Welcome to Illuminator
By Jakob Illum
Business Resilience is not something that lives in the IT department or the annual report by the CISO to the Board of Directors. It is much more than that.
Professionals acknowledge that you need to balance and focus on the trinity of People, Processes and Technology but for this to be effective, you must focus on culture first.
Also, senior management needs to ensure that the focus isn’t only on ensuring earnings are up and costs are low but also that the company is sustainable. In the current threat landscape, Change Management (not the ITIL version) is probably the most overlooked discipline in healthy Cyber Security.
Expertise in IT Operations and Information Security
With more than 25 years of experience within the fields of IT Operations and Information Security, I offer expert consultancy and interim management in both areas, focusing on safeguarding critical infrastructure with adherence to European regulations and industry standards.
Achieve Excellence in Security and IT Operations
The three pillars of a technically robust company are comprised of Change Management, a structured approach to IT Operations Information Security and Enterprise Risk Management, ensuring that you focus on the right risks to the company without overspending.
Change Management
Put the business back in the drivers seat. By utilizing frameworks like ISO22301, ensure the business takes ownership of the business critical processes including any supporting IT Services and sub processes. Perform Business Impact Assessment on business processes and identify any element that can endanger the process. Perform risk analysis on any IT Services that supports the business process.
Comprehensive IT Operations and Security Management
Let IT do what they do best and demand reporting of status and progress. By leveraging frameworks like ITIL that optimize your IT processes, improving efficiency and operational resilience in complex environments. Use ISO27001 or NIST to ensure safeguards and controls operate as expected and document and report from your ISMS.
Enterprise Risk Management
Information Security risks are not always the most important to address first. Use frameworks like ISO31000 to ensure proper risk management across the different types of risk. ERM is a structured way of managing a modern company. It ensures that the highest risks gets the right attention whether it is a market, credit or InfoSec risk. Use ISO27005 or NIST for the Information Security risks.
