About

I am an independent advisor working where security governance, regulation and software meet. My job is to make compliance something you can evidence rather than something you worry about: one management system, owned by the right people, that answers ISO 27001, NIS2 and GDPR, and is ready for the quantum-safe question when it comes.

My background sits exactly where that work lives. I spent six years inside BIPT, Belgium's federal telecommunications regulator, auditing operators against the ISO 27000 family, doing risk work on ISO 27005, co-building the sector incident-response capability (CSIRT) and coordinating between operators and government during incidents. That work is as much governance and regulation (GDPR, NIS, NIS2) as it is technology. Before and alongside it, a decade as software architect and CTO across data-intensive platforms means I can speak to engineering teams as fluently as to a board, and it is why I built Abacordo rather than recommending yet another spreadsheet. Over the last several years I have formalised a long-standing interest in quantum through the MIT xPro Quantum Computing programme and the IBM Qiskit certification track, and I build in Qiskit rather than only reading about it.

  • 6 yrssecurity audit and governance inside a national regulator
  • 10+ yrsas software architect and CTO
  • 2 mastersEngineering (KU Leuven) and Management (Vlerick)
  • Board to codefluent with executives, auditors and engineers alike

What I bring

  • The auditor's perspective. Six years of security audit, ISO 27001, 27002 and 27005 risk assessment and incident response, across GDPR, NIS and NIS2. I know which question comes next because I used to ask it.

  • A working management system, not a binder. I built Abacordo so that the register, the risks, the controls and the evidence stay linked and current after I leave.

  • Quantum-safe, honestly calibrated. Cryptographic exposure, the NIST post-quantum standards and crypto-agility, backed by hands-on Qiskit work and the judgment to tell demonstrable value from hype.

  • Translation between board and engineering. Engineering and management training, and a CTO track record, that turns regulatory change into decisions leadership can own.

  • Independent and vendor-neutral. I do not resell hardware, security products or migrations. The only thing I sell besides advice is the tool I built to support it.

Experience in brief

  • Founder, Abacas, 2023 to present. Independent GRC, security and technology advisory; builder of Abacordo.

  • Advisory Engineer, Network & Information Security, BIPT, 2017 to 2023. Security audit, risk and incident response, and governance at Belgium's federal telecom regulator.

  • Architecture and data roles. Software architect and CTO across data-intensive platforms, including big-data infrastructure and a real-time recommendation engine; cloud (AWS) and full-stack delivery.

Education and certification

  • MEng Computer Science, KU Leuven (magna cum laude); BEng Computer Science, KU Leuven (summa cum laude); Erasmus at Albert-Ludwigs-Universität Freiburg.

  • Master in General Management, Vlerick Business School (with distinction).

  • ISO/IEC 27001, 27002 and 27005.

  • MIT xPro Quantum Computing Fundamentals.

  • IBM Qiskit certification (in progress).

How I work

  • Plain language. If a policy or a recommendation cannot survive translation out of jargon, it is not ready.

  • Fixed scope wherever possible. You know what an engagement costs and delivers before it starts.

  • Vendor-neutral, structurally. No reselling, no referral fees, no preferred products.

  • Honest calibration. I tell you when a framework does not apply to you, when a control is not worth its cost, and when "not yet" is the right answer on quantum. All three are cheaper to hear early.

  • Capability transfer. The goal is that your team eventually needs me less, not more.