Information security · since 1995
It is the question almost every engagement starts from. Nearly always in those words. It comes from a chief executive before a delicate decision, from a board with nobody around the table it can really rely on for this, from someone in the public eye when something private starts to travel. It has very little to do with technology.
Decisions that matter are no longer taken without somebody in the room who can read technical risk. That changed in the last few years, and it will not change back.
A board today signs off on investments, acquisitions and technology suppliers that can be worth as much as a balance sheet. A chief executive signs statements about data protection they are personally answerable for. A public figure stakes a reputation on a file that was never meant to travel. In each of these cases what is needed is someone independent, with nothing to sell.
The appointment comes as the security expert supporting the chief executive, on boards and on the advisory boards of industrial groups. The call is to help decide, not to deliver training: when what is on the table is a technology investment, an acquisition, a critical supplier or an incident already under way. The mandate on a board →
Funds and investors also ask for a view on whether a technology company can genuinely do what it claims, and whether what it claims holds together. It is the same examination that later reaches a boardroom. Technology due diligence →
On these questions there is often nobody around that table to be relied on, because almost everyone has something to sell. Whoever sits there as an independent director is not selling software.
Responsibility for information security now rests personally with the people at the top. It is no longer a question of reputation or budget: it has a name attached, and it is the name of whoever is in charge.
Before an executive tells the market, a regulator or a board that the data is safe, somebody has to be able to verify that it actually is. That check belongs to someone with no stake in the outcome, and it goes in writing even when the answer is unwelcome.
There is also the privacy of people who live in the public eye: recognisable faces, parliamentarians, business owners, artists. How those cases are handled
Information security, since 1995, in four forms. A seat on a board or advisory board as the independent voice supporting the chief executive. The privacy of people who live in the public eye. Establishing, for funds and investors, whether a technology company can genuinely do what it claims. And two training programmes for people who hold information that is not their own.
It does not leave the room. The confidentiality agreement is signed before any document is received, and it runs in both directions. Not one client is named on this site, and none will be: the best work is the work nobody ever heard about. For a first approach there are three channels, in increasing order of confidentiality, ending in an encrypted one.
One, and it is declared. Valerio Pastore is co-founder and technical director of CyberGrant, and the patents listed in the public record are his. When he sits on a board that technology is not among the options: should an assessment reach the table, he recuses himself and asks for the recusal to be minuted. The condition is set before an appointment is accepted, not after.
Cloud platforms do encrypt data, but the platform holds the keys rather than the data itself, so it decrypts for anyone it considers authorised. An agent acting on an employee's behalf is, as far as the system is concerned, that employee. It reads everything in the clear within seconds and raises no alert. This was demonstrated live, in front of an audience of security leaders.
Less and less, if it teaches people to spot the artefact. Conventional training drills the odd link, the wrong sender or the spelling mistake: signals generative AI has erased, because those messages are now written better than ours. What still works is teaching the mechanism. Phishing, smishing and social engineering always pull the same three levers: authority, urgency, reciprocity. Anyone who recognises the lever also recognises the attack they have never seen before.
Why defending the network is no longer enough, and what happens when an AI agent reads your information. Including the demonstration run live in front of security leaders.
Read the thesis →Keeping a secret is not a matter of character: it is a discipline, and it can be learned. Nobody betrays out of bad faith — information leaves through courtesy, through vanity, through haste.
The two programmes →Patents filed and granted, international awards, companies, institutions. Including the 2006 application dropped over the cost of the national phases.
Open the record →