Herbert Fasching-Management Consultant
Check rate
Experience
Management Consultant
Siemens Energy
- Implementation of cyber risk management: building risk governance and defining processes
- Preparation of reporting and roll-out at HQ management level
- Training for around 30 decentralized CISOs globally
Project Manager
ING DIBA
- Building and expanding IT security / cyber: APT, penetration testing, technical state monitoring, security events, governance, threat intelligence, security event monitoring
- Creating governance documentation, improving and defining processes
- Creating user stories and implementing them in ServiceNow
- Quality assurance and audit support: creating auditable documents and collaborating with internal and external auditors
- Implementing DORA: gap analyses with IT and IT security, defining required actions and implementing them
- Implementing local (critical infrastructure, GDPR) and international standards (in-house IT security, Supply Chain Act)
- Outsourcing/contracts: supporting the outsourcing of cyber functions to Eastern Europe, contracts, GDPR compliance, risk assessment, and negotiations through contract signing
Project Manager
HUK-Coburg
- Implementing BCM: hazard and risk analyses at headquarters, subsidiaries, and branches
- Developing strategy options and implementing BCM processes at headquarters, HUK-Assistance, VRK Detmold, and Kassel
- Conducting over 100 risk analysis workshops and documenting all business processes
- Creating and implementing emergency processes and adjusting technical requirements (telecommunications and IT)
- Negotiating with works council committees up to signing company agreements
- Developing a specialist concept for crisis communication and implementing respective processes
Project Coordinator / Business Analyst
AXA
- Preparing for ISO 2700x implementation: risk analyses in business security, defining processes, and implementation
- Setting up a CERT (Cyber Emergency Response Team)
- Reviewing and improving site and building security
- Establishing information security controls in ARIS and linking them to ISO 22301 Business Continuity
- Planning and leading a four-day CERT cyber security exercise, including scenario development, training, execution, and lessons learned
- Introducing endpoint protection: market research, selection, project planning, and roll-out
- BCM/Pandemic/DR integration at Winterthur Insurance after AXA takeover: gap analysis, adapting emergency processes, integrating into crisis communication strategy, and merging emergency teams
- Implementing pandemic planning: workshops with stakeholders, strategy development, introducing emergency processes (hygiene, communication, administration, emergency measures), training the pandemic management team, purchasing and managing hygiene materials and medicine
- Implementing BCM: hazard analysis, strategic proposals with cost analysis, around 300 interviews and workshops, setting up and integrating software to manage a 1,500-person emergency organization
- Rolling out emergency processes to all 14 branches, 2 call centers, and the bank
- Designing, testing, and implementing a BC tool to manage emergency processes and around 200 customized emergency plans
- Implementing crisis communication: strategy development, workshops for crisis managers, communication matrix, individual emergency plans, external dark sites, and operational implementation
- Operational risk management: supporting the introduction and calculation of operational risks in collaboration with the Operational Risk team
- Preparing the establishment of AXA Bank Europe Prague/Brno: strategy definition for entering the Czech Republic and Slovak Republic markets, market analysis, product analyses, legal requirements, and presentation to management in Brussels
Project Manager
Commerzbank
- Further developing BCM: implementing crisis communication, aligning with audit requirements and MaRisk, and building a crisis team
- BCM exercises: scenario development, training of examiners and observers, conducting exercises, and lessons learned with internal audit
- Adapting the disaster recovery data center (DR): analyzing the IT environment in Frankfurt, adjusting emergency processes for all departments, and synchronizing processes and communication between Frankfurt and Prague
- BCM/DR exercise: test run of IT fallback to the emergency data center and one week of emergency operations, scenario development, execution, lessons learned, and final presentation
- Introducing BCM for investment banking: hazard and risk analysis, developing strategy options, supporting the setup of emergency trading rooms in Frankfurt, process definition and communication, live exercise, lessons learned, and final presentation
- Designing, testing, and implementing a BC tool to manage emergency processes and customized emergency plans
- Success stories: maintaining operations in the emergency data center during violent protests and two-week business continuity during a flood without any outages
Industry Experience
See where this freelancer has spent most of their professional time.
Experienced in Banking and Finance, Insurance, and Energy.
Business Area Experience
See which departments and functions this freelancer has contributed to most.
Experienced in Information Technology, Project Management, Operations, Audit, and Strategy.
Summary
I have built a solid track record in management consulting through diverse roles in energy, finance, insurance, and banking industries. I excel at designing and implementing risk and business continuity processes, developing effective governance frameworks, and executing complex security measures. My work ranges from establishing cyber risk management and building CERT teams to leading critical BCM projects with measurable impact.
I bring hands-on experience with process optimization, robust documentation, and audit support, supported by certifications in ISO 2700x, Lean Six Sigma, Scrum, and Prince2. I use my deep knowledge and structured approach to deliver reliable, secure, and efficient solutions in dynamic environments.
Skills
- Solid Knowledge In Most Areas Of A Bank
- Good Overview Of Insurance Departments
- Good Business Know-How
- Extensive Experience With Emergency And Security Concepts
- Cross-Departmental It-Finance-Risk-Customer-Legal Approaches
Languages
Education
Executive MBA · Finance/East-West Management/EU Law · Krems an der Donau, Austria
Diploma "Export Salesman" · International Law/Finance/Logistics/Marketing
Certifications & licenses
ISO 2700x Lead Implementer (Information Security)
PSM, Professional Scrum Master
Prince2® Foundation
Lean Six Sigma, Green Belt
Statistics
Experience
Global Experience
Expertise
Qualifications
Profile
Frequently asked questions
Have questions? Find more information here.
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Management Consultant
Nearby freelancers
Professionals working in or nearby Prague, Czech Republic
