Eerlijk Inzicht.
Sterkere Beveiliging.
I get you audit-ready. Audit & GRC, hands-on tech or training.
Ik maak uw organisatie audit-klaar. Audit & GRC, hands-on techniek of training.
What I Can Do for You
Mijn Dienstverlening
IT auditor by trade, with PCI DSS as my niche specialism and a broad, hands-on technical base around it. And to be frank: some problems genuinely need a deep specialist, and I'll tell you when that's the case. But most of the time you don't need Superman, you need a jack of all trades who speaks auditor, engineer and program manager.
IT-auditor van huis uit, met PCI DSS als nichespecialisme en daaromheen een brede, hands-on technische basis. En eerlijk is eerlijk: sommige vraagstukken vragen echt om een diepgespecialiseerde expert, en dat zeg ik er dan ook gewoon bij. Maar meestal heeft u geen Superman nodig, maar een duizendpoot die auditor, engineer én programmamanager spreekt.
Audit Preparation & Readiness
I know exactly what auditors look for. I have years of experience as an assessor, with PCI DSS as my specialism (former QSA). I prepare your organization end-to-end: gap analysis, evidence gathering, control testing, and remediation guidance. PCI DSS, ISO 27001, SOC 2, NIS2. Ready when it matters.
Auditvoorbereiding & Gereedheid
Ik weet precies waar auditors op letten. Jarenlange ervaring als assessor, met PCI DSS als specialisme (voormalig QSA). Ik bereid uw organisatie volledig voor: gap-analyse, bewijsverzameling, control testing en begeleiding bij het oplossen van bevindingen. PCI DSS, ISO 27001, SOC 2, NIS2. Klaar wanneer het erop aankomt.
Interim CISO / ISO / CSO
Need security leadership but no room for a full-time role? I step in as your interim CISO, Information Security Officer, or Chief Security Officer. Strategic direction, board-level reporting, policy development, and day-to-day security governance, for as long as you need it.
Interim CISO / ISO / CSO
Security-leiderschap nodig, maar geen ruimte voor een fulltime functie? Ik neem de rol op mij van interim CISO, Information Security Officer of Chief Security Officer. Strategische koers, rapportage op directieniveau, beleidsontwikkeling en dagelijkse security governance, zolang u het nodig heeft.
Control Frameworks & Policies
Together we build a control framework that fits your organization. From COBIT and NIST CSF mappings to practical policy sets, risk registers, and control matrices, embedded in your day-to-day operations.
Control Frameworks & Beleid
Samen bouwen we een control framework dat past bij uw organisatie. Van COBIT- en NIST CSF-mappings tot praktisch beleid, risicoregisters en control matrices, ingebed in uw dagelijkse bedrijfsvoering.
Compliance Automation & Analytics
Your people should be doing their jobs, not ticking compliance checklists by hand. I automate control monitoring, build data analytics pipelines, and set up continuous dashboards, so audit prep takes days, not months.
Compliance Automatisering & Analytics
Uw medewerkers moeten hun werk doen, niet handmatig compliance-lijstjes afvinken. Ik automatiseer control monitoring, bouw data-analysepipelines en richt doorlopende dashboards in, zodat auditvoorbereiding dagen kost in plaats van maanden.
Hands-on Implementation: Where Compliance Meets Deployment
Already know what needs to be implemented, but lack the hands to actually do it? That's where I come in. I bring the technical skills and the experience, as implementer or technical program manager, on-premises or in the cloud, preferably with open-source tooling. Short-term projects, hands-on. Get in touch.
Proficient across the stack, and honest about the point where a niche expert adds more value than I do.
Hands-on Implementatie: Waar Compliance en Techniek Samenkomen
Weet u al wat er geïmplementeerd moet worden, maar ontbreken de handen om het echt te doen? Daar kom ik in beeld. Ik breng de technische kennis en de ervaring mee, als implementeur of technisch programmamanager, on-premises of in de cloud, bij voorkeur met open-source tooling. Kortlopende projecten, hands-on. Neem contact op.
Breed inzetbaar, en eerlijk over het moment waarop een nichespecialist meer waarde toevoegt dan ik.
Knowledge transfer, short and focused. No slide marathons, but working sessions built around your own situation, in small groups, on-site or remote.
Kennisoverdracht, kort en gericht. Geen slidemarathons, maar werksessies rond uw eigen situatie, in kleine groepen, op locatie of remote.
PCI DSS in Practice
For teams that build, run or defend cardholder data environments. Scoping, segmentation, the twelve requirements translated to daily operations, and the evidence an assessor expects to see. A solid foundation for anyone working toward PCIP.
PCI DSS in de Praktijk
Voor teams die kaartdataomgevingen bouwen, beheren of beveiligen. Scoping, segmentering, de twaalf requirements vertaald naar de dagelijkse praktijk, en het bewijs dat een assessor verwacht te zien. Een stevige basis voor wie richting PCIP wil.
Audit-Ready Workshop
Your audit is coming. We walk through what auditors actually ask, practice the interviews, and check your evidence against expectations. You leave knowing where you stand, and what to fix first.
Audit-Ready Workshop
De audit komt eraan. We nemen door wat auditors écht vragen, oefenen de interviews en toetsen uw bewijsvoering aan de verwachtingen. U weet daarna waar u staat, en wat u als eerste moet oplossen.
