About

Who I am
I build insider risk capabilities for European organizations: the mandate and the operating model, the controls and the investigations, and the technology that carries them.
I am a senior insider threat specialist at a large European banking group, where I am building the insider threat capability from the ground up and acting as lead analyst. That means writing the processes and playbooks, presenting the function, resolving the friction between the parts of the organization it touches, and also configuring the tooling, triaging alerts, and working the cases.
Before that I spent over thirteen years as an officer in the Italian Army, in HUMINT and counterintelligence. The job then was reading intent from incomplete traces, to protect information, people, and assets. It still is.
Why I write
The doctrine of this discipline is almost entirely American, and its assumptions about collection do not survive contact with European employment law, works councils, and data protection. The difference is not only legal: what a security function is taken to be, and what it may reasonably ask of a colleague, is read differently on the two continents. The answers Europe needs exist, some in the instruments and the rest in the people doing the work, and neither is gathered in a common record. Setting them down is the work this site does. INTRA™ carries what the sources establish for a program, measure by measure, so that nobody has to assemble the record a second time. ITER™ carries what an insider event obliges, and from when: the reporting acts, the term on each, whom each is owed to, and the point the term runs from. Both are for whoever is building or running this function, and both are meant to be cited and argued with.
The thoughts and comments expressed are my own, and nothing on this site describes the internal practice of any organization I have worked for.
