Observe
Recognise business impact.
Group CISO · Interim CISO · Executive Advisor
Cybersecurity that is decided in the boardroom and effective in operations—for industrial, critical-infrastructure and regulated organisations, with dependable leadership and demonstrable progress.
Recognise business impact.
Clarify options and residual risk.
Activate owners and resources.
Steer demonstrable progress.
When pressure becomes real
The leadership constraint
The constraint is often not missing technology, but unclear accountability, competing priorities and decisions without a shared risk picture.
A CISO vacancy, unclear roles or a programme without dependable leadership.
Prepare for NIS2, critical infrastructure, customers or external assessments.
Prioritise findings, transformation and dependencies for decision.
Connect critical services, recovery and leadership capability.
Four engagement fields
Security Leadership
Regulatory Readiness
Secure Transformation
Operational Resilience
What management receives
A shared view of business-relevant risk, obligations and dependencies.
Clear options with consequences, residual risk, resources and decision authority.
A realistic 90-day sequence and the strategic steps that follow.
Owners, cadence, escalation and evidence for traceable progress.
Personal accountability
Matthias Totzauer supports executives, IT and security leaders when accountability, risk and delivery must be clarified at the same time.
Lead Auditor certifications are personal qualifications. ITCST does not provide independent certification audits.
Executive Insights
Focused analysis of security leadership, regulation, IT/OT and resilience—from the decision-maker’s perspective.
Effective CISO support depends on the mandate. Urgency, leadership need, decision rights and the intended outcome determine the right model.
Read article →A group-wide security model does not remove entity-level obligations. NIS2 readiness needs clear accountability, dependencies and evidence.
Read article →Remote maintenance is necessary in many industrial environments. Without controlled identities, approval, segmentation and monitoring, it becomes a critical attack path.
Read article →Next step
Define the security need without obligation, or discuss the situation directly with Matthias Totzauer.