From Cyber Risk to Audit-Ready — With a Clear System

I help companies implement ISO 27001, NIS2, GDPR, TISAX, DORA, SOC 2, PCI DSS, HIPAA and NIST — with structure, not guesswork.

Sandy Smajic — Cybersecurity & Compliance Consultant
ISO 27001
NIS2
TISAX
DORA
GDPR
SOC 2

A structured approach to security and compliance

Audit Readiness Focus
Preparation aligned with how auditors actually assess.
Framework-Based Roadmaps
Clear, prioritized steps grounded in recognized standards.
Measurable Risk Reduction
Controls that address your most relevant risks first.
Management-Ready Reporting
Documentation and status views your leadership can act on.
Sandy Smajic - Cybersecurity Expert

About Sandy Smajic

What started as a passion for technology in Bosnia evolved into a mission to strengthen the security and resilience of European organizations. Through hands-on work in industry, energy, and automotive environments, I saw the same recurring challenge.

Most companies knew they needed cybersecurity but didn't know where to start. Traditional assessments were often too expensive, too complex, or simply not designed for the realities of small and mid-sized businesses.

That's why I built this ecosystem — a structured system that makes cybersecurity and compliance practical, transparent, and outcome-driven for every organization.

8+
Years Experience
9
Frameworks Covered
3
Languages
BSc Information TechnologyISO 27001 Lead ImplementerTISAX PractitionerNIS2 Specialist

The Ecosystem I Built For You

After years of consulting, I saw the same pattern: companies struggling with fragmented tools, unclear processes, and advisors who left them with binders full of policies but little real implementation.

So I built an integrated system — tools and expertise that work together to take you from risk identification to audit readiness.

1
Identify risks
2
Manage compliance
3
Implement strategy
CyberHealth360 logo
1

CyberHealth360

Identify risks

A fast, automated assessment that reviews your current security posture and highlights gaps — giving you clarity on where you stand.

  • Instant risk overview
  • Priority roadmap
  • Framework alignment
ComplianceHub360 logo
2

ComplianceHub360

Manage compliance

A centralized GRC platform to manage your compliance documentation, track audit progress, and collaborate with your team — all in one place.

  • Multiple frameworks supported
  • Policy management
  • Audit tracking
Sandy Smajic Consulting logo
3

Sandy Smajic Consulting

Implement strategy

When you need hands-on guidance, I work directly with your team to implement controls, prepare for audits, and build a security culture that lasts.

  • Hands-on implementation
  • Audit preparation
  • Team training

"These tools work together. Start with an assessment, manage your journey in the platform, and bring in consulting when you need expert hands."

The Origin Story

Why I built this ecosystem

After years of advising organizations on security and compliance, I kept seeing the same pattern: companies knew they had a problem, but had no clear, affordable way to find out where they actually stood — or what to do next.

Consultants delivered thick reports that gathered dust. Tools were either enterprise-priced or too shallow to be useful. The gap between knowing and doing was where good intentions went to die.

So I built the ecosystem I wished my clients had: a free assessment to reveal the gaps, hands-on consulting to close them, and a platform to keep everything audit-ready — all connected, all reinforcing each other.

Identify

A free, automated assessment that shows exactly where you stand — no jargon, no sales call required.

Advise

Senior, independent consulting that turns findings into a prioritized, realistic roadmap.

Operate

A GRC platform that keeps your program living and audit-ready throughout the year.

The Platforms

Two platforms, one connected journey

CyberHealth360 tells you where you stand. ComplianceHub360 takes you the rest of the way to audit-ready.

CyberHealth360 platform
Instant risk score
Posture analysis
Priority roadmap
Framework gaps
Step 1 — Identify

CyberHealth360

A free, 5-minute automated assessment that scans your security posture and shows exactly where your gaps are — no consultant required. Get an instant risk score and a prioritized roadmap mapped to the frameworks that matter to your business.

Automated security posture scan in minutes
Instant, board-ready risk score
Prioritized roadmap aligned to ISO 27001, NIS2 & more
Clear next steps — no jargon, no guesswork
Step 2 — Manage

ComplianceHub360

A centralized GRC platform where you manage every framework, track audit progress, and collaborate with your team in one place. Turn your assessment results into a living compliance program that stays audit-ready year-round.

9 compliance frameworks supported out of the box
Centralized policy & document management
Real-time audit progress tracking
Team collaboration & evidence collection
ComplianceHub360 platform
Policy hub
Audit tracking
Team workflows
Evidence vault

External Lecturer

IT Security — HDBW Hochschule

IT Security
Information Security
Risk Management
Compliance
Business Continuity
AI-supported Security
Cloud Security
Identity Management
Academic Authority

Academic Expertise Meets Real-World Cybersecurity

Sandy bridges two worlds that rarely meet: hands-on industry consulting and academic teaching. As an external lecturer in IT Security, he helps shape the next generation of security professionals while applying the same rigor to every client engagement.

This dual perspective means your organization benefits from approaches that are both academically sound and proven in real audits — not theory for its own sake, and not shortcuts that fail under scrutiny.

Professional Journey

A career built across industry, regulation and academia

The experience behind the ecosystem — spanning hands-on security work, governance leadership and teaching the next generation.

Foundations

Security & IT Operations

Hands-on work securing infrastructure and systems — learning how attacks and failures actually happen, not just how they look in textbooks.

