Skip to content
Nicola Dibitetto
Let’s talk

[email protected]+39 379 366 0243

Area II of III

Cyber Security & Risk

I help companies make cyber security part of the way they work and of their digitalisation projects, with attention to risk and to regulatory compliance.

The problem

Security is dealt with in episodes: after an incident, on the eve of an audit, when a customer asks for it

The approach

I start from the critical processes and their exposure to risk, then build rules, roles and controls the organisation can actually sustain

The value

Data and business continuity protected without slowing down everyday work

The possible outcome

A risk map, written policies and procedures, continuity and recovery plans, security requirements built into projects and contracts

CS.01

Cyber Risk & Maturity Assessment

Know where you stand before deciding where to invest

When it is needed

When it is unclear how exposed the company is, or where it makes sense to start.

What I do in practice

  • Preliminary assessment of the cyber security maturity level
  • Mapping of critical processes and of the areas most exposed to risk
  • Identification of the main operational, technological and organisational threats
  • Analysis of vulnerabilities linked to suppliers and third parties
  • Assessment of reputational and regulatory risks

What stays with the company

A snapshot of the maturity level and a map of the critical processes with the risks they are exposed to

Ask about CS.01

CS.02

Security Governance & Compliance

Written rules, roles and controls, proportionate to the organisation

When it is needed

When security depends on individual habits rather than written rules, or when customers, auditors or regulations ask you to demonstrate how it is managed.

What I do in practice

  • Support in adopting recognised reference frameworks (ISO 27001, NIST, CIS)
  • Definition and formalisation of security policies and procedures
  • Assignment of roles and responsibilities
  • Support for GDPR compliance and for the management of internal controls
  • Planning and periodic review of security controls

What stays with the company

Formalised policies and procedures, with assigned responsibilities and planned controls

Ask about CS.02

CS.03

Business Continuity & Incident Readiness

Know what to do, and who does it, before it is needed

When it is needed

When a system outage or a cyber incident would find the company without a plan: no recovery priorities, no procedure, nobody in charge of communication.

What I do in practice

  • Mapping of critical business processes
  • Definition of business continuity (BCP) and disaster recovery (DRP) plans
  • Incident management and response procedures
  • Definition of communication flows in a crisis
  • Post-incident analysis and identification of corrective actions

What stays with the company

Continuity and recovery plans, incident response procedures and a communication scheme for moments of crisis

Ask about CS.03

CS.04

Cyber Risk in Digital Projects

Security joins the project at the start, not once testing is over

When it is needed

When a new system, a migration or the digitalisation of a process is starting and security risks being addressed only at the end.

What I do in practice

  • Building security requirements into IT projects
  • Risk analysis of digitalised processes
  • Security assessment of cloud environments and application systems
  • Support in defining access controls and data protection
  • Risk monitoring throughout the life of the project

What stays with the company

Security requirements written into the project and risks tracked for its whole duration

Ask about CS.04

CS.05

Supplier & Third-Party Security

Your security also depends on those who work for you

When it is needed

When services and data are entrusted to external suppliers and it is unclear what security guarantees they offer, or what the contract provides for.

What I do in practice

  • Analysis of service levels and of the security clauses in contracts
  • Support in evaluating requests for information and for proposals (RFI, RFP) and outsourced IT services
  • Monitoring of the risks linked to technology outsourcing
  • Verification that suppliers are aligned with the required security standards

What stays with the company

A review of suppliers against the required standards and specific remarks on contracts and service levels

Ask about CS.05

The other areas

A problem often touches more than one

Not sure which service fits your case?

That is normal: problems rarely come divided by area. Describe the situation and I will start from there.

Describe your needs