WIRD.
25+ years in IT consulting · ISACA CISA auditor

Governance that holds.
Security that's tested.
AI that pays back.

The executive partner for CEOs, CIOs and CISOs at companies where an hour of downtime, a failed audit or a botched migration costs far more than the consulting does. No project starts without a business case that still holds up at twelve months.

Active certifications

ISACA CISA ITIL 2011 Foundation Project Management Foundations — PMI

Certification track record

  • AWS Solution Architect – Associate · 2013–2016
  • PCI Professional (PCIP) · 2015–2018
  • ICT Security Specialist UNI 11506 · 2015–2018

Earned and not renewed: the skills are still operational, the formal credential isn't. I'd rather say so up front.

What I do

Six areas that overlap far more than companies expect: a security incident is almost always a governance problem too, and an AI project that ignores cloud spend never makes it to production.

Cloud Strategy & AWS

Cloud migration, serverless architecture and infrastructure cost optimisation (FinOps) on AWS.

AI & LLM Consulting

Generative AI integration, RAG systems over internal knowledge bases and intelligent process automation.

Google AI Essentials certified (Data Analysis, Content Creation, Research, Planning, Gemini)

Cybersecurity

ISACA CISA security audits, PCI-DSS and ISO 27000 compliance, and data protection in enterprise environments.

IT Governance

Project management (PMI/ITIL), vendor management and IT process re-engineering.

IT Due Diligence & M&A

IT and security posture assessment of target companies, for investment funds and acquirers: as-is analysis, gap to the required to-be, and CapEx/OpEx estimates backed by verifiable data.

Fractional CTO / CISO

Executive leadership on demand. Strategic direction to align technology with business objectives, without carrying the fixed overhead.

Selected engagements

What the work actually delivers

A few examples of how I support clients day to day — including the obstacles hit along the way.

AI / ANALYTICS

Smart Tips & Decision Intelligence

Multi-brand e-commerce group · 4 owned stores + marketplaces · ~120 employees · 6-month project

The work: algorithms that analyse company data flows in real time. The system generates proactive "Smart Tips" for management, surfacing corrective actions while they still matter.

The obstacle: for the first two months the system threw too many false signals. Sales data arrived from different platforms, with misaligned product taxonomies and orders duplicated between owned stores and marketplaces. I had to normalise the collection pipelines before management started trusting the recommendations.

Outcome: Once normalised, data-driven decisions in seconds instead of days, with stable adoption across the first two stores by month four.
GEN AI / AUTOMATION

Predictive Maintenance & App Generation

Mid-sized manufacturer, mechanical components · ~150 employees · 4-month project

The work: machine learning to predict failures on industrial plant, plus LLMs to auto-generate boilerplate code and speed up in-house application development.

The obstacle: the first predictive model, trained on only a few months of historical data, raised too many alerts on noisy sensors. I retuned the thresholds and put the experienced maintenance crew in the loop before going live. On the code-gen side, mandatory human review came in after the first auto-generated bugs.

Outcome: -30% unplanned downtime on the monitored lines and +50% development speed on internal applications, measured over the six months after release.
GOVERNANCE / ISO

ISO 27001 Compliance

B2B software house · ~60 employees · 8-month project

The work: end-to-end consulting through ISO 27001 certification. ISMS scope definition, security policy drafting, risk management and support through the certification body's audit.

The obstacle: the certification body's audit surfaced a minor nonconformity in privileged access management. I closed the gap in three weeks so the certification wouldn't slip.

Outcome: Certified on the first audit cycle, nonconformity closed on time, and security now part of day-to-day operations.
SECURITY / NIS2

NIS2 Directive Compliance

Multinational S.p.A., professional foodservice equipment (HORECA) · ~300 employees · 7-month project

The work: gap analysis and remediation plan for "essential" and "important" entities. Implementation of the technical and organisational measures the EU cyber-resilience requirements demand.

The obstacle: the gap analysis turned up more shadow IT than expected, and legacy OT systems never designed for the segmentation required. I had to renegotiate the remediation plan with the industrial plant vendors, adding roughly two months to the original estimate.

Outcome: Full compliance ahead of the regulatory deadline, with a business continuity plan tested and documented for the board.
AWS / HYBRID

Hybrid & Scalable Cloud

Highly seasonal e-commerce · ~80 employees · 5-month project

The work: hybrid architectures connecting on-premise datacenters to AWS, using managed services to guarantee automatic scaling through peak load.

The obstacle: during the first production failover test, auto-scaling didn't react fast enough to a simulated spike and checkout slowed briefly. I revised the scaling policies and alert thresholds before final go-live.

