Michael Georg Speller

Michael Georg Speller

Metropolregion Sankt Gallen
3547 Follower:innen 500+ Kontakte

Info

As your "Advocatus Diaboli", I uncover weaknesses and vulnerabilities in your internal or…

Serviceleistungen

Artikel von Michael Georg Speller

Beiträge

Aktivitäten

Anmelden, um alle Aktivitäten zu sehen

Berufserfahrung

  • GREY APE Grafik
  • -

  • -

  • -

  • -

  • -

  • -

  • -

  • -

  • -

    Lower Saxony, Germany

  • -

    Düsseldorf, Nordrhein-Westfalen, Deutschland

  • -

    Frankfurt am Main und Umgebung, Deutschland

  • -

    Germany

  • -

    Haar, Bavaria, Germany

  • -

    Bonn und Umgebung, Deutschland

  • -

    Amsterdam und Umgebung, Niederlande

  • -

    Dortmund und Umgebung, Deutschland

  • -

    Essen und Umgebung, Deutschland

  • -

    Hamburg

  • -

    Hamburg und Umgebung, Deutschland

  • -

    Deutschland

  • -

    Darmstadt und Umgebung, Deutschland

  • -

    Bitterfeld-Wolfen, Saxony-Anhalt, Germany

  • -

    Frankfurt am Main und Umgebung, Deutschland

  • -

    Stuttgart und Umgebung, Deutschland

  • -

    Frankfurt am Main und Umgebung, Deutschland

  • -

    Bonn und Umgebung, Deutschland

  • -

    München

  • -

    Essen, North Rhine-Westphalia, Germany

  • -

    Frankfurt am Main und Umgebung, Deutschland

  • -

    Duisburg und Umgebung, Deutschland

  • -

    Düsseldorf und Umgebung, Deutschland

  • -

  • -

    Frankfurt am Main und Umgebung, Deutschland

  • -

  • -

    Frankfurt am Main und Umgebung, Deutschland

  • -

    Oberursel, Hesse, Germany

  • -

    Frankfurt, Hesse, Germany

  • -

    Frankfurt Rhine-Main Metropolitan Area

  • -

    Wiesbaden, Hesse, Germany

  • -

  • -

    Frankfurt Rhine-Main Metropolitan Area

  • -

  • -

    Münster, North Rhine-Westphalia, Germany

  • -

    Ibbenbüren, North Rhine-Westphalia, Germany

Ausbildung

Veröffentlichungen

  • Shit happens – this time you got hit by an ICT-related incident...

    LinkedIn

    We will have reported the ICT-related incident and so we have done all we ought to do as claimed by the regulator!"

    Answers like these make me doubt whether internal legal departments, or internal auditors, or in general the 3rd LoD were sufficiently involved in the current hashtag#NIS2 or hashtag#DORA realization projects.

    Uhm, yes - sorry to bother you again with a personal hashtag#DORA fun episode.

    "What about your self-interests? - e.g. compensation of resulting…

    We will have reported the ICT-related incident and so we have done all we ought to do as claimed by the regulator!"

    Answers like these make me doubt whether internal legal departments, or internal auditors, or in general the 3rd LoD were sufficiently involved in the current hashtag#NIS2 or hashtag#DORA realization projects.

    Uhm, yes - sorry to bother you again with a personal hashtag#DORA fun episode.

    "What about your self-interests? - e.g. compensation of resulting damages or prosecution of aggressors, etc.?", I continue asking and look into empty faces.

    After reading my stuff, sharpen your awareness to get the most out of regulatory requirements: Your self-interest!

    Do not just restart the machines and thus destroy any evidence needed during the legal aftermath.

    There are more lessons to learn from regulatory requirements if you are not just ticking minimum boxes and ignoring what is not directly or explicitly addressed.

    Getting compensation for damages is a part of resilience, too.
    Maybe re-active, but very efficient!

    Veröffentlichung anzeigen
  • Mystery Audits to get reliable results about operational resilience for #DORA, #NIS2, #ESG, ...?

    Michael Georg Speller

    Leading financial institutions have discovered that mystery shopping is an effective method to evaluate service quality and reliability in B2C areas.

    But why limit this approach to B2C?
    Applying mystery audits in B2B areas for Operational Resilience Tests can provide more reliable and objective insights than standard procedures.

    Veröffentlichung anzeigen
  • General Contractors and 3rd Party Risks in Your Value Chain

    LinkedIn

    In the financial sector, general contractors play a decisive role in the successful implementation of ICT projects or in the management of ongoing operations or important functions as interim replacements for missing own staff.
    Due to the special regulatory obligations in these industries, improper selection of prime or general contractors can lead to non-compliance with laws or regulations, customer claims, delays, cost overruns, litigation, lost profits, poor quality, and recourse and…

    In the financial sector, general contractors play a decisive role in the successful implementation of ICT projects or in the management of ongoing operations or important functions as interim replacements for missing own staff.
    Due to the special regulatory obligations in these industries, improper selection of prime or general contractors can lead to non-compliance with laws or regulations, customer claims, delays, cost overruns, litigation, lost profits, poor quality, and recourse and sensitive fines.

    Veröffentlichung anzeigen
  • What´s your strategy during an audit? - bury your head in the sand or boldly present Self-Identified Issues (SII)...

