Gianluca PavoneSecurity and Data Protection

bio

I have never managed to be interested in only one thing. Technology came first, when I was a teenager. It started with gaming, which turned into writing code, taking machines apart, and trying to work out what this internet thing actually was. Law came later, for the same reason. Another system, with its own rules and its own ways of getting around them.

The two stayed separate for years. What changed was not one thing. Security became something companies had to answer for, people began asking where their data went, and AI arrived with questions nobody had rules for yet. All of it pointed the same way: the law had to be in the room where the systems get built. Sorry about that.

That is what I have done ever since. Building information security management systems and AI governance inside companies, running privacy and security assessments, and lately making my own tools for the parts of the job I come back to every week. The instinct has not changed since I was a teenager with a keyboard: if a thing is interesting, take it apart and find out how it works.

Mathematics and philosophy are the next things I want to learn properly. Same reason as everything else here.

certifications

  • ISO/IEC 27001 Lead Auditor
  • ISO/IEC 42001 AI Management Systems

expertise

The kinds of work I spend my time on.

  • 01

    ISO/IEC 27001 & ISMS operations

    Gap assessments, ISMS scoping, Statement of Applicability authoring and pre-certification dry runs, internal audits, awareness training, vendor risk.

  • 02

    ISO/IEC 42001 & AI governance

    AI inventory and classification, risk assessment under ISO 42001 and the EU AI Act, governance frameworks, and control design for AI management systems.

  • 03

    Incident response

    Incident response playbooks, tabletop exercises, post-incident reviews, personal-data-breach assessment and notification timing.

  • 04

    Privacy & security by design

    Reviewing product designs for privacy and security implications, threat modelling, DPIAs, records of processing, transfer assessments, data subject request handling.

contact