vCISO IT Director GRC AI

A CISO and an IT director for your organisation, without the full-time hire.

FP Exec works with SMEs that do not have a full-time CISO or IT director: security strategy, IT governance, ISO/IEC 27001, NIS2 and TISAX compliance, and responsible adoption of AI. As a defined project or a fractional engagement.

No obligation: we will see together whether I can help.

18 years
from technician to CISO and IT director
Lead Auditor
ISO/IEC 27001:2022
C|ISO
Certified Information Security Officer
Project or fractional
without a full-time hire

What I do

Four areas of practice

Expertise that usually takes several senior hires, brought together in one person who understands both the technology and the governance.

  1. vCISO / CSIRT for cybersecurity

    Security strategy, risk management and incident readiness, led by someone who has held the CISO role.

    Read more : vCISO / CSIRT for cybersecurity
  2. Fractional IT Director for governance

    Part-time IT leadership: roadmap, budget, suppliers and architecture aligned with business goals.

    Read more : Fractional IT Director for governance
  3. GRC and compliance

    ISO/IEC 27001, NIS2 and TISAX: from gap analysis to audit readiness, with a system that holds up over time.

    Read more : GRC and compliance
  4. AI: risk and implementation

    Governance, acceptable use policies and risk assessment to adopt AI with judgement, and make it work.

    Read more : AI: risk and implementation

Why FP Exec

From the server room to the boardroom

Over eighteen years I have held most of the roles in IT: technician, systems engineer, architect, then CISO and IT director. That is why I can turn a regulatory requirement into a configuration, and a technical risk into a decision management can actually take.

  • End-to-end view

    Technology, processes and governance considered together, not in silos.

  • Built for SMEs

    Measures sized to the resources you actually have. No documents left gathering dust.

  • One point of contact

    You work with me directly, from the first call to the final deliverable.

My background

Method

How we work

  1. Initial assessment

    I listen, gather documentation and talk to the key people, to build a clear picture of your security, IT and compliance.

  2. Plan

    Priorities, timing and costs in a plan that non-technical readers can follow, starting with the risks that matter most.

  3. Delivery

    I carry out the work or coordinate it with your team and suppliers, with progress you can check.

  4. Ongoing support

    I stay alongside you through a fractional engagement, or hand the know-how over to your team and close the project.

Certifications

Verified expertise

  • Auditor / Lead Auditor ISO/IEC 27001:2022 Gerico Security 2023
  • C|ISO — Certified Information Security Officer Fata Informatica 2024 valid until 2029
  • Certified Red Team Operations Management (CRTOM) Red Team Leaders 2026
  • Ethical Hacking Expert OPSWAT Academy 2026 valid until Apr 2027
  • Foundation Level Threat Intelligence Analyst arcX 2023
  • ITIL 4 Foundation AXELOS 2022
  • Google AI Essentials Google 2025
  • Google Prompting Essentials Google 2025

Free resource

Not ready for a call yet?

Start with the NIS2 self-assessment checklist: fifteen questions to see where your organisation stands. Fill it in online or download the PDF, no sign-up needed.

Open the NIS2 checklist

Let's talk about your organisation

A free introductory call to understand where you are and what you really need. If I am not the right person for the job, I will tell you.

info@fpexec.com LinkedIn