Dustin Dehez-Regulatory Risk Executive | Risk Governance & 2nd LoD in Banking | EU AI Act, DORA, MaRisk, NFR | CEO Secori Advisors GmbH

Check rate
Experience
External consultant
Deutsche Leasing
2nd LoD/Change the Bank (CtB)
- CtB: External consultant and workstream lead for rectifying findings by BaFin following a special IT audit in the 2nd LoD, management of the work package for revising the ICT Risk Management & ICT Asset Classification in accordance with DORA Chapter 2, the processes for structural analysis, protection requirements, and control assessments (4 FTEs).
External consultant
Deutsche Bank
3rd LoD/Run the Bank (RtB)
- External consultant for short-term validation of artifacts from remediated findings of the ECB's Joint Supervisory Team (JST) in third-party management
- Design and implementation effectiveness validation, test design, execution, and documentation, and preparation of validation reports.
External consultant
Hessische Landesbank
1st LoD/Run the Bank (RtB)
- External consultant in the bank's IT risk management department in an RtB function
- Conducting IT risk assessments and coordination with the relevant 2nd LoDs (information risk management, vendor risk management, data protection), operational risk management and loss bearing business units
- Running the annual IT risk exercise
- Running the annual IT stress test of the bank in cooperation with the bank's 2nd LoD information risk management
1st LoD/Change the Bank (CtB)
- Redesign of the information risk management core process to address ECB findings of an onsite inspection
- Redesign of the core process on information risk management within the non-financial risk framework
- Redesign of the intersection to the operational risk management processes
- Introduction of a new model to track deviations and feed them into the information risk management process
- Stakeholder management (2nd and 3rd LoD)
- Implementation of the new process for the risk managing division during the annual information risk exercise
External consultant
Deutsche Börse
1st LoD/Change the Bank (CtB)
- External consultant in a CtB project to redesign the third-party risk management of the group
- From January 2023 onwards: Workstream Lead (4 FTE) for the re-design and implementation of the future state of the third-party risk assessment. Responsible for the design of the new core process and various sub-processes, the new control set for third-party risk assessments, alignment of the control set with internal requirements, drafting of strategies and concepts and corresponding stakeholder reporting.
- July 2022 to December 2022: Workstream Lead (3 FTE) for the re-design of the third-party information security requirements. Development of the contractual amendment covering information security requirements for third parties. Alignment of the conceptual approach and the appendix with the relevant departments in the organisation (legal, 2nd and 3rd LoDs), and corresponding stakeholder reporting
- Drafting and aligning the documentation to close the corresponding findings with the regulatory authorities and alignment with the stakeholders to report finding closure
- Drafting and aligning of the cloud strategy and the cloud service provider assessment strategy
- Drafting and aligning of the group's supplier security guideline
- Drafting and aligning the new process landscape with stakeholders within the group and assuring approval from stakeholders and 3rd LoD.
- Ensuring that the future state meets regulatory requirements as stipulated in EBA-guidelines (ICT and outsourcing), MaRisk, BAIT, DORA
External consultant
Hessische Landesbank
2nd LoD/Run the Bank (RtB)
- External consultant in the bank's information risk management department (2nd LoD)
- Implementing the annual information risk assessment across the bank based on information risk appetite, in line with relevant regulatory guidelines (MaRisk, BAIT, EBA guidelines on outsourcing, ICT, GDPR, SREP) and in the run up to the ECB's on-site inspection (OSI). The annual risk assessment exercise included the assessment of the bank itself and all its subsidiaries and branches
- Reporting of information risk exposure to relevant stakeholders, preparation of risk reporting to the bank's non-financial risk steering committee
- Coordination and alignment with relevant other specialised 2nd LoDs (operational risk/third party risk-management), regular assessment of outsourcing risk reports and compliance checks for MaRisk AT9 compliance
- Preparation of various information risk reports and overhaul of risk repository in anticipation of ECB OSI
- Conducting ECB-led stress tests
External consultant
Deutsche Bank
1st LoD/Run the Bank (RtB)
- External consultant for information risk management in the bank's vendor/third-party risk management department