Security Awareness
Your people are your first line of defense, not the weakest link. A practical session on phishing, social engineering, passwords and MFA, and what to do when something looks off. Tailored to your organization, no scare stories.
Security Awareness
Uw medewerkers zijn uw eerste verdedigingslinie, niet de zwakste schakel. Een praktische sessie over phishing, social engineering, wachtwoorden en MFA, en wat te doen als iets niet klopt. Toegespitst op uw organisatie, zonder bangmakerij.
Technical Sparring Session
A consultancy discussion, not a lecture. Bring your architecture or development plans; together we assess the security, compliance and business impact before you commit budget. Cheaper than finding out afterwards.
Technische Sparringsessie
Een adviesgesprek, geen college. Breng uw architectuur- of ontwikkelplannen mee; samen toetsen we de security-, compliance- en businessimpact vóórdat u budget vastlegt. Goedkoper dan er achteraf achter komen.
How I Work
Mijn Werkwijze
Every engagement starts with a no-commitment assessment. What comes out of it is yours to act on, or we continue together.
Elke opdracht begint vrijblijvend met een inventarisatie. Wat daaruit komt kunt u zelf oppakken, of we gaan samen verder.
Assess
We map your current state: existing controls, gaps, compliance obligations, and upcoming audit timelines. Honest about where you stand.
Inventariseren
Samen brengen we uw huidige situatie in kaart: bestaande controls, hiaten, compliance-verplichtingen en aankomende audittermijnen. Eerlijk over waar u staat.
Build
Design control frameworks, write policies, set up automated monitoring, and create the evidence structure auditors expect to see.
Opbouwen
Control frameworks ontwerpen, beleid schrijven, geautomatiseerde monitoring inrichten en de bewijsstructuur opzetten die auditors verwachten.
Prepare
Mock audits, evidence review, team coaching, and auditor engagement. I connect you with the right audit firm and manage the prep process.
Voorbereiden
Proefaudits, bewijsreview, teamcoaching en afstemming met de auditor. Ik breng u in contact met het juiste auditkantoor en begeleid de voorbereiding.
Support
Ongoing advisory during and after the audit. Remediation support, continuous monitoring, and keeping you compliant year-round.
Ondersteunen
Doorlopende advisering tijdens en na de audit. Ondersteuning bij remediatie, continue monitoring en het hele jaar door compliant blijven.
Honest. Clear. Pragmatic.
Eerlijk. Duidelijk. Pragmatisch.
Auditor's Perspective
Years on the other side of the table taught me how assessors think, what they prioritize, and where organizations typically fall short. That perspective now works in your favor.
Auditorperspectief
Jarenlange ervaring als assessor leert je precies waar organisaties struikelen en hoe toetsers hun oordeel vormen. Die kennis zet ik nu in vóór u.
Technical Depth
Infrastructure, networking, security engineering, and a hands-on understanding of software development and complex architecture. Deep enough to challenge any technical team, sharp enough to translate the findings into boardroom language.
Technische Diepgang
Van infrastructuur en netwerken tot security engineering, softwareontwikkeling en complexe architecturen. Technisch sterk genoeg om mee te kijken met elk team, zakelijk scherp genoeg om het helder op directieniveau te brengen.
Pragmatic
Every recommendation I make is something your team can actually implement and maintain. No shelfware, no box-ticking. Only measures that hold up under scrutiny.
Pragmatisch
Wat ik adviseer, kan uw team ook echt uitvoeren en volhouden. Geen papieren tijgers, geen vinkjeslijstjes. Alleen maatregelen die overeind blijven bij een toetsing.
Who Is Behind Be Frank
Over Mij
Daniel van den Akker
My career started in the engine room: infrastructure, networking, and security engineering. A personal passion for software development means I'm equally at home reading code, reviewing middleware, and understanding complex application architectures. I moved into IT audit and compliance as a PCI DSS Qualified Security Assessor, conducting assessments and advisory engagements across industries. That means I deliver value on the shop floor and in the boardroom alike.
Ik ben begonnen in de techniek: infrastructuur, netwerken en security engineering. Daarnaast ontwikkelde ik een sterke affiniteit met softwareontwikkeling, waardoor ik net zo goed mijn weg vind in code, middleware en complexe applicatielandschappen. Vanuit die technische basis maakte ik de stap naar IT-audit en compliance als PCI DSS Qualified Security Assessor, met assessments en adviesopdrachten in uiteenlopende sectoren. Daardoor lever ik waarde op zowel de werkvloer als in de directiekamer.
I hold a Bachelor's degree in Network Infrastructure Design (ing.) from Hogeschool Zuyd and a Master's degree in IT Auditing from TIAS School for Business and Society (Tilburg University). Current certifications: CISA and CISSP. Previously held: PCI DSS QSA, 3DS QSA, CEH, CCNA, CCNP, LPIC-1, MCSA, and MCSE. Broad in knowledge and experience.
Ik ben afgestudeerd als ing. in Network Infrastructure Design aan Hogeschool Zuyd en heb een Executive Master in IT Auditing behaald aan TIAS School for Business and Society (Tilburg University). Mijn huidige certificeringen zijn CISA en CISSP. Eerder behaalde ik onder meer PCI DSS QSA, 3DS QSA, CEH, CCNA, CCNP, LPIC-1, MCSA en MCSE. Breed in kennis en ervaring.