CISO as-a-service.
I help organisations build their cybersecurity governance, define a risk-based roadmap, implement security projects, and give management the visibility they need, without hiring a full-time CISO.
Scope of the mandate
Governance. Operational. Technical. Resilience. Reporting.
Governance
Strategy & business alignment
- Cyber business cases with cost-benefit analysis; prioritised roadmap for exco approval
- Risk register, security policies, Statement of Applicability. Living documents tied to the actual threat landscape, not shelfware
Operational
Security by design
- Security requirements embedded from project kickoff, not as an afterthought
- Architecture review gate: no go-live without security sign-off
- Change management tied to security baselines
Technical
Detect, respond, remediate
- Vulnerability scans → risk-rated findings → prioritised remediation tracking to closure
- Incident response playbooks and crisis communication plans calibrated to your risk profile
Resilience
Continuity under pressure
- Business Impact Analysis drives the scope: BCP/DRP designed around what actually matters
- Crisis simulations tested under realistic conditions, not just documented on a shelf
Reporting
Prove progress to the board
- Traffic-light dashboards, quarter-over-quarter progress, executive-ready format
- KPIs aligned to risk appetite: compliance coverage, MTTR, patch status, incident trends, residual risk evolution
The roadmap
How I approach the first months working with you.
A structured ramp-up, from assessment to running security function.
After 6 months you have: a maturity assessment, governance framework, first standards deployed, quick wins in place, a security roadmap, and a dossier ready for your permanent CISO or for continued engagement.
Movement I
Understand & assess
Month 1–2. Map the current state, identify critical gaps, deliver first wins.
- Stakeholder interviews to understand business priorities and risk tolerance
- Maturity assessment across governance, technical, operational domains
- Asset inventory and critical systems mapping
- Quick wins deployed immediately: MFA, password policies, awareness basics
- Deliver: maturity report + risk overview
Movement II
Build foundations
Month 3–4. Put the governance structure and core documentation in place.
- Security policy updated and approved by management
- Governance committee set up with clear roles and meeting cadence
- Priority standards deployed (access control, incident management, change management)
- Documentation framework structured and operational
- Risk register initiated, linked to business impact
Movement III
Deliver & hand over
Month 5–6. Leave you with a running security function and a clear path forward.
- 3-year security roadmap with prioritised initiatives and budget estimates
- KPI dashboard tracking compliance, risk reduction, and operational metrics
- Complete handover dossier: current state, risks, stakeholder map, documentation, action plan
- Recommendations for the next 12 months
Maturity assessment.
Most organisations start at maturity level 1-2: informal processes, no documentation, reactive posture.
→ After 6 months, the goal is to reach level 3 on critical domains: defined, documented, applied.
Target sectors.
Private and public sector organisations across Luxembourg and the Benelux.
Government agencies
Municipalities
PSFs
Credentials
Emmanuel Genesteix
20 years in IT. Certified where it matters.
- 20 years in IT, cybersecurity, infrastructure & programme management
- Regulated sectors: finance, government, transport
- Certifications: ISO 27001 Lead Implementer & Auditor, ITIL V4, PRINCE2, SAFe 5, Scrum Master, TOGAF, AWS Cloud Practitioner
- Education: Executive MBA (IE Business School) · Master of Science Innovation (ESCP Europe)
Let's talk.
30 minutes to understand your situation. Free, no commitment.