whoami
Infosec practitioner with 25+ years of experience | Since 2019, Group CISO of an international group (7000+ employees). Formerly: head of operational security, head of security projects & governance at a central bank | Expertise: risk analysis, pentests, incident and crisis handling, CTI, security policies, definition of secure systems, applied cryptography | Strong experience in international contexts | Lecturer at university level – Paris Sorbonne Nord & Nanterre | Conference speaker | Research activity | 2015 GIAC web Application Pentester & 2016 Security/Safety management ESCP certified | Multilingual (French, Spanish, English, German)
I’m interested in all types of risk, not just IT risks. And I believe that when it comes to security, we must do more than just act quickly and well. We have to think security. Security is not inherently good; security is not a “right”; security is not just about reducing risk; the perception of security is never objective. Safety is a way of managing risk. And we need to think about how we manage things.
No cookies, no adds, no infinite scroll.
This website is up since 27th January 2000 (https://web.archive.org/web/20071207180406/http://www.cryptosec.org/index.php3 )
Mastodon:
https://infosec.exchange/@cryptosec
LinkedIn:
https://www.linkedin.com/in/rossenbach/
Un de mes premiers codes, Fortran, fin du XXe siècle
Myself, wearing the truth about my job