Outcome: The following Black Friday ran with zero downtime, and infrastructure costs stayed under control thanks to the FinOps monitoring introduced mid-flight.
M&A / DUE DILIGENCE

IT Due Diligence for an Acquisition

Private equity fund · target company assessment · 6-week engagement

The work: IT and security posture assessment of a target company on the acquiring fund's mandate, across six domains: Governance & Risk Management, Infrastructure & Network, Identity & Access Management, Business Continuity & Disaster Recovery, Applications & ERP, and AI Governance & Shadow AI. Valuation of the existing IT assets and CapEx/OpEx estimates for the investment needed to close the gap between the as-is found and the to-be the fund required. Reporting produced with AI support.

The obstacle: in due diligence you get no direct access to production systems — the picture has to be reconstructed from documentation, interviews and indirect checks, in a matter of weeks. The AI Governance domain took unplanned extra work, because AI tools the target's IT function had never inventoried turned out to be in daily use.

Outcome: CapEx/OpEx figures backed by verifiable data and an as-is → to-be path documented domain by domain: a financial picture that holds up at the negotiating table.
Portrait of Andrea Toso, founder of WIRD
Who's behind WIRD

Andrea Toso

Founder · Innovation Advisor & AI Strategist

25+ years' experience ISACA CISA Auditor

Over 25 years in the field, alongside industrial groups and companies of every size through the challenges of digital transformation. My job is to close the gap between technical innovation and what management is actually trying to achieve.

Innovation doesn't get improvised: every strategy I put forward is balanced by rigorous risk control and regulatory compliance. Technology should be invisible, effective and secure — so the business can stay focused on its core.

I work hands-on: I don't stop at the theory, I take part in defining and executing the strategy, managing resources and technology vendors. The best solutions don't come out of a lab — they come from listening closely to what the company actually needs.

Full background on LinkedIn

I'm not the cheapest option

And I don't try to be. Better said up front, so neither of us wastes time.

This works if

  • An hour of downtime, a failed audit or a data breach costs you more than the consulting does.
  • You want someone who stands behind what they advise against, not just what they sell.
  • You need senior capability across several fronts — security, cloud, governance, AI — without building an in-house department.
  • You'd rather talk to the person doing the work than to an account manager.

Probably not me if

  • The deciding factor is the lowest quote for the same number of days.
  • You need execution against specs someone else has already locked down, with no room for technical judgement.
  • The goal is a certificate to hang on the wall, with no intention of changing the processes.
  • You're looking for a supplier who always says yes.

Straight answers

Does AI deliver measurable ROI right away, or is it just hype?

Generative AI isn't there to play with, it's there to cut waste. I implement solutions — RAG assistants, predictive analytics — only when the business case shows a return within 6–12 months. No experiments, just operational efficiency.

If we get hit by ransomware, is my company legally covered?

Criminal and civil liability usually lands on the board. Aligning to the NIS2 directive and running ISO 27001 audits doesn't just lock down the data — it shields management from legal exposure and keeps the business running even under attack.

Is AWS cloud spend predictable, or am I risking surprises on the invoice?

Pay-as-you-go cloud gets away from you without governance. I apply strict FinOps practice: real-time monitoring and intelligent auto-scaling. You pay for the resources that generate value, and the infrastructure waste goes away.

Can we modernise IT without stopping production?

I know an hour of downtime costs thousands. The migration strategy I use (hybrid cloud) is designed to run in parallel. I modernise the technology stack while your company keeps invoicing, with no operational interruption.

Why an external partner instead of hiring an in-house IT manager?

Hiring a CISO, a cloud architect and an AI specialist would run north of €200k a year in fixed salary alone. With WIRD you talk to me directly — ISACA CISA certified auditor, with hands-on experience across AWS, governance and AI — a single point of contact covering all of it, with a network of specialists I bring in when a project needs extra capacity, and you pay only for the time actually required.

How do you handle confidentiality around our data and sensitive business information?

I sign an NDA before any data is shared or any system access is granted, and I apply the same least-privilege principle I recommend to my clients: I access only what the project requires, for as long as the project requires it. Nothing relating to a client is shared with third parties — not even anonymised — without explicit authorisation.

If we use generative AI, does our company data end up in someone else's model?

No. For every AI project I first assess what data can leave the company perimeter and under what contractual guarantees (training opt-out, EU-region hosting). Where confidentiality is critical I steer towards self-hosted models or enterprise APIs with explicit no-training clauses: the same care I apply to security and governance applies to AI.

How does the engagement work — fixed contract, project-based or pay-as-you-go?

It depends on the objective. An audit or a certification (ISO 27001, say) is typically project-based, with defined milestones and deliverables; a fractional CTO/CISO role is a retainer with an agreed, reviewable number of days per month. Either way you deal directly with the person doing the work, not an account manager — and it's the first conversation that settles which model fits.