Information security and systems consultancy for businesses and organizations that take their security seriously.
Let's talkFor mid-sized businesses and organizations that have reached the point where information security is no longer "an IT department matter" but a management matter — driven by regulatory obligations, customer requirements, an incident experience, or simply business maturity.
I also collaborate as a trusted external partner with consultancy firms delivering security and resilience projects.
My work is organized around four pillars covering the full security lifecycle of a business — from initial assessment to ongoing governance. I take on either focused projects in a single pillar, or complete programs combining several.
Before you can protect yourself properly, you need to know what exactly you're protecting against. We start with an honest, practical mapping of where you stand today.
Based on the identified risks, we design proportionate measures — calibrated to the risk, without overburdening your operations.
However much you prevent, some incidents will happen. The difference between serious damage and a manageable situation is preparation.
Once the above are working, you need governance that maintains and documents them — for management, auditors, and supervisory authorities.
When your security is in order, you don't just avoid damage — you gain:
Who used to ask you for certifications or security questionnaires — and now you can deliver.
In cyber insurance, in financing, in partnerships with larger organizations.
In tenders and partnerships, where reliable security becomes the differentiating factor.
Less time spent on crises and uncertainty, more on growth.
With over 28 years of experience in IT and Information Security, I have designed, implemented, audited and improved security systems in a regulated financial institution. My approach is not based on theoretical models. It is based on what works in practice: in real environments, with limited resources, strict requirements, audit reviews, and the need for documented decisions.
My professional experience is supported by certifications and ongoing involvement in governance, security, and risk management, including: CISM (ISACA), COBIT 2019 Foundation, and active participation in European forums on risk management and information security.
You work directly with me — no intermediate layers, no junior teams, no loss of information. This means faster understanding of your problem, more direct communication, and solutions tailored to the real size, structure and needs of your business.
Every project ends with practical deliverables: policies, procedures, registers, action plans, reports, checklists, and documentation that can be used by management, IT, internal audit, external auditors, or supervisory authorities. The goal isn't to deliver an impressive presentation. The goal is to deliver material that can be applied, approved, and audited.
My experience spans both the technical side of security and its administrative, regulatory, and audit dimensions. This means I can translate requirements related to security policies, risk management, access controls, business continuity, DORA, NIS2, COBIT or ISMS into practical procedures, understandable documents, and actionable steps.
The engagement can be adapted to the needs of your organization: fixed fee per project or service package, daily rate for retainer or support, or subcontracted collaboration with consultancy firms that need specialized experience in IT governance, cybersecurity, risk management, and compliance.
The initial conversation is always free of charge and confidential. Send a message and I will get back to you shortly.
info@cybergovernance.gr