Executive Cybersecurity Leadership · Strategy · Transformation

Cybersecurity leadership for decisions with operational consequences.

Matthias Totzauer supports boards, executives and IT/OT leaders in industrial, critical-infrastructure and regulated organisations—personally, discreetly and through effective delivery.

Frame your situation Two clear paths · local in your browser · no registration
Confidential first conversation
CISSPCISMCISAISO 27001 Lead AuditorISO 22301 Lead Auditor
ITCST / Executive Decision ArchitectureCybersecurity Decision Navigator
Private by design
01

Observe

Recognise business impact.

02

Decide

Clarify options and residual risk.

03

Mobilise

Activate owners and resources.

04

Embed

Steer demonstrable progress.

15+Years in IT and security
C-LevelReporting and decisions
IT + OTGovernance through delivery
DE / ENInternationally deployable

One clear entry point

What do you need to frame with confidence?

Choose the path that matches the question in front of you. Both assessments stay at management level, provide immediate orientation and lead into professional validation only when useful.

  • No registration
  • Processed locally
  • No automated decision

ITCST Compliance Navigator

What does your management need to clarify now?

Four short steps provide an indicative assessment, three concrete management decisions and a shareable executive brief in about 90 seconds.

90 seconds · no sign-upStart

NIS2 · ISO/IEC 27001 · BSI

Concise management guidance—not an audit in the browser.

No sign-up · unverified self-assessment · not an audit or legal advice. For a download or enquiry, the Navigator passes selection identifiers only; contact details are processed only in the separate enquiry form.

  1. 01Possible classificationImportant, essential or requiring review
  2. 02Control areasTen measure areas plus the ISMS view
  3. 03Reporting & governance24h, 72h, final report and internal incident record

Defined engagement frameworks

Transparent investment framework.

The compact assessment remains free. Validation, readiness and implementation use clearly scoped B2B engagement frameworks.

01 · Entry engagement

Executive Compliance Validation

€3,300 net

Document review, 90-minute workshop, validated assessment and management note with three prioritised decisions.

Clarify the scope
02 · Project corridor

NIS2 & ISO Control Readiness

€13,200–€19,800 net

High-level gap analysis, control-area mapping, evidence position and review of governance, reporting and internal incident governance.

Frame readiness
03 · Project corridor

Compliance Implementation Sprint

€22,000–€33,000 net

90-day roadmap, RACI, incident and reporting templates, action governance and management cadence through dependable handover.

Scope implementation
04 · Separate software roadmap

Full Compliance Navigator · software

Enterprise scope-based framework

The later full version will manage control mappings, evidence, actions, accountability and maturity. It is deliberately not part of this free high-level check; licensing and implementation will be scoped separately.

Register interest in the roadmap

B2B fees exclude applicable VAT. The project corridor is fixed before engagement based on entities, sites, IT/OT scope and available evidence.

Sources and legal basis
§ 2 BSIG·§ 28 BSIG·§ 30 BSIG·§ 31 BSIG·§ 32 BSIG·§ 33 BSIG·§ 35 BSIG·§ 38 BSIG·§ 39 BSIG·§ 8 KRITISDachG·EU 2024/2690·BSI-Portal·MIP·ISO/IEC 27001:2022

The leadership constraint

More tools do not solve a leadership problem.

The constraint is often not missing technology, but unclear accountability, competing priorities and decisions without a shared risk picture.

A

Leadership Gap

A CISO vacancy, unclear roles or a programme without dependable leadership.

B

Regulatory Pressure

Prepare for NIS2, critical infrastructure, customers or external assessments.

C

Technical Exposure

Prioritise findings, transformation and dependencies for decision.

D

Operational Resilience

Connect critical services, recovery and leadership capability.

Executive engagement architecture

Clear remit.
Clear accountability.

Three clearly defined engagements for three leadership situations. Scope, accountability and fees are agreed only after professional qualification.

Engagement 01

Decision mandate · 2–3 weeks

Executive Cyber Decision Sprint

Move from cybersecurity uncertainty to a defensible management decision and a prioritised 90-day plan.

Decision outcome

You receive a decision package with standalone value, whether or not a follow-on engagement is commissioned.

Engagement 02

Programme design · 6–8 weeks

Cyber Resilience 100-Day Blueprint

Turn disconnected activities into an approval-ready cyber-resilience programme with a target model, budget logic and clear governance.

Decision outcome

Executives, finance and technology leaders receive one aligned basis for budget, resource and delivery decisions.

Engagement 03

External security leadership · defined term

Fractional CISO & Cyber Transformation Office

Personally led cybersecurity governance and disciplined programme direction without prematurely building a full-time internal CISO structure.

Decision outcome

Management gains accountable leadership, a dependable steering cadence and transparent decisions instead of an open-ended activity list.

No clear engagement shape yet?

The Decision Navigator structures the trigger, business impact and leadership need—without registration or an obligation to make contact.

Open Decision Navigator

Four engagement fields

From decision need to an effective engagement.

What management receives

Decision capability, not activity reporting.

01

Situation report

A shared view of business-relevant risk, obligations and dependencies.

02

Decision papers

Clear options with consequences, residual risk, resources and decision authority.

03

Prioritised agenda

A realistic 90-day sequence and the strategic steps that follow.

04

Leadership model

Owners, cadence, escalation and evidence for traceable progress.

Traceable competence

Evidence before self-promotion.

Qualifications and engagement profiles are stated precisely. Client names, testimonials and project metrics appear only with explicit approval.

15+

Years across IT, security leadership and regulated environments

CISSP · CISM · CISA

Recognised qualifications across security, governance and assurance

ISO 27001 · ISO 22301

Lead Auditor qualifications for information security and resilience

IT · OT · Critical infrastructure

Leadership from executive governance through operational delivery

Portrait of Matthias Totzauer
Matthias Totzauer Group CISO · Interim CISO

Personal accountability

Peer-level leadership.
Depth when it matters.

Matthias Totzauer supports executives, IT and security leaders when accountability, risk and delivery must be clarified at the same time.

Lead Auditor certifications are personal qualifications. ITCST does not provide independent certification audits.

Executive Insights

Perspective for better decisions.

Focused analysis of security leadership, regulation, IT/OT and resilience—from the decision-maker’s perspective.

Confidential first conversation

Which decision can no longer remain open?

In 25 minutes, clarify the decision need, urgency and engagement fit directly with Matthias Totzauer.