Group CISO · Interim CISO · Executive Advisor

Interim CISO and executive cybersecurity for critical situations.

Cybersecurity that is decided in the boardroom and effective in operations—for industrial, critical-infrastructure and regulated organisations, with dependable leadership and demonstrable progress.

Run the cybersecurity check 3 questions · about 3 minutes · immediate result
Discuss an engagement
CISSPCISMISO 27001 Lead AuditorISO 22301 Lead Auditor
ITCST / Decision ModelExecutive control
Decision ready
01

Observe

Recognise business impact.

02

Decide

Clarify options and residual risk.

03

Mobilise

Activate owners and resources.

04

Embed

Steer demonstrable progress.

15+Years in IT and security
C-LevelReporting and decisions
IT + OTGovernance through delivery
DE / ENInternationally deployable

The leadership constraint

More tools do not solve a leadership problem.

The constraint is often not missing technology, but unclear accountability, competing priorities and decisions without a shared risk picture.

A

Leadership Gap

A CISO vacancy, unclear roles or a programme without dependable leadership.

B

Regulatory Pressure

Prepare for NIS2, critical infrastructure, customers or external assessments.

C

Technical Exposure

Prioritise findings, transformation and dependencies for decision.

D

Operational Resilience

Connect critical services, recovery and leadership capability.

ITCST Decision Navigator

Which security decision does your organisation need to make next?

Define your starting point in three short steps. You will receive a non-binding view of the relevant priorities, key dependencies and the advisory format most likely to fit your situation.

  • No technical expertise required
  • No confidential system details
  • No registration
  • Result in about three minutes
  1. 01
    Select the trigger What is creating the need to act?
  2. 02
    Define business impact Which consequences need to be limited?
  3. 03
    Receive a prioritised agenda See the relevant priorities and a suitable starting format.
Define your security priorities 3 questions · about 3 minutes · non-binding · immediate result

Four engagement fields

From decision need to an effective engagement.

What management receives

Decision capability, not activity reporting.

01

Situation report

A shared view of business-relevant risk, obligations and dependencies.

02

Decision papers

Clear options with consequences, residual risk, resources and decision authority.

03

Prioritised agenda

A realistic 90-day sequence and the strategic steps that follow.

04

Leadership model

Owners, cadence, escalation and evidence for traceable progress.

Portrait of Matthias Totzauer
Matthias Totzauer Group CISO · Interim CISO

Personal accountability

Peer-level leadership.
Depth when it matters.

Matthias Totzauer supports executives, IT and security leaders when accountability, risk and delivery must be clarified at the same time.

Lead Auditor certifications are personal qualifications. ITCST does not provide independent certification audits.

Executive Insights

Perspective for better decisions.

Focused analysis of security leadership, regulation, IT/OT and resilience—from the decision-maker’s perspective.

Next step

Which decision can no longer remain open?

Define the security need without obligation, or discuss the situation directly with Matthias Totzauer.