Herbert Fasching-Management Consultant
Check rate
Experience
Management Consultant
Siemens Energy
- Introduction of cyber risk management: setting up risk governance and defining processes
- Preparation of reporting and rollout at HQ management level
- Training for around 30 decentralized CISOs worldwide
Project Manager
ING DIBA
- Build-out and expansion of IT security/cyber: APT, penetration testing, technical state monitoring, security events, governance, threat intelligence, security event monitoring
- Creation of governance documentation, process improvement, and definition
- Creation of user stories with implementation in ServiceNow
- Quality assurance and audit support: creation of auditable documents and cooperation with internal and external auditors
- Implementation of DORA: gap analyses with IT and IT security, identification of necessary actions and implementation
- Implementation of local (critical infrastructure, GDPR) and international regulations (in-house IT security, supply chain law)
- Outsourcing/contracts: support for outsourcing cyber functions to Eastern Europe, contracts, GDPR compliance, risk assessment, and negotiations through contract signing
Project Manager
HUK-Coburg
- Implementation of BCM: threat and risk analyses at headquarters, subsidiaries, and branches
- Development of strategy options and implementation of BCM processes at headquarters, HUK-Assistance, VRK Detmold, and Kassel
- Conducted over 100 workshops on risk analysis and documentation of all business processes
- Creation and implementation of emergency procedures and adjustment of technical requirements (telecommunications and IT)
- Negotiations with works council bodies up to the conclusion of company agreements
- Development of a technical concept for crisis communication and implementation of related processes
Project Coordinator / Business Analyst
AXA
- Preparation for ISO 2700x implementation: risk analyses in business security, process definitions, and implementation
- Setup of a CERT (Cyber Emergency Response Team)
- Review and improvement of site and building security
- Establishment of IS controlling in ARIS and integration with ISO 22301 business continuity
- Planning and leading a four-day CERT cyber security exercise including scenario development, training, leadership, and lessons learned
- Implementation of endpoint protection: market research, selection, project planning, and rollout
- BCM/pandemic/DR integration in Winterthur Insurance after acquisition by AXA: gap analysis, adjustment of emergency procedures, integration into crisis communication strategy, and merging of emergency teams
- Introduction of pandemic planning: stakeholder workshops, strategy development, implementation of emergency procedures (hygiene, communication, administration, emergency measures), training of the pandemic management team, procurement and administration of hygiene products and medications
- Implementation of BCM: threat analysis, strategic proposals with cost analysis, interviews and workshops (around 300), setup and integration of software to manage a 1500-person emergency organization
- Rollout of emergency procedures to all 14 branches, 2 call centers, and bank
- Design, testing, and implementation of a BC tool to manage emergency procedures and around 200 customized emergency plans
- Introduction of crisis communication: strategy development, workshops for crisis managers, communication matrix, individual emergency plans, external dark sites, and operational implementation
- Operational risk management: support for the introduction and calculation of operational risks in collaboration with the OR team
- Preparation for setting up AXA Bank Europe Prague/Brno: strategy definition for entering the CR and SR markets, market analysis of Czech Republic/Slovakia, product analyses and legal requirements, presentation for management in Brussels
Project Manager
Commerzbank
- Further development of BCM: introduction of crisis communication, adaptation to audit requirements and MaRisk, establishment of a crisis team
- BCM exercises: scenario development, training of auditors and observers, exercise leadership, lessons learned with internal audit
- Adaptation of disaster recovery data center (DR): analysis of the IT environment in Frankfurt, adjustment of emergency processes in all departments, synchronization of processes and communication between Frankfurt and Prague
- BCM/DR exercise: test run of IT fallback to emergency data center and one week of emergency operations, scenario setup, leadership, lessons learned, and final presentation
- Introduction of BCM for investment banking: threat and risk analysis, development of strategy options, support in setting up emergency trading rooms in Frankfurt, process definition and communication, live exercise, lessons learned, and final presentation
- Design, testing, and implementation of a BC tool to manage emergency procedures and customized emergency plans
- Success examples: maintaining operations in the emergency data center during violent protests and two-week continuity of operations during flooding without outages
Industry Experience
See where this freelancer has spent most of their professional time.
Experienced in Banking and Finance, Insurance, and Energy.
Business Area Experience
See which departments and functions this freelancer has contributed to most.
Experienced in Information Technology, Project Management, Operations, Audit, and Strategy.
Summary
I have built a solid track record in management consulting through diverse roles in energy, finance, insurance, and banking industries. I excel at designing and implementing risk and business continuity processes, developing effective governance frameworks, and executing complex security measures. My work ranges from establishing cyber risk management and building CERT teams to leading critical BCM projects with measurable impact.
I bring hands-on experience with process optimization, robust documentation, and audit support, supported by certifications in ISO 2700x, Lean Six Sigma, Scrum, and Prince2. I use my deep knowledge and structured approach to deliver reliable, secure, and efficient solutions in dynamic environments.
Skills
- Solid Knowledge In Most Banking Areas
- Good Understanding Of Insurance Departments
- Strong Business Management Know-how
- Extensive Experience With Emergency And Security Concepts
- Cross-departmental Approaches In It, Finance, Risk, Customer, And Legal
Languages
Education
Executive MBA · Finance/East-West Management/EU Law · Krems an der Donau, Austria
Diploma "Export Merchant" · International Law/Financing/Logistics/Marketing
Certifications & licenses
ISO 2700x Lead Implementer (Information Security)
PSM, Professional Scrum Master
Prince2® Foundation
Lean Six Sigma, Green Belt
Statistics
Experience
Global Experience
Expertise
Qualifications
Profile
Frequently asked questions
Do you have questions? Here you can find further information.
Where is Herbert based?
What languages does Herbert speak?
How many years of experience does Herbert have?
What roles would Herbert be best suited for?
What is Herbert's latest experience?
What companies has Herbert worked for in recent years?
Which industries is Herbert most experienced in?
Which business areas is Herbert most experienced in?
Which industries has Herbert worked in recently?
Which business areas has Herbert worked in recently?
What is Herbert's education?
Does Herbert have any certificates?
What is the availability of Herbert?
What is the rate of Herbert?
How to hire Herbert?
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Management Consultant
Nearby freelancers
Professionals working in or nearby Prague, Czech Republic
Most recent projects
FRATCH works with many companies and recruitment agencies. Here you will find our recently posted projects and opportunities.