Marco BrondaniSecurity, AI risk and platform strategyBook a call

Operator record

About

Nearly three decades as the person responsible for whether complex systems hold together or quietly fall apart.

Nearly three decades in technology and security leadership, as a CISO, as a CTO, as the person responsible for whether complex systems hold together or quietly fall apart. I have built platforms, secured them, watched them scale, and dealt with what happens when architectural choices made years earlier finally surface as consequences nobody planned for.

That work has crossed industries and architectures: retail and hospitality, financial services, traditional distributed systems, blockchain infrastructure, enterprise platforms, across the US, Europe, Japan and the Asia-Pacific region. Along the way I have been named on patents as inventor and co-inventor, not because patents are the point, but because the problems I was working on did not have existing answers.

Patents

The two most recent are the ones that bear on the work I do now. System and method for interoperable digital asset creation, management and execution (Futureverse IP, US20250284511A1, 2025), where I am first-named inventor. And System and method for collecting and managing contextual data related to the activity of AI agents (Futureverse IP, US20250111358A1, 2025), which is the problem of knowing what an autonomous system actually did, approached from the inside rather than from the governance layer above it.

Three earlier families came out of web platform work at UsableNet between 2012 and 2017, covering web service implementation, menu compression and automated site analysis. All five are on Google Patents.

Most people at this intersection come from one direction or the other. There are security professionals who understand governance but not architecture, and technology leaders who can build platforms but have never sat with the accountability when those platforms fail. Having been both, I read the gap between how a system is supposed to behave and how it actually behaves under pressure from both sides. That is the judgment the work rests on.

Somewhere in that breadth a conviction settled in. The most important questions in technology are almost never technical. They are about power, accountability, and what happens to both when systems become too complex for any single person to fully understand. That conviction is what produced OSRA, which audits the infrastructure substrate that governance frameworks assume and do not verify, and it runs through the books and the essays as well.

I work with organizations navigating decisions they cannot fully delegate. Mid-market companies facing NIS2, DORA or EU AI Act obligations without the internal expertise to govern them properly. Founders and leadership teams making platform architecture choices whose security implications will not surface for years. Boards that need someone in the room who speaks both languages, technical and institutional, without losing precision in either direction.

I am based in Germany and available globally. Working languages are English and Italian.

Next step

Book a call

A thirty minute call to establish what you are exposed to and whether an engagement is worth running.

Book a call