About
I am an independent advisor working where security governance, regulation and software meet. My job is to make compliance something you can evidence rather than something you worry about: one management system, owned by the right people, that answers ISO 27001, NIS2 and GDPR, and is ready for the quantum-safe question when it comes.
My background sits exactly where that work lives. I spent six years inside BIPT, Belgium's federal telecommunications regulator, auditing operators against the ISO 27000 family, doing risk work on ISO 27005, co-building the sector incident-response capability (CSIRT) and coordinating between operators and government during incidents. That work is as much governance and regulation (GDPR, NIS, NIS2) as it is technology. Before and alongside it, a decade as software architect and CTO across data-intensive platforms means I can speak to engineering teams as fluently as to a board, and it is why I built Abacordo rather than recommending yet another spreadsheet. Over the last several years I have formalised a long-standing interest in quantum through the MIT xPro Quantum Computing programme and the IBM Qiskit certification track, and I build in Qiskit rather than only reading about it.
- 6 yrssecurity audit and governance inside a national regulator
- 10+ yrsas software architect and CTO
- 2 mastersEngineering (KU Leuven) and Management (Vlerick)
- Board to codefluent with executives, auditors and engineers alike
What I bring
The auditor's perspective. Six years of security audit, ISO 27001, 27002 and 27005 risk assessment and incident response, across GDPR, NIS and NIS2. I know which question comes next because I used to ask it.
A working management system, not a binder. I built Abacordo so that the register, the risks, the controls and the evidence stay linked and current after I leave.
Quantum-safe, honestly calibrated. Cryptographic exposure, the NIST post-quantum standards and crypto-agility, backed by hands-on Qiskit work and the judgment to tell demonstrable value from hype.
Translation between board and engineering. Engineering and management training, and a CTO track record, that turns regulatory change into decisions leadership can own.
Independent and vendor-neutral. I do not resell hardware, security products or migrations. The only thing I sell besides advice is the tool I built to support it.
Experience in brief
Founder, Abacas, 2023 to present. Independent GRC, security and technology advisory; builder of Abacordo.
Advisory Engineer, Network & Information Security, BIPT, 2017 to 2023. Security audit, risk and incident response, and governance at Belgium's federal telecom regulator.
Architecture and data roles. Software architect and CTO across data-intensive platforms, including big-data infrastructure and a real-time recommendation engine; cloud (AWS) and full-stack delivery.
Education and certification
MEng Computer Science, KU Leuven (magna cum laude); BEng Computer Science, KU Leuven (summa cum laude); Erasmus at Albert-Ludwigs-Universität Freiburg.
Master in General Management, Vlerick Business School (with distinction).
ISO/IEC 27001, 27002 and 27005.
IBM Qiskit certification (in progress).
How I work
Plain language. If a policy or a recommendation cannot survive translation out of jargon, it is not ready.
Fixed scope wherever possible. You know what an engagement costs and delivers before it starts.
Vendor-neutral, structurally. No reselling, no referral fees, no preferred products.
Honest calibration. I tell you when a framework does not apply to you, when a control is not worth its cost, and when "not yet" is the right answer on quantum. All three are cheaper to hear early.
Capability transfer. The goal is that your team eventually needs me less, not more.