1 – Consulting activities in the fields of IT / Information Security and operational IT security

  • Risk and IT Management Support: Providing assistance for risk and IT management functions,
  • Comprehensive and Specific IT and Information Security Risk Analysis: Analyzing risks related to IT and information security comprehensively and specifically,
  • Design and Implementation of IT and Information Security Control Plans: Creating and implementing control plans for IT and information security,
  • Internal and External Audit Implementation and Follow-Up Recommendations: Executing internal and external audits and providing follow-up recommendations with action plans,
  • Monitoring Compliance with Applicable Regulatory Standards: Ensuring compliance with relevant regulatory norm.

2 - ICT Risk Management - Internal Control

  • Governance, Risk, and IT Compliance Assessment and Implementation: Evaluating and establishing governance, risk management, and an IT control environment or Information Security (e.g., implementing a security strategy),
  • Implementation of IT Management Processes (e.g., ITIL Service Support – Incident, Problem, Change Management): Putting in place processes for managing IT services,
  • Regulatory Compliance for IT and Information Security Processes or Activities (e.g., DORA; NIS2):Ensuring compliance with regulations related to IT and information security

3 - IT Management and Chief Internal Audit support

IT Management support

  • Operational Implementation of IT Strategic Plans: Putting into practice the strategic plans related to IT,
  • Ad Interim Operational IT Responsibility: Temporarily taking on an operational IT role,
  • Internal Coordination and Monitoring Activities: Managing and coordinating internal processes and activities and tracking progress.
  • Project Management and Oversight: Handling project management tasks and ensuring successful execution.

Chief Internal Audit Support

  • Development of an IT / Information Security Audit Framework: Creating a framework for conducting audits related to IT and information security,
  • Design of Multi-Year IT / Information Security Audit Plans: Developing audit plans spanning multiple years for IT and Information Security,
  • Planning, Coordination, and Audit Oversight: Managing the planning, coordination, and monitoring of audit activities,
  • ‘C-Level’ or Operational Reporting: Providing reports at the executive level or operational level.

4 - IT Audit and ICT Maturity evaluation

  • IT Process (Cybersecurity) Analysis: Examining and evaluating IT and cybersecurity processes,
  • Technical Review of IT and Security for Critical Applications or Infrastructures: Assessing the technical aspects of IT and security for critical applications or infrastructure,
  • Execution of IT Process Maturity Assessment Missions: Conducting missions to evaluate the maturity of IT processes,
  • Compliance Mission for IT Requested by a Regulatory Authority (e.g., CSSF – High Privilege Account Management): Fulfilling compliance missions related to IT as requested by a supervisory authority,
  • Analysis of IT & Security Underpinnings and Risks Associated with Business Processes: Investigating IT and security aspects underlying business processes (e.g., analyzing IT and information security for payment processes, conducting technical reviews of AML applications),
  • Execution of Integrated Audit Missions (i.e., IT and Security Assessment in the Context of Functional Business Audits): Carrying out integrated audit missions, evaluating IT and security within functional business audits.