ABOUT
KASIS
I'm a cybersecurity and GRC professional working across information security, governance, risk, compliance and auditing.
My work centers on helping organizations understand where they stand: translating regulatory frameworks and technical risk into governance structures, policies and controls that hold up under audit. That means moving fluently between the language of standards bodies, the priorities of leadership, and the day-to-day realities of the people who have to operate the controls.
My approach is deliberately grounded: assess honestly, document clearly, and build security programs that are sustainable rather than performative. I stay close to the standards I audit against (ISO/IEC 27001, 27701 and 42001 among them) and treat continuous learning as part of the job, not a side project.
Where I work.
Hover or tap a discipline to expand it.
Off the clock.
This space is for the parts of my life outside client work: hobbies, side interests, learning in progress, or anything else I choose to share. Content coming soon.