Dionysis Karamitopoulos
Fractional CTO | Security Governance, GRC & Cyber Risk
Operating focus
Industry experience
Cybersecurity · GRC · Technology · Gaming & Entertainment · Professional Services
Company stages
SME · Enterprise · Independent Advisory
Operating regions
Europe (Greece · Germany) | Remote International Advisory
Languages
Greek · English
Executive statement
I am a security-focused Fractional CTO and GRC Security Architect specialising in security governance, cyber risk management, control design and audit-ready compliance. I work with organisations that need to strengthen cybersecurity governance, establish clear risk ownership, improve control effectiveness or prepare for regulatory and audit requirements. I translate security, privacy and regulatory obligations into practical operating models, measurable controls, risk treatment decisions and accountable governance structures. My work covers ISO/IEC 27001:2022 implementation, ISO/IEC 27701 privacy governance, NIS 2 readiness, GDPR alignment, enterprise risk assessment, compliance auditing, security architecture, Microsoft 365 security and Identity and Access Management. At executive level, I help determine security priorities, risk treatment, control ownership, governance structures and the level of exposure the organisation is prepared to accept. I work across leadership, technical teams, risk and compliance functions to ensure that cybersecurity decisions are aligned with business objectives rather than treated as isolated technical activities. My technical background allows me to bridge governance and implementation. I assess whether controls are not only documented, but correctly designed, implemented, evidenced and capable of demonstrating effectiveness. The outcomes I focus on are stronger risk visibility, clearer accountability, improved control maturity, reduced security exposure and sustainable audit readiness. My objective is to give leadership a defensible view of cyber risk while building security governance that can operate effectively as the organisation grows.
Leadership scope
Owned security architecture, governance and compliance outcomes across infrastructure, endpoint security, identity, risk and ISO/IEC 27001 readiness initiatives. Led security infrastructure build-out and control implementation in business environments, including regulated and business-critical casino operations. Currently provide independent advisory on cybersecurity governance, GRC, cyber risk, AI security governance and third-party security, translating technical and regulatory requirements into risk treatment and control decisions.
Selected outcomes
- Built a company security infrastructure from the ground up, covering firewall, VPN, endpoint governance and secure access controls.
- Led ISO/IEC 27001:2022 readiness activities across policies, risk assessment, control alignment and certification preparation.
- Designed and developed a GRC platform now piloted with 4 German companies for risk, controls, evidence and audit-readiness workflows.
- Supported security governance and risk decisions across cybersecurity architecture, AI risk and third-party security through a global expert advisory network.
Profile verified 2026-08-28. Direct contact details are shared only after a mutual introduction.