Berlin, Berlin, Germany
Most specialists tunnel down a single shaft, deep, but narrow. I operate at the harder, scarcer intersection: standing above several distinct disciplines at once and seeing how they connect. Where the legal requirement meets the technical reality meets the business goal, and someone has to tell you what to actually do about it. I am brought in at the decision level, where the structural calls are made. For three decades, that pattern has held across banking, insurance, aviation, energy, and the public sector: translating complex, massive environments into clear, board-level judgment. That is what Aliventi Advisory does. One thing, done rarely well: synthesis. Engagements tend to follow a recurring shape. They begin with a narrow, urgent technical brief, an EU AI Act classification, a NIS2 or DORA readiness review, a security architecture rescue, and broaden once it is clear that what the client values is the judgment, not the task. The relationship settles into its natural form: trusted adviser to the executive. But systems engineering principles don’t care about scale. That pattern doesn't stop at the enterprise boundary. Alongside commercial advisory work, the practice maintains an active, independent research track focused on the mathematical and computational foundations of systems, semantics, and emergent compute. Alongside client work, I maintain an independent research practice in foundational AI, semantic computation, and complex systems. The same architectural instincts that produced ISADORA (a compliance-framework architecture, 2016) led, over fourteen years of structured iteration, to a body of formal work now approaching open publication: frameworks for deterministic semantic encoding, governance-enforced computation, and operator-based systemic risk modelling. Based between Warsaw, Dublin and Germany. On-site as a default: advisory works when you're in the room. Feel free to get straight to the point in whichever language suits the complexity best: English, German, Dutch, or Polish. Let's start with a conversation.
Independent strategic advisory at the decision level: where the legal requirement meets the technical reality meets the business goal, and someone has to say what to actually do about it. Aliventi Advisory exists for one thing, done rarely well: synthesis. The ability to stand above several disciplines at once: AI governance, security architecture, regulatory compliance, enterprise strategy, and see how they connect. The deliverable is not a document. It is judgment, made legible to everyone who needs to act on it. Current advisory focus: EU AI Act readiness and classification, DORA and NIS2 regulatory alignment, ISO 42001 and ISO 27001 governance design, and board-level responsible AI strategy. Engagements begin narrow and technical, and tend to broaden once it becomes clear that what the client values is the judgment, not the task. Based between Dublin, Warsaw and Germany.
Brought in for NIS-2 compliance at a German food distributor with zero security architecture, zero NIS-2 awareness, and a stack of emerging regulatory problems nobody had mapped yet. Built the programme from nothing, against BSI Standards 200-1 to 200-4 and IT-Grundschutz, not generic frameworks, while systematically resolving every problem that surfaced along the way. And problems surfaced constantly. Peppol obligations appearing. xRechnung and ZUGFeRD compliance gaps in the e-invoicing chain. An EDI provider carrying operational risk that needed replacing mid-programme. Software development partners requiring continuity assessment. An ERP relationship that needed honest evaluation. None of these were in the original brief. Every one of them got addressed, within my domain or by identifying the responsible actors and making sure it landed on the right desk with the right urgency. The advisory style is open: the objective is a given, but the path toward it gets analysed for what actually works. Quick fix or sustainable solution: that's a mode selector, chosen deliberately per problem, not by default. Close coordination with the business owner and senior management throughout, because compliance without executive engagement is theatre. The real shift came from recognising that a pure NIS-2 exercise is a cost. So I turned it into something else: a dual track. Compliance first: real compliance, built to pass a BSI audit, not the management illusion of compliance. Architecture second: an enterprise governance baseline built on the same BSI standards, where NIS-2 becomes the first output of a framework that serves the organisation long after the auditor leaves. The result: a company moving from mid-size operations to enterprise-grade governance, with a tangible deliverable that creates value for the business.
Brought in by an NBB-supervised insurer to resolve critical audit findings in IT security and architecture under regulatory pressure. The engagement was driven by the National Bank of Belgium's supervisory expectations, within a delivery window that a Big Four team of eight had not closed in twelve months. Authored the data-anonymisation governance framework that became the milestone deliverable: completed in seven weeks. Repositioned Enterprise Security Architecture within the organisation's governance model, shifting it from a technical function to a risk-informed, board-visible discipline. Introduced structured impact analysis (BIA, RIA, SIA) into project and change delivery, connecting security decisions to business outcomes rather than compliance checklists. Operated across NBB Circulars, Solvency II, DORA, and Belgium's CyFUN guidance: drawing directly on prior regulatory experience under BaFin (Germany) and DNB (Netherlands), where comparable instruments apply within the same Solvency II landscape.
As an experienced Information Security Consultant, I acted as an external advisor on a wide range of information security topics, primarily focusing on tactical and operational improvements. My main tasks involved addressing audit findings to ensure improvements could be demonstrated in subsequent audits. In my role, I raised awareness of information security issues and aligned security practices with the BSI IT Grundschutz Catalog, BaFIN, and MaRISK requirements. I engaged in technical tasks such as evaluating software solutions, drafting test plans, and compiling comprehensive test data sets. My advisory extended to the Digital Operational Resilience Act (DORA) and Regulatory Technical Standards (RTS), assisting management in planning and workload assessment. Key achievements included: Developing extensive test sets and documentation for solution evaluation. Writing model documents for security architecture guidance. Identifying technological weaknesses and providing mitigation guidance. Additionally, I facilitated workshops and individual consultations to embed security practices into project management, conducted trainings on frameworks like SABSA, and proactively addressed audit findings to ensure continuous improvement. My efforts significantly aided the bank in achieving robust information security measures and regulatory compliance.