Information security for senior leadership and people in the public eye

«Who can I trust?»

Information security · since 1995

It is the question almost every engagement starts from. Nearly always in those words. It comes from a chief executive before a delicate decision, from a board with nobody around the table it can really rely on for this, from someone in the public eye when something private starts to travel. It has very little to do with technology.

Where decisions get made

Decisions that matter are no longer taken without somebody in the room who can read technical risk. That changed in the last few years, and it will not change back.

A board today signs off on investments, acquisitions and technology suppliers that can be worth as much as a balance sheet. A chief executive signs statements about data protection they are personally answerable for. A public figure stakes a reputation on a file that was never meant to travel. In each of these cases what is needed is someone independent, with nothing to sell.

Boards and advisory boards

The independent voice at the table

The appointment comes as the security expert supporting the chief executive, on boards and on the advisory boards of industrial groups. The call is to help decide, not to deliver training: when what is on the table is a technology investment, an acquisition, a critical supplier or an incident already under way. The mandate on a board →

Funds and investors also ask for a view on whether a technology company can genuinely do what it claims, and whether what it claims holds together. It is the same examination that later reaches a boardroom. Technology due diligence →

On these questions there is often nobody around that table to be relied on, because almost everyone has something to sell. Whoever sits there as an independent director is not selling software.

Chief executives

One more certainty before signing

Responsibility for information security now rests personally with the people at the top. It is no longer a question of reputation or budget: it has a name attached, and it is the name of whoever is in charge.

Before an executive tells the market, a regulator or a board that the data is safe, somebody has to be able to verify that it actually is. That check belongs to someone with no stake in the outcome, and it goes in writing even when the answer is unwelcome.

There is also the privacy of people who live in the public eye: recognisable faces, parliamentarians, business owners, artists. How those cases are handled

Since 1995
First security program on a cover disc
PC Magazine no. 100 · Feb 1996
Patents
US 12,596,770 · EP 4,427,154
USPTO and EPO · granted
Institutions
European Commission
European Defence Agency
Defence
Military bodies and public institutions
Work not publicly documented
Next session
12–13 October Milan

Two days on who, inside an organisation, is allowed to know what — and on what it entails to hold the keys.

Twelve participants at most · held in Italian · venue given to those enrolled · also behind closed doors on site
Ask for a place
Frequently asked

The questions that come
before a phone call.

What exactly do you do?

Information security, since 1995, in four forms. A seat on a board or advisory board as the independent voice supporting the chief executive. The privacy of people who live in the public eye. Establishing, for funds and investors, whether a technology company can genuinely do what it claims. And two training programmes for people who hold information that is not their own.

What happens to what you are told?

It does not leave the room. The confidentiality agreement is signed before any document is received, and it runs in both directions. Not one client is named on this site, and none will be: the best work is the work nobody ever heard about. For a first approach there are three channels, in increasing order of confidentiality, ending in an encrypted one.

Is there a conflict of interest?

One, and it is declared. Valerio Pastore is co-founder and technical director of CyberGrant, and the patents listed in the public record are his. When he sits on a board that technology is not among the options: should an assessment reach the table, he recuses himself and asks for the recusal to be minuted. The condition is set before an appointment is accepted, not after.

Why is an AI agent a risk to corporate data?

Cloud platforms do encrypt data, but the platform holds the keys rather than the data itself, so it decrypts for anyone it considers authorised. An agent acting on an employee's behalf is, as far as the system is concerned, that employee. It reads everything in the clear within seconds and raises no alert. This was demonstrated live, in front of an audience of security leaders.

Does anti-phishing training still work?

Less and less, if it teaches people to spot the artefact. Conventional training drills the odd link, the wrong sender or the spelling mistake: signals generative AI has erased, because those messages are now written better than ours. What still works is teaching the mechanism. Phishing, smishing and social engineering always pull the same three levers: authority, urgency, reciprocity. Anyone who recognises the lever also recognises the attack they have never seen before.