Advisory

Most organizations don’t see the gap clearly until something goes wrong.

On one side: the security infrastructure they’ve built, the platforms they run, the AI systems they’re adopting faster than they understand. On the other: the governance reality, which is how those systems are actually overseen, interpreted for the board, and held accountable when the pressure arrives. The distance between those two things is where most of the real risk lives. It’s also, in my experience, where most of the important decisions get made badly.

Closing that distance is the work I do.

I’ve spent thirty years operating at the intersection of technology strategy and institutional risk, as a CTO, as a CISO, across the world. Most people in this space come from one direction or the other: the security professionals who understand governance but not architecture, or the technology leaders who can build platforms but haven’t sat with the accountability when those platforms fail. Having been both, I read the gap between how a system is supposed to behave and how it actually behaves under pressure from both sides. That’s the judgment I bring to the work.

I work with organizations navigating decisions they can’t fully delegate. Mid-market companies facing NIS2, DORA, or EU AI Act obligations without the internal expertise to govern them properly. Founders and leadership teams making platform architecture choices whose security implications won’t surface for years. Boards that need someone in the room who speaks both languages, technical and institutional, without losing precision in either direction.

The engagements vary. What doesn’t vary is the starting point: an honest assessment of where things actually are, not where they’re supposed to be.

Where most engagements begin

AI Risk & Readiness Assessment. A fixed-scope diagnostic, typically three to four weeks, built on the Operational Substrate Risk Audit methodology I publish openly.

OSRA

Apr 27
OSRA

Operational Substrate Risk Audit Framework

It examines the AI systems your organization actually runs, the ones it is about to run, and the distance between what your documentation claims and what the machines do. You receive a risk register, a prioritized remediation roadmap drawn from a catalogue of concrete actions, and a summary written for the board rather than for the security team. The methodology, scoring model, and a complete worked example are public, so you can evaluate the approach before we ever speak.

Other scoped assessments follow the same shape: a security architecture review, pre-investment technology due diligence, a regulatory readiness check before something becomes urgent.

Ongoing engagements

Fractional CISO. Senior security leadership for organizations that need CISO-level judgment without a full-time hire. Security posture assessment, governance framework development, board reporting, regulatory readiness, and the translation of technical risk into decisions that leadership can actually act on.

CTO Advisor. Work with founders and leadership teams on platform architecture, technology strategy, and the structural decisions that determine whether systems scale coherently or accumulate fragility over time. Architectural tradeoff analysis, build-versus-buy decisions, technical due diligence for investors. The CTO perspective informs the security work too: understanding what gets built is inseparable from understanding what can be protected.

Executive & Board Advisory. Direct engagement with leadership teams, boards, and audit committees on AI governance, platform risk, cybersecurity obligations, and regulatory exposure. This is the territory where CISO and CTO thinking converge, and where most organizations currently have the least clarity. Particularly relevant for organizations operating across multiple geographies or entering markets where the threat environment is unfamiliar. I also serve in non-executive director and advisory board roles.

How I work

The thinking behind these engagements is public. The Operational Substrate Risk Audit is an open methodology with a complete worked example. My book, The Split Problem, examines what we can and cannot know about AI systems. The essays apply the same judgment to cases you’ll recognize. If the way I think is wrong for your organization, you’ll know before spending a euro.

I’m based in Germany. Available globally. Working languages are English and Italian.

If you’re dealing with a problem at the intersection of technology, risk, and strategic decision-making, and you want a conversation with someone who has sat in the room where those decisions get made, I’d be glad to hear from you. A short note describing your situation is enough to start.

advisory@marcobrondani.com