Herbert Fasching-Management Consultant
Check rate
Experience
Management Consultant
Siemens Energy
- Introduced cyber risk management: set up risk governance and defined processes
- Prepared the reporting and rolled it out at HQ for management level
- Trained about 30 decentralized CISOs worldwide
Project Manager
ING DIBA
- Built and expanded IT security/cyber: APT, penetration testing, technical state monitoring, security events, governance, threat intelligence, security event monitoring
- Created governance documentation, improved and defined processes
- Created user stories and implemented them in ServiceNow
- Quality assurance and audit support: produced auditable documents and worked with internal and external auditors
- Implemented DORA: carried out gap analyses with IT and IT security, defined actions needed and implemented them
- Implemented local (CRITIS, GDPR) and international regulations (internal IT security, Supply Chain Act)
- Outsourcing/contracts: supported outsourcing of cyber functions to Eastern Europe, handled contracts, GDPR compliance, risk, and negotiations up to contract signing
Project Manager
HUK-Coburg
- Introduced BCM: risk and hazard analyses at headquarters, subsidiaries, and branches
- Developed strategy options and implemented BCM processes at headquarters, HUK-Assistance, VRK Detmold, and Kassel
- Conducted over 100 workshops for risk analysis and documented all business processes
- Created and implemented emergency processes and adjusted technical requirements (telecommunications and IT)
- Negotiated with works councils until company agreements were finalized
- Developed a specialist concept for crisis communication and implemented the related processes
Project Coordinator / Business Analyst
AXA
- Prepared for ISO 2700x implementation: risk analyses in business security, process definitions, and implementation
- Set up a CERT (Cyber Emergency Response Team)
- Reviewed and improved site and building security
- Established IS control in ARIS and linked it with ISO 22301 Business Continuity
- Planned and led a four-day CERT cyber security exercise including scenario development, training, leadership, and lessons learned
- Introduced endpoint protection: market research, selection, project planning, and roll-out
- Integrated BCM/pandemic/DR into Winterthur Insurance after takeover by AXA: gap analysis, adapting emergency processes, integrating into crisis communication strategy, and merging emergency teams
- Introduced pandemic planning: workshops with stakeholders, strategy development, implementing emergency processes (hygiene, communication, administration, emergency measures), trained the pandemic management team, procured and managed hygiene supplies and medical products
- Introduced BCM: hazard analysis, strategy proposals with cost analysis, interviews and workshops (around 300), set up and integrated software to manage a 1500-person emergency organization
- Rolled out emergency processes to all 14 branches, 2 call centers, and the bank
- Designed, tested, and implemented a BC tool to manage emergency processes and around 200 customized emergency plans
- Introduced crisis communication: strategy development, workshops for crisis managers, communication matrix, individual emergency plans, external dark sites, and operational implementation
- Operational risk management: supported the introduction and calculation of operational risks in collaboration with the operational risk team
- Prepared for the establishment of AXA Bank Europe Prague/Brno: strategy definition for entry into the corporate and retail markets, market analysis in Czech Republic/Slovakia, product analyses and legal requirements, presentation to management in Brussels
Project Manager
Commerzbank
- Advanced BCM: introduced crisis communication, adapted to audit requirements and MaRisk, and set up a crisis team
- BCM exercises: scenario development, training of auditors and observers, led the exercises, and lessons learned with internal audit
- Adapted disaster recovery data center (DR): analyzed the IT environment in Frankfurt, updated emergency processes for all departments, and synchronized processes and communication between Frankfurt and Prague
- BCM/DR exercise: test run of IT fallback to DR data center and one week of emergency operations, scenario setup, leadership, lessons learned, and final presentation
- Introduced BCM for investment banking: hazard and risk analysis, developed strategy options, supported setting up emergency trading rooms in Frankfurt, defined processes and communication, live exercise, lessons learned, and final presentation
- Designed, tested, and implemented a BC tool to manage emergency processes and customized emergency plans
- Success stories: maintained operations in the DR data center during violent protests and continued operations for two weeks during a flood without outages
Industry Experience
See where this freelancer has spent most of their professional time.
Experienced in Banking and Finance, Insurance, and Energy.
Business Area Experience
See which departments and functions this freelancer has contributed to most.
Experienced in Information Technology, Project Management, Operations, Audit, and Strategy.
Summary
I have built a solid track record in management consulting through diverse roles in energy, finance, insurance, and banking industries. I excel at designing and implementing risk and business continuity processes, developing effective governance frameworks, and executing complex security measures. My work ranges from establishing cyber risk management and building CERT teams to leading critical BCM projects with measurable impact.
I bring hands-on experience with process optimization, robust documentation, and audit support, supported by certifications in ISO 2700x, Lean Six Sigma, Scrum, and Prince2. I use my deep knowledge and structured approach to deliver reliable, secure, and efficient solutions in dynamic environments.
Skills
- Solid Knowledge Of Most Areas Of A Bank
- Good Overview Of Insurance Departments
- Good Business Know-how
- Extensive Experience With Emergency And Security Concepts
- Cross-departmental Approaches In It, Finance, Risk, Customer, And Legal
Languages
Education
Executive MBA · Finance/East-West Management/EU Law · Krems an der Donau, Austria
Diploma in Export Sales · International Law/Finance/Logistics/Marketing
Certifications & licenses
ISO 2700x Lead Implementer (Information Security)
PSM, Professional Scrum Master
Prince2® Foundation
Lean Six Sigma, Green Belt
Statistics
Experience
Global Experience
Expertise
Qualifications
Profile
Frequently asked questions
Do you have questions? Here you can find further information.
Where is Herbert based?
What languages does Herbert speak?
How many years of experience does Herbert have?
What roles would Herbert be best suited for?
What is Herbert's latest experience?
What companies has Herbert worked for in recent years?
Which industries is Herbert most experienced in?
Which business areas is Herbert most experienced in?
Which industries has Herbert worked in recently?
Which business areas has Herbert worked in recently?
What is Herbert's education?
Does Herbert have any certificates?
What is the availability of Herbert?
What is the rate of Herbert?
How to hire Herbert?
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Management Consultant
Nearby freelancers
Professionals working in or nearby Prague, Czech Republic
