top of page

work with nuno

make the Invisible, Visible. Turn Risk, into Action.

I partner with leaders to surface what matters and translate complex cybersecurity, regulatory and operational requirements into clear priorities, accountable governance and executable action.

As a Fractional CISO and Cyber Risk Advisor, I help regulated organizations integrate cyber risk into enterprise decision-making and resilience.

Nuno2.png
Make the Invisible, Visible.

Nuno Costa

The risks organisations cannot always see

Between technology and governance

The risks that matter most sit between policy and execution, assumptions and evidence. That is where I work to help leaders surface what matters.

01

Strategic Governance

Translating complex regulatory requirements into clear priorities and accountable action.

02

Enterprise Decision

Integrating cybersecurity risk into executive decision-making and internal governance.

03

Operational Evidence

Building defensible evidence and preparing for regulatory and assessment scrutiny.

How Nuno helps

Strengthening Resilience

I help regulated organizations integrate cyber risk into enterprise decision-making, strengthen resilience, build defensible evidence and prepare for regulatory and assessment scrutiny through expert Fractional CISO and Cyber Risk Advisory services.

Integration

Cybersecurity risk integrated into ERM and executive decision-making.

Preparation

Ready for CMMC Level 2 and NIST SP 800-171 assessments.

Definition

Defining CUI boundaries, data flows, and control ownership.

Accountability

Preparing management bodies for NIS2 accountability and governance.

Areas of support

Core Strategic Focus Areas

01
02
03
04
Risk Integration
Assessment Readiness
Governance Transformation
Operational Resilience

Integrating cybersecurity risk into ERM and executive decision-making to ensure total organizational alignment.

Preparing organizations for CMMC Level 2, NIST SP 800-171 assessments, and regulatory scrutiny.

Establishing or improving ISO/IEC 27001-aligned security governance and NIS2 accountability for management bodies.

Defining CUI boundaries, data flows, control ownership, and strengthening incident governance and regulatory readiness.

ai-generated-IMAGE.jpg

Ways to work together

Flexible Advisory Partnerships

I am available for fractional leadership, advisory retainers, assessment-readiness programmes, governance transformation and strategic partnerships. My work draws on CMMC, NIST SP 800-171/171A, NIST RMF, CSF 2.0, IR 8286, SP 800-53/53A, ISO 31000, ISO/IEC 27001/27005/27035, ERM, GRC, NIS2, and data protection.

Fractional Leadership
Advisory Retainers
Readiness Programmes
Strategic Partnerships

Final invitation to connect

Turn requirements into accountable governance

Let's explore how to empower your leadership.

Experience and credibility

With more than two decades of experience, I have worked across information security governance, cyber risk, data protection, digital transformation and operational resilience in public administration, defence, aerospace and other regulated environments. I also teach cybersecurity governance, ERM, CMMC and NIST subjects in postgraduate and professional education. Combining consulting, implementation, research and teaching allows me to communicate effectively from control owners to executive leadership.

Nuno5.png
bottom of page