Björn Bausch

External Data Protection Officer, Project Manager EU-GDPR

Björn Bausch
Limburg, Germany

Erfahrungen

Apr. 2024 - Bis heute
11 Monaten
Lorem ipsum dolor sit amet

Chemiekonzern

  • Basisprüfung NIS-2 Betroffenheit
  • Registrierung NIS-2
  • Durchführung einer IST-Analyse
  • Erstellung Pflichtenheft
  • Kontrolle der Umsetzung der NIS-2 Konformität
  • Etablierung des Meldewesens im Kontext NIS-2
  • Risikoanalyse und Sicherheit für Informationssysteme
  • Bewältigung von Sicherheitsvorfällen
  • Aufrechterhaltung und Wiederherstellung, Backup-Management, Krisen-Management
  • Sicherheit der Lieferkette, Sicherheit zwischen Einrichtungen, Dienstleister-Sicherheit
  • Sicherheit in der Entwicklung, Beschaffung und Wartung, Management von Schwachstellen
  • Bewertung der Effektivität von Cybersicherheit und Risiko-Management
  • Schulungen Cybersicherheit und Cyberhygiene
  • Kryptografie und Verschlüsselung
  • Personalsicherheit, Zugriffskontrolle und Anlagen-Management
  • Multi-Faktor Authentisierung und kontinuierliche Authentisierung
  • Sichere Kommunikation (Sprach, Video- und Text)
  • Sichere Notfallkommunikation
Jan. 2018 - Bis heute
7 Jahren 2 Monaten

External Data Protection Officer, Project Manager EU-GDPR

Techem Group

Consulting activity to support a global energy corporation with 19 companies and 6,500 employees in implementing EU-GDPR:

  • Project manager EU-GDPR
  • External group data protection officer
  • Management of kick-off workshops for respective project starts including definition of necessary preparations for subprojects
  • Data protection management according to EU-GDPR
  • Creation and implementation of various data protection concepts (e.g. deletion concepts, order data processing, IT guidelines, data breach etc.)
  • Accompanying/conducting data protection audits as part of audit activities to be coordinated and controlled
  • Consideration of GDPR, BDSG_neu TKG, TMG, IT Security Act
  • Training and gathering internal requirements of the works council (Techem AT)
  • Conducting various audits
  • Preparation for ISO/IEC 27001 certification (information security) for Techem AT
Aug. 2017 - Bis heute
7 Jahren 7 Monaten

CEO and External Data Protection Officer

b-pi sec GmbH

Management in Information Security Management and external data protection officer for various clients:

  • Disciplinary and technical management
  • Data protection
  • Data protection projects
  • Data protection management according to EU-GDPR
  • Consideration of BDSG, TKG, TMG, IT Security Act
  • Implementation of ISMS according to ISO 27001 and BSI basic protection
  • Vulnerability management
  • Forensic analysis
  • IT security implementations
  • Conducting status analyses in data protection and information security
  • Expert activities
  • Lecturer
  • Consulting services on use of automation possibilities and AI including Machine Learning
Mai 2017 - Dez. 2017
8 Monaten

External Consultant

KfW Bankengruppe

Consulting activity to support the banking group in IT Security Audits. In particular, supporting audit management in conducting IT Security Checks as part of the 2017 audit plan:

  • Project preparation and project organization
  • Support in conducting and following up IT Security Audit
  • Management of kick-off workshops at respective project starts including definition of necessary preparations and audit activities
  • Management of results presentation meetings and mediation between auditor and audited organizational unit in discussions on findings
  • Accompanying/conducting data protection preliminary/on-site controls as part of audit activities to be coordinated and controlled
  • Initiating risk analysis for findings found, plausibilization of measures to remedy findings
  • Data protection management according to EU-GDPR
  • Consideration of BDSG, BDSG_neu TKG, TMG, IT Security Act
Jan. 2015 - Jan. 2017
1 Jahr 1 Monate

Head of Department

Cyber Security Consulting Firm

Setup and management of Digital Forensics & Cyber Security department and external data protection officer for various clients:

  • Disciplinary and technical management
  • Vulnerability management
  • Forensic analysis
  • IT security implementations
  • Conducting status analyses
  • Expert activities
  • Data protection projects
  • Data protection management according to EU-GDPR
  • Consideration of BDSG, TKG, TMG, IT Security Act
  • Implementation of ISMS according to ISO 27001 and BSI basic protection
  • Lecturer
Dez. 2015 - Jan. 2019
3 Jahren 2 Monaten

Head of Department

Association of European Experts and Assessors

Contributing to and building up current IT security topics and data protection projects:

  • Head of department Data Protection & Compliance
  • Data protection
  • EU-GDPR, BDSG, TKG, TMG, IT Security Act
  • Lecturer
  • Forensics
  • Regional manager RLP & NRW
  • Seminar development
März 2010 - Dez. 2015
5 Jahren 10 Monaten

Head of IT

BBK Braun-Gillette Health Insurance

Overall responsibility for the IT department of a statutory health insurance:

