doing nothing.

IT sustainability is at exactly the same point cybersecurity was fifteen years ago.

The question isn’t how much we will put into it in 2027.

The question is: what are we waiting for to get started?

Five mistakes. Five steps.

Cybersecurity took ten years to stop telling itself stories.

I didn’t build yet another awareness workshop. I left my position as CIO to build the tool that was missing.

You don’t have ten years.

Order the raw audit before the end of the year, it is the only move that makes a 2027 budget possible.

Everything else is simply the logical consequence of that first number.

Newsletter

Stay tuned!

Subscribe to our newsletter
newsletter