Services

Four areas, one point of contact

Each area answers a problem SMEs run into again and again: security with nobody in charge, IT that grew without direction, requirements from customers and regulators, AI used without rules. Take one, or combine them.

vCISO / CSIRT for cybersecurity

Security strategy, risk management and incident readiness, led by someone who has held the CISO role.

The problem

Security sits with the IT manager, who already has plenty on their plate. Nobody has the full picture of the risks, and if ransomware hit tomorrow it would be unclear who decides, what gets isolated and who needs to be told.

What you get

  • A security strategy with clear priorities, signed off by management
  • A risk register that is kept current and makes sense to the board
  • An incident response plan with CSIRT roles, escalation paths and contacts
  • Tabletop exercises to test the plan before you need it
  • A security lead your customers, auditors and insurers can talk to

How we work

As a project, to build the strategy and the incident response plan. As a fractional engagement, to lead security over time: regular meetings, reporting to management, oversight of suppliers and remediation work.

Sample deliverable

Incident response plan with a CSIRT RACI matrix, playbooks for ransomware, data breaches and email compromise, and a checklist for notifying the authorities.

Fractional IT Director for governance

Part-time IT leadership: roadmap, budget, suppliers and architecture aligned with business goals.

The problem

IT has grown in layers: different suppliers, contracts renewed by default, overlapping projects. Management has nobody who can translate technology choices into costs, risks and benefits.

What you get

  • A multi-year IT roadmap aligned with the business plan
  • A considered IT budget that separates running costs from investment
  • Suppliers and contracts reviewed, with measurable service levels
  • Documented architecture and a record of key decisions
  • An IT team with clear roles and a clear point of reference

How we work

As a fractional engagement, on agreed days and as part of management meetings. As a project, for specific needs: supplier selection, a migration, an infrastructure assessment.

Sample deliverable

A 24-month IT roadmap with prioritised initiatives, cost estimates, dependencies and progress indicators, presented to management.

GRC and compliance

ISO/IEC 27001, NIS2 and TISAX: from gap analysis to audit readiness, with a system that holds up over time.

The problem

A customer asks for ISO/IEC 27001 certification or a TISAX assessment, or your organisation falls under NIS2. You need compliance that works in practice, not a binder of procedures nobody follows.

The standards

  • ISO/IEC 27001

    The international standard for information security management systems. I guide you from defining the scope to the Statement of Applicability, through internal audits and on to the certification audit with the body of your choice.

  • NIS2

    The EU directive on network and information security, transposed in Italy by Legislative Decree 138/2024. We establish whether and how your organisation is in scope, what governance and incident reporting obligations apply, and which security measures to adopt in proportion to your size.

  • TISAX

    The security assessment model used across the automotive supply chain, based on the VDA ISA questionnaire. I prepare your organisation for the assessment: gap analysis against the required level, measures and evidence. The assessment itself is carried out by an accredited audit provider.

What you get

  • A gap analysis against the standard, with priorities and effort estimates
  • A management system designed around your organisation: scope, roles, risks, controls
  • Essential policies and procedures, written to be followed
  • Internal audits and management review
  • Preparation for, and support during, the third-party audit

How we work

As a project, with a defined path to the audit. As a fractional engagement, to keep the system alive after certification: internal audits, risk updates, handling non-conformities.

Sample deliverable

ISO/IEC 27001:2022 gap analysis report assessing the Annex A controls, with a risk treatment plan and a timeline to certification.

I provide advisory and compliance support. I am not a certification body and do not issue certificates.

AI: risk and implementation

Governance, acceptable use policies and risk assessment to adopt AI with judgement, and make it work.

The problem

Your people are already using AI, often without rules: customer data pasted into public chatbots, tools picked individually, no risk assessment. Meanwhile management wants to know where AI can create real value.

What you get

  • A map of how AI is used across the organisation today, and the related risks
  • A clear acceptable use policy for all staff
  • Criteria for assessing AI tools and vendors, data protection included
  • A governance model consistent with the EU AI Act (Regulation 2024/1689)
  • Pilot use cases selected, implemented and measured with your team

How we work

As a project, for the policy, the risk assessment and the first use cases. As a fractional engagement, to steer adoption over time and update the rules as tools and regulation change.

Sample deliverable

A company policy for generative AI, with a classification of permitted data, a list of approved tools and a process for requesting new ones.

Engagement

Two ways to work together

  • Project

    Objective, scope, timeline and deliverables agreed up front. Suited to a gap analysis, audit preparation, an incident response plan or an IT roadmap.

  • Fractional engagement

    A part-time CISO or IT director on an agreed monthly commitment. Suited to organisations that need ongoing leadership but cannot justify a full-time role.

Method

How we work

  1. Initial assessment

    I listen, gather documentation and talk to the key people, to build a clear picture of your security, IT and compliance.

  2. Plan

    Priorities, timing and costs in a plan that non-technical readers can follow, starting with the risks that matter most.

  3. Delivery

    I carry out the work or coordinate it with your team and suppliers, with progress you can check.

  4. Ongoing support

    I stay alongside you through a fractional engagement, or hand the know-how over to your team and close the project.

Let's talk about your organisation

A free introductory call to understand where you are and what you really need. If I am not the right person for the job, I will tell you.

info@fpexec.com LinkedIn