[ interim ciso ]

Security and compliance you can prove.

For software companies and scale-ups that must meet laws, standards and customer requirements. I work out what applies to you, take the lead as interim CISO and make security part of the daily work.

Role
interim CISO or advisor
Duration
3 to 24 months
Commitment
2 to 3 days a week
Available
now

Services

What I do for you

[ 01 ]

Baseline scan

Which laws and standards apply to you, what do your customers ask for and where do you stand today? Within two weeks you have an overview, you know the biggest risks and there is a plan for the next ninety days.

[ 02 ]

Interim CISO

I temporarily take responsibility for information security and compliance: from risk analysis and policy to customer questionnaires, supplier agreements and reporting to management.

[ 03 ]

Certification and audits

From baseline to certificate. I set up the management system, make the controls demonstrable and prepare your team for the external audit.

Need an interim CTO as well, or help with architecture or quality assurance? That is possible too, as an addition or on its own.

Expertise

Laws, standards and customer requirements

Laws and regulations

Dutch Cybersecurity Act (NIS2), Cyber Resilience Act, DORA, GDPR and the AI Act. I translate what the law asks into concrete measures, with the evidence to match.

Standards and certifications

ISO 27001, NEN 7510, SOC 2 and BIO. A certificate that fits how you really work, so the next audit does not become a new project.

Customer requirements

Security questionnaires, supplier assessments, contract requirements and due diligence. One standing set of answers and evidence, so a questionnaire no longer costs you weeks.

Sound familiar?

When you call me in

  • [ ]A customer sends a security questionnaire or asks for a certificate, and the deal stalls.
  • [ ]Your organisation falls under the Cybersecurity Act (or your customers do) and nobody knows exactly what you must be able to show.
  • [ ]You build software and the Cyber Resilience Act sets requirements for how you report vulnerabilities and ship updates.
  • [ ]You supply banks or insurers and suddenly there are DORA requirements in the contract.
  • [ ]The external audit is coming and the documentation lags behind the practice.

Approach

From first conversation to handover

  1. 01

    Intro

    One hour, no obligation. Afterwards you know whether I am the right person.

  2. 02

    Baseline scan

    In two weeks I map out which requirements apply and where you stand. You get a ninety-day plan that you can also carry out without me.

  3. 03

    Execution

    I take charge, work with your team and report to management.

  4. 04

    Handover

    I train a permanent successor or your own team and leave everything recorded for the next audit.

Erik Kasimier

About Erik

Who you are hiring

I come from software development and have led IT teams for years. That is why I know what a control demands in practice, and can explain it to both management and the auditor.

  • [ ]In software development since 2008, including as senior software engineer at FontoXML and Liones.
  • [ ]From 2017 to 2025 at ANWB: Solutions Architect, Lead IT & Development and Head of Technology at ANWB Energie.
  • [ ]Independent since September 2023 with Nogato IT Consultancy, based in Gouda.
  • [ ]Recent assignments: ISO 27001 preparation at a health-tech scale-up and quality assurance at an international standards organisation.

Is there a questionnaire, audit or deadline on your desk?

Tell me briefly where you stand. You will hear from me within one working day.