- Project lead in the development and implementation of the major change in the key operating procedure on information security requirements in third-party relationships, supporting the shift to the cloud-based landscape and aligning the information security requirements for vendors with applicable regulatory requirements (MaRisk AT9, BAIT, GDPR, EBA Guidelines on outsourcing, HKMA, MAS, FED, PRA) and relevant industry standards (ISO 27001, CCM, SOC2)
- Auditing of the bank's risk exposure in numerous third-party/outsourcing relationships, auditing of evidence submitted by third-parties and their compliance with the bank's information security requirements
- Tracking and assessing risk mitigation plans for third parties, including the coordination of finding closures
- Coordination with stakeholders in different business units across the bank
- Reporting and documentation of the bank's risk exposure based on the Cyber-, IT-, and non-IT-risk appetite based on relevant ISO 27001 and ISO 27005 criteria
External consultant
Hessische Landesbank
2nd LoD/Run the Bank (RtB)
- External consultant for the introduction of the bank's information risk management following the establishment of a dedicated information risk department and the carve-out of information risk from regular operational risk based on the regulatory IT- and risk management requirements (BAIT and MaRisk)
- Refreshment exercise of the bank's GRC framework in the roll-out of the new information risk framework
- Running the annual information risk assessment across the bank based on the information risk appetites
- Onboarding and training of departmental information risk managers
- Establishing and tracking of risk mitigating measures across the bank
- Implementing the information risk standards at the bank's various subsidiary units
- Mapping risks according to ISO 27001 standards
- Coordination and alignment with relevant other specialised 2nd LoDs (operational risk/third party risk-management), regular assessment of outsourcing risk reports and compliance checks for MaRisk AT9 compliance
- Regular reporting of information risk to the CISO and preparation of reporting to non-financial risk steering board
Track-II Diplomacy for the Minsk Dialogue and the Konrad-Adenauer-Foundation
External consultant
Renewable Energy Company
- External consultant for the introduction of an information security management system (ISMS) based on the ISO 27001 for a small renewable energy company, subject to the country's critical infrastructure regulation (KritisV) and energy legislation (Energiewirtschaftsgesetz, EnWG).
- Overall design of the ISMS, corresponding processes and governance structure and internal target measures
- Project progress reporting and coordination with internal and external stakeholders
- Implementing and coordinating an ISO 27001 and ISO 27019 based governance and policy structure, as well as mapping of regulatory requirements to the new information security management system and establishment of a governance, compliance, and risk framework
External Data Protection Officer
Tax Accountancy Partnership
- External Data Protection Officer
- Introduction of a software tool to run the data privacy management system
- Implementation and maintenance of a record of processing activities
- Data protection impact assessments and transfer impact assessments and corresponding risk management
Project lead
Lürssen
- Project lead for the data privacy management system across the group to align the company with GDPR legislation
- Managing stakeholder engagement across the group, including compliance, legal, and business units in the organisation
- Data protection impact assessments (DPIA) and Transfer Privacy Impact Assessments (TPIA)
- Reporting project progress to the group's board
- Design, implementation, and maintenance of a record of processing activities, including the related processes and documentation (process governance, reporting)
- Introduction of a software tool for the data privacy management system
- Harmonisation with other regulatory frameworks (mainly harbour and shipping laws and regulations)
- Training of company leadership and staff
British Business Intelligence Provider
- Due diligence for the German part of a larger British due diligence
- Open-Source Intelligence and assessment of collected evidence
- Strategic consulting for project continuation
Track-II Diplomacy of the Konrad-Adenauer-Foundation in the trilateral exchange between Ukraine, Russia, and Germany
- Participation in the trilateral exchange with Russian and Ukrainian Members of Parliament
- Assessment of the German OSCE Presidency 2016
- Assessment of the OSCE monitoring missions in Ukraine
Founder and CEO
secori advisors GmbH
Founder (since 10/2014) and Chief Executive Officer (since 09/2025), with 5 direct reports and 20 indirect reports. Built a company from scratch without seed funding and grew it into a risk consultancy with ~ EUR 3 million in annual turnover, now certified as a Great Place to Work, with extremely low employee turnover. Drove change in the firm, from scaling to people management and establishing internal governance for the adoption of AI in the firm.