    LinkedIn - Pulse

    In the Bible, in the second book of Samuel, you can read how the future King David reacted when he heard of King Saul's death in the battle of Mount Gilboa: He had the reporter unceremoniously slain by one of his men.

    Killing the bad news bearers has generally been popular for a while. Corresponding reports can be found in ancient Greece and the Aztec ruler Montezuma is said to have ordered the execution of the messengers when the Spaniard Cortez was reported to him.

    Now in 2021…

    In the Bible, in the second book of Samuel, you can read how the future King David reacted when he heard of King Saul's death in the battle of Mount Gilboa: He had the reporter unceremoniously slain by one of his men.

    Killing the bad news bearers has generally been popular for a while. Corresponding reports can be found in ancient Greece and the Aztec ruler Montezuma is said to have ordered the execution of the messengers when the Spaniard Cortez was reported to him.

    Now in 2021 over the last months, we have faced a lot of requests asking to quickly heal or somehow otherwise whitewash "things" people identified or assumed as possible regulatory issues.

    Veröffentlichung anzeigen
  • Consulting vs. Contracting - a matter of adding value or counting hours...

    LinkedIn - Pulse

    Working with consulting vendors often lacks efficiency due to unclear expectations and wrong governance approach - when companies hire someone to support their business, they often fail to identify exactly enough what they want to achieve.

    Veröffentlichung anzeigen
  • 8 Draft Theses on Ethical Guidelines before Outsourcing AI services

    LinkedIn - Pulse

    As most customers are solely concerned by the usually fined potential misuse of personal data, we developed 8 theses to think about before undertaking a "semi-blind" outsourcing driven by technical or sales departments due to some neat features.

    Veröffentlichung anzeigen
  • New Standard Contractual Clauses (SCCs) for GDPR data transfers between EU and 3rd countries - 5 important steps

    LinkedIn - Pulse

    As a consequence of the Shrems II case, the so-called standard contractual clauses (SCCs), i.e. the “pre-approved clauses” issued by the European Commission had to be reworked and are in place now.

    With regard to new contracts, companies will have to replace the former sets of SCCs starting a least September 27th, 2021 - nevertheless it is recommended to use the new SCC´s in current negotiations from now on.

    Veröffentlichung anzeigen
  • EU Digital Operational Resilience Act (DORA) planned for 2022

    LinkedIn - Pulse

    From 2022, the Digital Operational Resilience Act (DORA) should ensure uniformity and homogenize the state of different regulations in the entire EU economic area for all participants to guarantee the operational stability of operational systems in the long term by preparing companies for conceivable disruptions and threats in ICT to make incidents robust survive.

    Veröffentlichung anzeigen
  • Turn over from STOP-LOSS to TAKE-PROFIT during supervisory audits

    LinkedIn - Pulse

    The costs of correcting one single finding after a supervisory audit in the banking industry vary depending on the maturity level of the audited as well as the maturity level of the project organization between 20K and 250K Euros. In some EU countries, penalties will have to be calculated on top. Any Euro you lose in the case of expensive measures or penalties will have to be earned again elsewhere in your organization.

    Veröffentlichung anzeigen
  • Top 10 hints when to "call a bluff"​ during Cloud Outsourcing Negotiations

    LinkedIn - Pulse

    As a regulated (financial) industries customer, you should definitely "call the bluff" during contract negotiations with public cloud service providers as soon as you are facing one or more of the following 10 phrases:...

    Veröffentlichung anzeigen
  • ESMA´s Consultation on Outsourcing to Cloud Service Providers

    LinkedIn - Pulse

    The ESMA (European Securities and Markets Authority) recently published its consultation on draft cloud outsourcing guidelines to help investment banks comply with financial services regulations when processes or functions of investment activities are outsourced to cloud service providers (CSPs).

    Veröffentlichung anzeigen
  • Renewal of the German BSI's Cloud Computing Compliance Controls Catalogue (C5:2020)

    LinkedIn - Pulse

    The German Federal Office for Information Security (BSI) has fundamentally revised its Cloud Computing Compliance Controls Catalogue (C5:2016), which was dated from 2016. Due to its quality, the catalogue was widely accepted beyond the borders of Germany.

    Veröffentlichung anzeigen
  • Guidelines on ICT and security risk Management released by the EBA

    LinkedIn - Pulse

    After about one year of work the EBA has released the 2019 Guidelines on ICT and security risk management yesterday (28th. Nov. 2019)
    The final document now counts 129 pages, though the "core" is concentrated on pages 14 to 29 (section 3.1. to 3.8), whereas pages 34 to 129 are used to document the EBA´s feedback on the public consultation and give some interesting insights about the motivation and background of the different participants of the discussion.

    Veröffentlichung anzeigen

Sprachen

  • English

    Muttersprache oder zweisprachig

  • German

    Muttersprache oder zweisprachig

Erhaltene Empfehlungen

Weitere Aktivitäten von Michael Georg Speller

Michael Georg Spellers vollständiges Profil ansehen

  • Herausfinden, welche gemeinsamen Kontakte Sie haben
  • Sich vorstellen lassen
  • Michael Georg Speller direkt kontaktieren
Mitglied werden. um das vollständige Profil zu sehen

Weitere ähnliche Profile

Entwickeln Sie mit diesen Kursen neue Kenntnisse und Fähigkeiten