Trusted by European Institutions

Cybersecurity Governance & AI Risk Management

Strategic security advisory for critical information systems. We architect risk frameworks, conduct impact assessments, and ensure AI compliance at the highest institutional level.

We Work With
European Commission Directorate-General for Informatics — DIGIT S1 CyberSecurity Unit
EY Ernst & Young Luxembourg

Strategic Advisory for Information Systems Security

Risk Assessment

Systematic risk identification using ISO 27005, NIST AI RMF, and ITSRM methodologies. Threat modeling, vulnerability assessment, and risk treatment strategies.

AI Governance

ISO/IEC 42001 AI management systems. NIST AI RMF implementation. EU AI Act compliance and high-risk AI classification.

Security Frameworks

ISO 27001 alignment, NIST 800-53 control mapping, and institutional security policies. IT Security Plans for European institutions.

Regulatory Compliance

EU AI Act, NIS2, Commission Decision 46. Framework crosswalks and control mapping for multi-standard compliance.

Deep Institutional Knowledge

We operate at the intersection of cybersecurity governance, AI regulation, and European institutional requirements. Our methodologies integrate ISO management systems with NIST risk frameworks and emerging AI-specific standards.

  • ISO/IEC 27001 & 27005 — Information Security Management
  • ISO/IEC 42001 — AI Management Systems (AIMS)
  • NIST AI Risk Management Framework (AI RMF)
  • NIST Cybersecurity Framework & SP 800-53
  • EU AI Act (Regulation 2024/1689) Implementation
  • ITSRM / GovSec Institutional Methodologies
Integrated Governance Approach
1
Context & Scope
ISO 42001 AIMS scope definition, AI system inventory, regulatory mapping
2
Risk Assessment
NIST AI RMF functions: Map, Measure, Manage, Govern
3
Control Framework
ISO 27001 + NIST 800-53 controls with AI-specific extensions
4
Compliance Alignment
EU AI Act requirements mapped to management system controls
MS

Marco Sarzina

Founder & Principal Consultant

Senior IT security consultant specialized in cybersecurity governance for European institutions. Expert in ISO/IEC 27001, ISO/IEC 42001 AI management systems, and NIST frameworks including the AI Risk Management Framework and Cybersecurity Framework.

Currently engaged on European Commission DIGIT projects, integrating AI governance standards with institutional security requirements and EU AI Act compliance.

PMP PRINCE2 Practitioner MSP Practitioner AgilePM PRINCE2 Agile
View full profile on LinkedIn

Ready to Strengthen Your Security Posture?

We engage on select strategic projects where our expertise creates maximum impact. Contact us to discuss your security governance challenges.

mailto@retoken.info
Italy • Belgium • Luxembourg
Start a Conversation