André Ataíde

Cyber Security Consultant & Advisor · Intelligence-to-Operations bridging

Portugal

I help technology teams prepare the evidence that regulators, auditors, and investors require — without slowing down delivery.

My work sits at the intersection of security governance, GRC, and engineering. I build systems that connect detection output, compliance controls, and release gates into audit trails that are ready when the regulator asks.

Everything I produce is grounded in the EU Cyber Resilience Act (CRA), ISO 27001, NIS2, and DORA.

No active detection pipeline

Knowing a CVE exists in the NVD is not the same as knowing it is being actively exploited. Without correlation against CISA KEV, the CRA Article 14 notification clock starts running without the organisation knowing.

No decision evidence

Regulators do not ask for the patch — they ask for the record of who assessed the risk, when, with what criteria, and what was decided. A Jira ticket and a git commit are not that record.

Knowing ≠ demonstrating

An organisation can have solid internal processes and still fail CRA compliance — because it did not produce the artifacts the regulation requires as proof. Annex VII must exist on paper.

Wardex

Risk-driven release gate engine. CRA Art. 14 notification artifacts, KEV correlation, and HMAC-chained audit trail.

Gleipnir

3CP reference implementation — tokenless, VRF-verified post-quantum provenance anchoring for chain of custody.

I2O (Intelligence-to-Operations)

Practical lab bridging CTI and operations — evolving from misp-playground into a full intelligence-to-operations workflow environment.