This site measures reach exclusively on its own server, without cookies and without third parties.

Information security that reaches operations.

ISO 27001, NIS2, the Cyber Resilience Act and cloud attestation – delivered with the engineers, not from the desk. Plus twenty years of IT project leadership, from mid-market companies to an international group. Based in the Stuttgart area, available for selected project and interim mandates across the EU.

Consulting profile (PDF) Discuss a mandate

Three roles, one line

I take responsibility where technology, organisation and regulation meet – and carry it through to the result.

INFORMATION SECURITY & COMPLIANCE

Engaged as: ISO 27001 implementation lead · NIS2 / CRA readiness lead · Compliance programme lead · Information security officer (interim)

Someone has to own the security – not just document it.

NIS2 is in force across the EU, the Cyber Resilience Act reports since September 2026, an audit is coming – and the board is liable. What is missing is the person who turns the standard into measures and talks to the auditor.

More

IT PROJECT LEADERSHIP

Engaged as: IT project manager · Senior project manager IT · ERP project lead · Infrastructure / new-build sub-project lead

A project has to be brought to completion.

The ERP has not gone live for months. The new building is up, the IT is not. The project management role is vacant or was never filled.

More

IT LEADERSHIP

Engaged as: Interim head of IT · IT lead on assignment

Operations, projects, investment and evidence belong in one pair of hands.

The IT lead is vacant or overloaded. Operations, projects, investments and audit evidence continue regardless.

More
  • 1st BSI C5 attestation of the organisation
  • 14 EU large-scale warehouses
  • 3 new builds to final acceptance
  • 8 years external Data Protection Officer
  • 20+ years of project responsibility

What you can measure it by

CLOUD PLATFORM OF AN INTERNATIONAL RETAIL GROUP

First BSI C5 attestation for the organisation

Worked through the complete criteria catalogue criterion by criterion with the auditor, mapped it against the existing ISO 27001 control set, translated it into technical requirements. External auditor: a Big Four audit firm. C5 is the German federal cloud security standard, comparable in rigour to SOC 2.

INTERNATIONAL FOOD RETAIL GROUP · LOGISTICS IT

IT infrastructure for 14 EU distribution centres, three new builds in parallel

Overall responsibility for 14 sites ranging from 10,000 to 40,000 m². Three new builds in the Netherlands and Belgium from planning to final acceptance – server room, network core, WLAN, trade coordination, contract management with suppliers.

OWN CONSULTING PRACTICE

ERP migrations and process digitalisation in the Mittelstand

Over twenty years: system selection, data modelling, migration, interfaces. Sales processes roughly 40 % faster, technical service roughly 50 % more efficient, and in the reorganisation of a construction company more than 30 % savings in personnel costs.

View all projects

What this covers in practice

Compliance & information security

BSI C5, ISO 27001, ISMS and DSMS development, audit management and evidence management, GDPR expertise from eight years as an external data protection officer, NIS2, the Cyber Resilience Act and the EU AI Act worked in

Infrastructure & new builds

network planning, structured cabling, server rooms, WLAN surveys, WAN redundancy, trade coordination, partial and final acceptance

CRM, ERP, data & interfaces

system selection, implementation and migration, data modelling and cleansing, EDI and web shop integration, document management

Processes & automation

process analysis and standardisation, workflow automation with n8n, controlled use of AI with a framework and approval paths; more under Digitalisation & Processes

Working together

AVAILABILITY
Selected mandates; scope and start by arrangement
CONTRACT
Direct contract or via agency
LOCATION
Based near Stuttgart, Germany; remote-first across the EU, on-site by arrangement
DOCUMENTS
Consulting profile as PDF, no registration

Looking to fill a permanent position in Germany? See the German site.

If what you actually need is ongoing support

This site is for selected mandates with clear responsibility. If instead you need someone to look after your IT permanently – operations, support, managed services, ongoing data protection – then falocon Ltd is the right address. The company is run by Leonie Franz; I work there part-time until the end of 2026.

falocon.com →

Listen first, then assess

In a first conversation we establish what the situation is and whether I am the right person. If I am not, I will say so – that saves us both time.

Request a conversation