  • Migration of existing server landscape to new data center
  • Creation of workflows
  • Disciplinary and technical management
  • System conversion
  • IT security consideration
  • Data protection management
  • BDSG, TKG, TMG, IT Security Act
  • Introduction of new backup solution
  • Introduction of DMS using d.velop d.3
  • Employee training
  • Documentation
  • Server system setup
  • Introduction of BI using COGNOS
  • Development of customer-specific analyses and evaluations
  • Introduction of specific workflows
  • Responsible for introducing nationwide CMS software specific to health insurance
  • Development and documentation of authorization concepts for operating systems and business applications
  • Technical and disciplinary team management
  • Monitoring migration steps
  • Escalation management
  • Discussion of relocation options with goal of decision-making on sourcing options
  • Discussion of cloud strategy
  • Definition of interfaces, especially considering cloud/outsourcing strategies
Juli 2009 - Nov. 2009
5 Monaten

Network Engineer Consultant

Syzygy Deutschland Media & Advertising Agency

Building a VMWare landscape including backup:

  • Planning and implementing VMWare projects
  • Team management
  • ESX4 introduction and support of VMs
  • Internal training
  • Planning and organizing backup topics
  • Introduction of Symantec Veritay Backup Exec 12.5
  • Network planning and support
  • Installation of various Windows servers and their support
  • Support and maintenance of implemented customer systems
  • Remote maintenance
  • Discussion of relocation options with goal of decision-making on sourcing options
  • Discussion of cloud strategy
  • Definition of interfaces, especially considering cloud/outsourcing strategies
März 2008 - März 2009
1 Jahr 1 Monate

Management Consultant

IT Strategy Consulting

  • Project management for:
  • Implementation of complex IT solutions
  • BlackBerry integrations
  • Introduction of AVAYA telephone systems
  • Migration of various Windows servers
  • Introduction of modern video conferencing systems
  • Introduction of modern backup solutions
  • IT strategy and control at international real estate corporations
  • IT strategy and control at international law firms
  • Planning, coordination and implementation of customer-specific IT training
  • Offer management, budget planning & controlling
  • Control and disposition of internal and external service providers
  • Planning, maintenance, care and migration of complex IT solutions
  • Domain-spanning networking
  • Implementation of BlackBerry servers
  • Implementation and controlling of backup solutions
  • Connection of modern ticket systems
  • Maintenance of complex Microsoft environments
  • Remote maintenance of complex Microsoft environments
  • Installation of modern firewalls
  • Setup of VPN access
  • Discussion of relocation options with goal of decision-making on sourcing options
  • Discussion of cloud strategy
  • Definition of interfaces, especially considering cloud/outsourcing strategies
Sept. 2005 - März 2008
2 Jahren 7 Monaten

Interim IT Manager

Insurance Company

Planning and realignment of IT:

  • Implementation of IT department in corporation
  • Design of IT infrastructure
  • Deployment and distribution of hardware and software
  • Working time planning
  • Work assignment planning
  • Curriculum development
  • Employee motivation
  • Employee management
  • Organization planning
  • Presentation development
  • Creation of system documentation
  • Development, organization and implementation of user-specific seminars and training
  • Discussion of relocation options with goal of decision-making on sourcing options
  • Discussion of cloud strategy
  • Definition of interfaces, especially considering cloud/outsourcing strategies
Sept. 2001 - Juni 2005
3 Jahren 10 Monaten

Senior Consultant

Deutsche Bahn AG

  • Contributing to management, operation and further development of intranet and internet application OPEN
  • Planning and configuration of information and telecommunications systems
  • Setup, operation and administration of systems according to customer requirements
  • Systematic limitation and elimination of system faults using modern expert and diagnostic systems
  • User and system consulting
  • Creation of system documentation
  • Development and organization of user-specific seminars and training
  • Implementation of user-specific seminars and training
  • Design of complex qualification projects to achieve strategic corporate goals
  • New business models and organizational forms for further education
  • Integration of e-learning
  • Criteria and methods for evaluation and controlling of further education
  • Project management for introduction of evaluation module EvaSys
  • Discussion of relocation options with goal of decision-making on sourcing options
  • Discussion of cloud strategy
  • Definition of interfaces, especially considering cloud/outsourcing strategies

Zusammenfassung

Björn Bausch ist Inhaber eines Beratungshauses für Datenschutz, Informationssicherheit und Compliance. Zeitgleich ist er in den drei Kernkompetenzen absoluter Fachexperte. Neben der Betreuung von Mandaten als externer Datenschutz- und Informationssicherheitsbeauftragter hält er regelmäßige Fachvorträge oder agiert immer wieder als Key-Note-Speaker.

Sprachen

Deutsch
Muttersprache
Englisch
Verhandlungssicher

Ausbildung

Dez. 2015 - Jan. 2019

Verband Europäischer Sachverständiger und Gutachter e.V.

IT Security and Data Protection · Germany

Zertifikate & Bescheinigungen

Auditor

DEKRA

BSI IT-Grundschutz-Praktiker

Bait / Kait / Vait - Aufsichtsrechtliche Anforderungen

Compliance Officer

TÜV

EU-DSGVO & BDSG Neu

KBW

Edv-Sachverständiger Systeme und Technik

Fachkraft für Datenschutz

DEKRA

Hinweisgeberschutzbeauftragter

ISO 27001 Foundation

PECB

IT-Forensic-Analyst

Sachverständiger IT-Forensic