- SAP SE: Designed and delivered an enterprise-wide AI Governance & Control Framework, translating regulatory and industry requirements into a unified, auditable control model for AI-enabled processes and applications. Defined a control library of 200–250 measures, established audit evidence requirements, and aligned cross-functional stakeholders to strengthen AI governance, assurance, and regulatory compliance.
- Deutsche Leasing: Led BaFin remediation workstream following a special BaFin IT audit, redesigning guidelines for the IT landscape ("information network"), structural analysis, and protection requirements classification, delivered new end-to-end processes and tool integration, positioning 2nd LoD for BaFin closure and DORA compliance.
- Deutsche Bank: Validated finding closure as Internal Audit (3rd LoD) to close JST (ECB) findings in outsourcing management.
- Hessische Landesbank: Ran IT risk management for Hessische Landesbank (1st LoD): annual IT risk assessments, stress tests, and cross-LoD coordination. Redesigned the core information risk process to resolve ECB findings, introduced a deviation-tracking model, and embedded the new framework into the bank-wide risk exercise—accepted by the ECB and operationalised across non-financial risk governance.
- Deutsche Börse: Redesigned third-party risk management from the ground up; delivered DORA-ready processes, closed regulatory findings, and implemented new vendor security requirements across the cloud and supplier landscape. New framework aligned to EBA guidelines, MaRisk, BAIT, and approved by Internal Audit and regulators.
- Deutsche Bank: Redesigned vendor information security framework: delivered cloud-ready procedures compliant with MaRisk, BAIT, EBA, HKMA, MAS, FED, PRA, ISO 27001, and SOC2. Audited third-party risk exposure, coordinated finding closures.
Non-Residential Senior Research Fellow
Global Governance Institute
- Numerous lectures on foreign policy, security, and development affairs
- Numerous publications (in Foreign Affairs, American Foreign Policy Interests, among others)
- Field research and evaluation projects on German development assistance
- Research and conference trips to various countries, including Pakistan, Israel, Togo, Benin, and the PR China
Personal Staff of the chief economist Professor Norbert Walter
Deutsche Bank Group
- Preparation of lectures and presentations
- Preparation of briefs
- Coordination of events
Industry Experience
See where this freelancer has spent most of their professional time.
Experienced in Banking and Finance, Information Technology, Professional Services, Government and Administration, and Manufacturing.
Business Area Experience
See which departments and functions this freelancer has contributed to most.
Experienced in Information Technology, Project Management, Audit, Legal, Operations, and Strategy.
Summary
Many years leading non-financial risk, ICT and third-party risk management projects for international banks, Landesbanken, stock exchanges and financial service providers. Proven track record in resolving ECB and BaFin findings, implementing ISO 27001 frameworks and enabling digital transformation under regulatory pressure and streamlining BAU processes in 2nd LoDs. Deep expertise across all three lines of defence (1st, 2nd, 3rd). CEO and founder of ~ €3m annual turn-over risk and compliance advisory firm, with a track record of employee satisfaction and consistent growth. Part-time PhD candidate (International Relations, cyber deterrence), with a Master of Science (MSc) in Global Central Banking and Financial Supervision (Warwick Business School), completed in 2026, with a dissertation on the German industry’s perspectives on the digital euro and monetary risks. Master of Arts (MA in International Affairs and Cyber Security) from King’s College London.
Languages
Education
University of Reading
PhD candidate · International Relations, cyber deterrence · Reading, United Kingdom
King’s College London
M.A. · International Affairs (Cyber Security) · London, United Kingdom
University of London/London School of Economic and Social Sciences (LSE)
B.Sc. · Politics and International Relations · London, United Kingdom
Certifications & licenses
Certified Outsourcing Manager
Bank Verlag
Annex SL Certified Integrated Management Systems Lead Auditor for ISO27001, 14001, 9001, 20000
SoftQualM
Certified Non-Financial Risk Manager
Frankfurt School of Finance & Management
ISO 31000 Risk Manager
PECB
Statistics
Experience
Global Experience
Expertise
Qualifications
Profile
Frequently asked questions
Have questions? Find more information here.
Daily Rate Distribution
The rates shown represent the typical market range for freelancers in this position based on recent contracts on our platform.
Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a External consultant
Nearby freelancers
Professionals working in or nearby Bad Homburg, Germany
