This site measures reach exclusively on its own server, without cookies and without third parties.

INFORMATION SECURITY & COMPLIANCE

An attestation does not come from documents, but from decisions

Engaged as: ISO 27001 implementation lead · NIS2 / CRA readiness lead · Compliance programme lead · Information security officer (interim)

NIS2 has been transposed across the EU, the Cyber Resilience Act has required vulnerability and incident reporting since 11 September 2026 and applies in full from 11 December 2027, and the new Machinery Regulation applies from January 2027. Every affected company needs someone who scopes the obligation, closes the gaps, keeps the evidence and talks to the auditor – and who takes the board out of personal liability. That is the role I fill.

On the cloud platform of an international retail group I led the organisation's BSI C5 programme through to audit readiness, with a Big Four audit firm as external auditor – working through the complete criteria catalogue criterion by criterion with the auditor, clarifying interpretation, agreeing test conditions and evidence expectations for each control. The attestation was achieved, after my handover in the final phase. C5 is the German federal cloud security standard, comparable in rigour to SOC 2.

Discuss a programme

The combination that is usually missing

Compliance programmes rarely fail on the regulation. They fail on the translation: the consultant knows the catalogue but not the platform. The engineer knows the platform but not what the auditor actually wants to see. In between, a ping-pong of criteria tables and queries develops that costs months.

I stand at that point. Twenty years of infrastructure and network practice mean I can discuss a logging, segmentation or hardening control with the person responsible, rather than sending them a line from the catalogue and waiting for an answer. And I know the other side of the table: an auditor does not want a collection of policies but evidence that a control actually works.

What sets me apart is judgement: in a programme with a hundred open items, seeing immediately what genuinely sits on the critical path to attestation.

Services

ISO 27001 / 27002

ISMS development, control design and implementation, internal audit processes, preparation for certification audits.

NIS2

applicability check against the national transposition, registration with the competent authority, derivation of the risk-management measures under Article 21 from the existing control set, incident reporting under Article 23, evidence management towards management and supervisory authority. Worked in, without a completed project reference yet – I say so up front, not in the meeting.

Cyber Resilience Act

applicability to products with digital elements, reporting processes for actively exploited vulnerabilities and severe incidents (since September 2026), preparing conformity through to December 2027: risk assessment, vulnerability management across the support period, software bill of materials (SBOM), interplay with the Machinery Regulation. Worked in, without a completed project reference yet.

Cloud attestation (BSI C5)

gap analysis against the criteria catalogue, agreement of interpretation and test conditions with the auditor, mapping against existing control sets, translation into technical requirements, evidence governance through to audit readiness.

GDPR

DSMS development, policy framework, record of processing activities, technical and organisational measures, training, audit documentation. Eight years of practice as an external data protection officer for several companies.

Audit management

interface between the technical organisation and the external auditor, evidence collection and management, enablement of control owners, preparation and support during the audit.

CER/KRITIS, EU AI Act

regulatory assessment, applicability analysis, derivation of what needs to be done. Worked in, without a completed project reference yet.

How a programme runs with me

Establish the gap position.

What already exists, where existing controls apply, where there is genuinely a gap. Where an ISO 27001 control set is in place, the route to C5 is shorter than most assume – provided someone does the mapping properly.

Clarify interpretation with the auditor before work begins.

The most expensive mistake in an attestation programme is evidence that is not accepted at the end. I agree test conditions and evidence expectations for each control in advance.

Translate into technical requirements.

Not "control X is to be implemented", but specifically what the platform, infrastructure or security team has to do – in their language and with the reasoning behind it.

Enable and lead the control owners.

Compliance does not work by assignment. Those responsible have to understand why something is required, otherwise paper is produced instead of effect.

Govern the evidence, one interface to the auditor.

I am the single point of contact externally. That protects your teams from direct queries and the auditor from contradictory answers.

Hand over repeatably.

An attestation is not a project with an end but a state that has to be confirmed annually. I build in the routines that carry that – otherwise your successor is at the same point in twelve months.

Who this is for

Mid-market manufacturers and service providers that need an information security owner

, because NIS2 or the Cyber Resilience Act obliges them for the first time and nobody can carry the role on the side.

Cloud and platform providers

who need a C5 attestation because their customers in the public sector or in regulated industries ask for one.

Companies facing ISO 27001 certification

who find that policies alone are not enough.

Organisations with an audit coming up

and no one to drive the programme through to the result.

Companies under NIS2 or within the scope of the EU AI Act

who first need to know whether and how far they are affected at all.

Framework

AVAILABILITY
Selected mandates
MODE
Remote-first, on-site for audit dates and critical phases
LANGUAGES
German and English – audit communication in both languages

Consulting profile – PDF

Do you need an ongoing data protection officer? An external DPO mandate is a standing obligation, not a project – for that, falocon Ltd (www.falocon.com) is the right address. This site is about selected mandates with a clear result.

What is coming up for you?

Tell me the framework and the deadline. In a first conversation I will tell you whether that is realistic – even if the answer is uncomfortable.

Request a conversation