Matthias Totzauer · Executive Cybersecurity

Take ownership when clarity matters.

Security executive with more than 15 years of experience at the intersection of leadership, regulation, IT/OT architecture and operational delivery.

Portrait of Matthias Totzauer
Matthias Totzauer Group CISO · Interim CISO

Executive profile

Leadership and technical depth in one person.

Matthias Totzauer works with boards, executives, and IT, security and operations leaders when security decisions must be made under time pressure, regulatory pressure or during complex transformation.

His approach combines an executive-ready risk picture with the technical substance required for realistic target states, transitions and priorities. The dialogue remains personal; accountability is not delegated to an anonymous delivery team.

Working principles

Clear in decision. Pragmatic in delivery.

01

Business impact before technology

Risk work starts where services, obligations and decisions are affected.

02

Clarity before activity

A clear owner and a defensible decision are more valuable than a long action register.

03

Depth without jargon

Technical relationships are explored to the level required for an accountable decision.

04

Transition, not dependency

Engagements build leadership and delivery capability that remains in the organisation.

Qualifications

Verified. Relevant. Personally accountable.

01CISSP

Certified Information Systems Security Professional

02CISM

Certified Information Security Manager

03ISO 27001 LA

Information Security Management

04ISO 22301 LA

Business Continuity Management

Qualification boundary

The Lead Auditor certifications document personal competence. ITCST does not provide independent certification or conformity audits.

Next step

Which decision can no longer remain open?

Define the security need without obligation, or discuss the situation directly with Matthias Totzauer.