If you own compliance in a Belgian organisation, you know the real job is not passing the audit. It is keeping the evidence alive between audits, across ISO 27001, NIS2 and GDPR, with a team that is usually one person. I help you set it up properly, and I built Abacordo so it stays that way.

Independent, senior, vendor-neutral. Six years auditing critical infrastructure for the Belgian regulator, a decade building software, and a certified specialisation in quantum-safe cryptography.

Three frameworks, one set of records

ISO 27001, NIS2 (via CyberFundamentals) and GDPR article 32 ask for largely the same things: a risk register, a set of measures, an owner for each, proof they are working, and a calendar of things that expire. Most organisations keep that in three spreadsheets and a shared drive. Then someone leaves.

My approach is to build one management system that answers all three, record each fact once, and make the evidence part of how the organisation already works.

Where I help

  • GRC advisory

    Gap analysis, risk assessment, policy set, internal audit and audit preparation for ISO 27001. NIS2 scoping, CCB registration and CyFun self-assessment. GDPR article 32 measures and DPO support. Fixed scope, fixed fee. See services →

  • Abacordo

    The compliance platform I use with clients: one set of records for assets, risks, controls, suppliers, incidents and documents, answering ISO 27001, NIS2 and GDPR at once, with a full audit trail. Your own AI assistant can work in it directly. See Abacordo →

  • Fractional CISO or GRC lead

    One or two days a week to run the management system, report to the board and face the auditor, until the role can move inside.

  • Quantum-safe transition

    The EU expects the move to post-quantum cryptography to start by the end of 2026. It is a risk-management measure like any other, and I am one of the few GRC advisors who also works hands-on in Qiskit. See quantum-safe →

Who I work with

Mid-sized organisations in Belgium that fall under NIS2 or hold data that must be protected for years: security installers, manufacturers, health and care providers, professional services, software companies and public bodies. Usually the person I talk to is the CISO, the compliance or GRC officer, the DPO, or the CEO who has just found out that this is now their problem.

How engagements work

Assessments and audits run on a fixed scope and fixed fee, agreed before we start. Ongoing roles run on a retainer, reviewed quarterly. Abacordo is in closed beta; clients on an engagement get it set up as part of the work, and other organisations can request access. Some of this work qualifies for Belgian or European innovation support; if yours does, I will tell you before we start.

Why work with me

I have sat on the other side of the table. At BIPT, the Belgian federal telecom regulator, I audited operators against ISO 27001, 27002 and 27005, co-built the sector CSIRT and handled incident coordination between operators and government. Since then I have worked as software architect and CTO, and added MIT xPro Quantum Computing and IBM Qiskit to the toolbox. I know what a supervisor will ask, and I know what it takes to build the system that answers.

Not sure where you stand? Book a 30-minute conversation. You bring the current state of your compliance, I tell you what an auditor or the CCB would ask first, and whether a formal gap analysis is worth it. Book a conversation →