— a comprehensive, collaborative system serving your business —
My mission is to make information security understandable and accessible for businesses. I help organizations set up or improve their information security program, with a focus on simplicity and business engagement.
Information security risks are like any other business risk: the business owns them and sets the priorities. Specialists advise, but decisions on risk treatment rest with the business. A pragmatic approach is essential, given how complex and intertwined information security is with all business processes.
My name is Remco Vaal, and since 2022 I have been working as an independent information security consultant. I assist organizations in organizing security not as isolated initiatives, but as one cohesive whole: clear, practical, and easily explained to both management and engineers.
The issues in my work mainly involve designing, implementing, or further developing an integrated information security program, or one or more of its core components. This includes policy & frameworks, governance, risk & compliance, architecture, specific technical measures, and/or their interrelationship. I do not implement products as an engineer, but I work closely with technical teams to ensure that choices are logical, fit into the whole, and are future-proof.
Organizations I work for are characterized by the following:
That could be a CISO, IT/Security Manager, or IT responsible person thinking: "This needs to be more professional, it can be improved, but where do we start?"
Similar situations are treated in the same manner.
Measures cover the full scope of the environment.
The entire chain and infrastructure are taken into account.
The result is demonstrable and measurable where possible.
Security is proportional to the value being protected.
Together, these five principles form the foundation for clear, reliable, and secure information security — proportional, cohesive, and demonstrable.