Information security · Consulting · Training

Security without jargon
and without scaremongering

I translate regulatory requirements into a security strategy that fits your business – understandable, prioritised and workable day to day. More than nine years of experience from complex corporate structures, now independently at your side.

View services → Self-check: free, takes 2 minutes, runs entirely in your browser – no data transmitted.

  • CISSP
  • ISO 27001 Lead Auditor
  • IT-Security Manager (TÜV)
Can Yildiz, information security consultant

Where I usually start

30 minutes, free and without obligation. Afterwards you will know whether and how I can help.

Are we in scope for NIS2 – and from when?
Where do we really stand against ISO 27001?
Which measures deliver the most security per euro?

9+

Years of experience in information security

CISSP

Certified by (ISC)²

27001

ISO Lead Auditor

TÜV

IT Security Manager

Services

Security that works in everyday practice

From the applicability analysis to hands-on implementation – you decide how far I accompany you.

Interim management

Experienced security leadership on a temporary basis – effective from day one.

Talks & speaking

Cybersecurity explained clearly – for expert audiences and management alike.

Can Yildiz, information security consultant

About

Can Yildiz – consultant, trainer and speaker

Nine years of information security in corporate environments taught me one thing: security rarely fails because of technology, but because of translation work.

As an independent consultant I help companies translate regulatory requirements into a business-oriented security strategy. My network in the security industry keeps me close to current trends and specialist fields – and my certifications make that expertise well-founded and verifiable. That way I make decisions that hold up technically as well as economically.

I am convinced that continuous learning and sharing knowledge are decisive for success in the fast-moving world of IT security.

More about my background

How I work

Four steps to resilient security

A transparent process with clear results – you always know what we are working on.

1

Initial consultation

Free and without obligation: in 30 minutes we clarify your situation, the trigger and the outcome you want.

2

Analysis

I review documentation, conduct interviews and determine your maturity against the standard relevant to you.

3

Roadmap

You receive a prioritised list of measures with effort, ownership and a realistic timeline.

4

Implementation

On request I support the implementation hands-on – as project lead, interim security officer or sparring partner.

Training

Knowledge that stays in-house

In-house training for your teams – on site or remote, tailored to your industry.

Advanced · 1 day including a tabletop exercise

Incident response basics

What happens in the first hours of a security incident – and who makes which decision.

Frequently asked questions

Answers up front

Your question is not listed? Drop me a line – I usually reply within one working day.

Ask a question

NIS2 covers far more companies than its predecessor – what counts is your sector, headcount and turnover. In an applicability analysis we usually clarify within a few days whether and to what extent you fall under the rules, and which obligations follow concretely.

Often yes – especially when customers or tenders require proof. What matters is a sensibly cut scope: a lean scope that is honestly lived is worth more than a large one that only exists on paper.

After a free initial consultation comes an analysis phase, from which a prioritised roadmap emerges. Whether I then support the implementation is up to you – many clients take the first steps themselves and bring me in for reviews and critical milestones.

Both. Workshops, audits and training often take place on site, while ongoing collaboration is mostly remote. Being based in Oberursel in the Rhine-Main region means short distances to Frankfurt and much of Hesse.

Billing is by daily rate or as a fixed price for clearly defined packages such as a gap analysis. You always receive a transparent effort estimate before the project starts – with no hidden items.

Yes, as an external security officer or interim CISO. That makes particular sense when the capacity or certification is missing internally, but the role has to be filled for regulatory reasons.

Let us talk about your situation

30 minutes, free and without obligation. You describe the situation, I tell you honestly what I make of it.