
Alberto Afonso
Subject Matter Expert | Area Partner | Cybersecurity | Information Security | ISO/IEC 27001 | Risk Management | Business Continuity
About the specialist
Information security and cybersecurity specialist with more than a decade of professional experience, focused on the implementation and coordination of information security management system projects based on ISO/IEC 27001.
He has supported public and private organisations in security maturity assessment, risk management, conformity assessment, development of policies and procedures, business continuity, disaster recovery and cybersecurity incident response.
He applies international frameworks such as ISO/IEC 27001, ISO/IEC 27005, NIST SP 800-37 and CIS Controls, and carries out vulnerability assessments and penetration testing of networks and web applications.
He has particular experience in the Angolan market, including the banking and financial sector, strengthening organisations' security, resilience and risk management capability.
Areas of Expertise
Information Security and Cybersecurity
- Information security management systems
- ISO/IEC 27001
- Cybersecurity
- Security maturity assessment
- Vulnerability management
- Penetration testing
- Network security
- Web application security
- Cybersecurity incident response
- CIS Controls
- NIST
Risk Management and Compliance
- Information security risk management
- ISO/IEC 27005
- NIST SP 800-37
- Risk assessment and treatment
- Conformity assessment
- Compliance management
- Gap analysis
- Security control assessment
- National and international standards and regulations
Business Continuity and Resilience
- Business continuity planning — BCP
- Disaster recovery planning — DRP
- Business impact analysis — BIA
- Business continuity management
- Disaster recovery
- Incident management and response
Integrated Security
- Physical and logical security
- Integrated security systems
- CCTV
- Access control
- Infrastructure security
Sectors of Experience
Credentials
10 years of professional experience
- Credentials
- 10+ years of professional experience in information security and cybersecurity
- Certified Information Systems Security Professional — CISSP, ISC2
- Certified Cloud Security Professional — CCSP, ISC2
- ISO/IEC 27001 Lead Implementer, PECB
- Darktrace Cyber Engineer
- Experience leading and coordinating information security and cybersecurity projects for medium and large organisations in Angola
- Experience in security maturity assessment, risk management, conformity assessment and control implementation based on international frameworks
- Experience developing information security policies and procedures, business continuity plans and disaster recovery plans
- Experience coordinating cybersecurity incident response teams, vulnerability management and penetration testing of networks and web applications
Available Services
Information Security Consulting
Diagnosis, maturity assessment, definition of policies and procedures and development of information security systems and controls.
ISO/IEC 27001 Management Systems
Implementation, maintenance and improvement of information security management systems in line with ISO/IEC 27001.
Cybersecurity
Security posture assessment, vulnerability identification, control assessment and strengthening of incident prevention and response capability.
Risk Management
Identification, assessment and treatment of information security risks based on frameworks such as ISO/IEC 27005 and NIST.
Business Continuity
Development of business continuity plans and disaster recovery plans, contributing to organisations' operational resilience.
Audit and Compliance
Assessment of conformity with national and international information security and cybersecurity standards, regulations and frameworks.
Training
Training and technical capability programmes in information security, cybersecurity, ISO/IEC 27001, risk management and business continuity.