Services

Video meeting . 15 mins
5060
Video meeting . 30 mins
30
Video meeting . 15 mins
10
Popular
Video meeting . 60 mins
50

About me

DOCUMENTED WEAKNESS or WEAK DOCUMENTATION is easy prey in AUDITS and ATTACKS as it gives others precise clues as to where to drill down WHAT I DO DIFFERENTLY DUE TO MY MULTI-DISCIPLINARY BACKGROUND... With the upcoming IT Regulations (#DORA, etc.) Financial institutions and their third-party providers are under pressure when it comes to ensuring transparency and accountability for an agile 360° compliance challenge 30+ years of multi-disciplinary experience within IT operations in front of a sound legal & regulatory background let me operate with a holistic unbiased approach outside the bounds of internal conflicts of interest or knowledge silos ✓ I transform organizational, technological, or regulatory RISKS into lean-agile COMPLIANCE SERVICES before old omissions are uncovered by getting the PAPERWORK in ORDER (policies, instructions, contracts, minutes, etc.) as they serve as PIECES OF EVIDENCE of sound IT governance and control frameworks ✓ I apply BUSINESS ANALYSIS and DESIGN THINKING methodologies to establish regulatory-sound processes, policies, instructions, and operations by ▸treating auditors, regulators, and even attackers as "special clients" deserving of "sound services" ▸transforming outdated set&forget audit practices into an agile GRC program ▸enabling inclusive, proactive crisis- and attack-resilient training practices ✓ I provide sound expertise in relevant areas of IT-DueDiligence/IT-Audits/-Assessments according to applicable legal, regulatory, or security requirements ▸Governance & Organization ▸IT Risk Management ▸CyberSecurity ▸Business Continuity Management / Disaster Recovery ▸3rd party DueDiligence/Audit ▸Information Security ✓ I have been learning alongside clients in the most critical industries ▸Finance (banks, investment, insurance firms) ▸IT/Cloud providers ▸Energy/Solar ▸Transport/Aviation ▸Health, etc ▶ Emerging Challenges need an open-minded and agnostic root-cause-analysis-driven approach ▸toward operations, functions, and technology ▸regardless of hierarchy, knowledge silos, mainstream credos, skill shortages, or ▸the underlying internal conflicts of interest ▸getting rid of the negative "check-the-box" reputation produced by "auditors" without a proven background to spot true weaknesses 🎲 ROLLING DICE once a year and ticking some checkboxes is NO appropriate continuous AUDIT APPROACH ⌛ The question is NOT IF, BUT WHEN the next challenge is at your door ☑ Get back in the lead and turn yearly re-acting into continuous pro-acting ☎ Let´s get in contact!