Specialization

Governance, Risk & Compliance

Leading ISO 27001, TISAX and GDPR programs across regulated sectors, translating standards into controls organizations can sustain.

Leadership

Independent Consultant & vCISO

Advising organizations across healthcare, finance, manufacturing and critical infrastructure as a trusted, independent security partner.

Today

Consultant, Lecturer & Platform Founder

Combining consulting, an academic teaching role in IT Security and the CyberHealth360 and ComplianceHub360 platforms into one ecosystem.

Framework Coverage

Capability across the frameworks that matter

A transparent view of where my expertise runs deepest — so you know exactly what you are getting.

Expert
Advanced
Working

Information Security

ISO 27001 / 27002Expert
NIST CSFAdvanced
SOC 2Advanced

EU Regulation

NIS2Expert
GDPRExpert
DORAAdvanced

Sector & Specialist

TISAXExpert
PCI DSSWorking
HIPAAWorking

Depth of hands-on experience with each framework.

How It Works

1

Identify gaps

We assess your current security posture and identify compliance gaps.

2

Define priorities

We create a clear roadmap based on your business needs and risk profile.

3

Implement what matters

We implement the controls and processes that protect your business.

Services & Pricing

Clear pricing. Clear outcomes. Choose the service that fits your needs.

ISO 27001 Implementation

€85-130/hour

Complete information security management system setup and certification support.

What you get:

  • Implementation plan
  • Documentation
  • Audit prep
  • Staff training

Outcome:

An audit-ready organization with a structured ISMS.

NIS2 Compliance

€95-130/hour

European cybersecurity directive readiness for organizations in scope.

What you get:

  • Gap analysis
  • Risk framework
  • Incident setup
  • Supply chain

Outcome:

Regulatory readiness aligned with NIS2 requirements.

TISAX Assessment

€90-130/hour

Automotive industry security assessment and certification preparation.

What you get:

  • Readiness check
  • Control setup
  • Prototype protection
  • Cert support

Outcome:

Qualify as a trusted partner in the automotive supply chain.

GDPR Compliance

€75-120/hour

Data protection regulation compliance and privacy management.

What you get:

  • Privacy audit
  • Data mapping
  • Policy creation
  • DPO support

Outcome:

Reduced exposure to data protection penalties.

Security Assessments

€75-120/hour

Vulnerability assessments, penetration testing, and security auditing.

What you get:

  • Vulnerability scan
  • Pen testing
  • Risk analysis
  • Remediation plan

Outcome:

Measurable risk reduction with a clear remediation plan.

Process Automation

€65-110/hour

Power Automate and SharePoint integration for secure workflows.

What you get:

  • Workflow design
  • Automation setup
  • Integration
  • Training

Outcome:

More efficient, secure and repeatable processes.

What You Get From This System

Clear understanding of your security risks
Structured compliance approach
Faster audit readiness
Reduced business risk
Efficient, framework-based implementation
Ongoing expert support

Start With a Structured Assessment

Identify your risks and compliance gaps in minutes with CyberHealth360.

Standards & Frameworks

Expertise across international cybersecurity standards and regulatory frameworks.

ISO 27001

Information Security Management

NIS2

EU Cybersecurity Directive

TISAX

Automotive Security Standard

GDPR

Data Protection Regulation

Selected Engagements

How the ecosystem performs in practice

Anonymized examples drawn from real engagements across regulated sectors.

Specialty Pharmaceuticals

The challenge

A growing pharma company needed to demonstrate robust information security to international partners but had no formal ISMS in place.

The approach

Ran a structured gap analysis, then built a proportionate ISO 27001 management system aligned to how their teams actually worked.

The outcome

Reached certification readiness with an ISMS the internal team could sustain — and the credibility to satisfy partner due diligence.

ISO 27001GDPR

Energy & Utilities

The challenge

A regional energy provider faced expanded obligations under NIS2 and was unsure which requirements applied to them.

The approach

Clarified scope and entity classification, mapped existing controls against NIS2, and prioritized the gaps that mattered most.

The outcome

A clear, board-approved roadmap to compliance and measurably improved resilience against the most relevant threats.

NIS2ISO 27001

Automotive Supply Chain

The challenge

A tier supplier risked losing contracts without a valid TISAX label and limited internal security maturity.

The approach

Prepared the organization for assessment — closing control gaps, structuring evidence and coaching the team through the process.

The outcome

Successfully positioned for the required TISAX label, protecting existing contracts and unlocking new business.

TISAXISO 27001

Case studies are anonymized to protect client confidentiality. Outcomes are described qualitatively.

How We Work Together

Available wherever you operate

Flexible engagement models designed around your needs, your team and your timezone.

Remote-first

Most consulting, workshops and reviews are delivered efficiently online, wherever you are based.

On-site when it counts

For assessments, workshops and key milestones, on-site engagement across the DACH region and EU is available.

English & German

Engagements, documentation and stakeholder communication delivered in both English and German.

Start with a free assessment or book a 30-minute consultation — no commitment required.

If You Are Serious About Compliance, the Next Step is Clear.

Book a consultation to discuss your cybersecurity needs and how we can help protect your business.

Email

info@sandysmajic.com

Phone

+49 176 70035262

Location

Essen, Germany

LinkedIn

Connect