Founder Story
Elias Nassall: This Can Be Done Better
Five years of Big Four consulting and one thought on repeat: this can be done better. Elias Nassall explains why he is building at KaitoSec the solution he wanted on every project, and what resilience means to him.
By Elias Nassall · Published 9 October 2026 · 5 min read
During my years in consulting, the same thought kept coming back to me: this can be done better. The connection between management systems can be done better. Working with the standards can be done better. And for the client, it can be faster, more efficient and cheaper.
At KaitoSec, we are now building exactly the solution I always wanted on my projects.
Who I am
I'm Elias Nassall, 27 years old. I studied security management and then spent around five years in Big Four consulting, working in cybersecurity. My clients came from both the public sector and private industry, in the context of NIS2, DORA, IT-Grundschutz and BSI Standard 200-4.
The work covered information security, emergency management and resilience. But my real passion was always business continuity management. I care deeply about keeping the lights on, no matter what happens. Making sure processes keep working and customers keep getting served.
Certificate or security
The clients I supported as a consultant came with very different motives. Some wanted a certificate fast so they could be compliant. Others genuinely wanted to become secure and build resilience. And in between, there was every combination under the sun.
Both are legitimate. A certificate opens doors, and under NIS2 or DORA many organizations simply have no choice. But what always drove me more was the second question: will the lights stay on when things get serious? A certificate alone doesn't answer that.
Whatever goal a client came with, the road there often looked similar: lots of documentation and lots of manual work. The more time went into these mandatory exercises, the less was left for what actually matters. And that's exactly where it started to bother me.
This can be done better
There wasn't one single moment that brought me to KaitoSec. It was a series of experiences in which I kept seeing how inefficient the old way of doing things is.
Moving content from one document to the next by copy and paste. Spending what felt like several weeks filling in mapping tables for every new standard, starting from scratch each time. And most of the time, the data already exists. Take a BCMS engagement: much of what I need for it is already there at the client. It just isn't connected.
I'm convinced there are better approaches. That conviction is why I joined KaitoSec. Our goal is to build compliance and resilience together, as efficiently and painlessly as possible for our customers.
Security shouldn't depend on budget
Many organizations, especially mid-sized companies and the public sector, don't have a large team for information security and BCM. Often a handful of people carry it on top of their day-to-day work, on a tight budget. For them, compliance mostly means extra effort: gathering information and filling out questionnaires. That can really hurt.
On top of that comes the complexity of the cybersecurity world. Process structures have to be examined, and requirements from different management systems are interconnected. At KaitoSec, we have turned this knowledge into software. That makes the complexity accessible even to people with no prior experience.
The platform isn't meant to just make work easier, but to take it off your plate. Data that has been captured once is reused across management systems and standards instead of being requested again for every new standard. If you have few people, you save time and effort and can focus on the decisions that really need a human.
Ultimately, we are lowering the barrier to entry. We want to make cybersecurity accessible to small companies too, because everyone has a right to security. For a long time, large vendors charged a lot of money for it. We want to help break down that barrier.
What I do today
At KaitoSec, my main focus is driving business continuity management forward: according to ISO 22301 and BSI Standard 200-4, and connected with other standards. I want to approach resilience holistically, beyond any single standard. I also talk to customers.
Alongside that, I work in business continuity management at an operator of critical infrastructure (KRITIS). There, I help make sure people can rely on their electricity to live their everyday lives in comfort and safety. In essence, you're also safeguarding livelihoods.
What resilience means to me
To me, resilience means adaptability. Having the awareness for a situation and then being able to act the way it demands. In other words, being able to be what the situation requires of me.
That includes not only reactive structures that kick in once damage has occurred. It also includes structures that let me prepare for a situation in advance. And for that, I need to know which situations could come my way in the first place. Adaptability requires a holistic understanding.
The other part is the human component. Systems are only as good as the people behind them, in understanding them just as much as in using them. And in the end, it's people who are affected by cyberattacks and other incidents. On one side as victims, on the other as the ones who have to respond: as crisis managers, as managing directors, as process owners.
People respond with the help of systems, but also out of their training, their personality and the routines they have built for themselves. As human beings, not just in their professional role. That's why, to me, resilience is also personal strength, and it belongs in every cybersecurity process.
If you'd like to talk about business continuity management or resilience, feel free to reach out to me on LinkedIn.
- Founder Story
- Resilienz
- Business Continuity Management
- Informationssicherheit