I'll tell you what you don't want to hear. Then I'll help you change it.

Security Architecture · Secure Development · AI Agent Security · Compliance · vCISO

15+ years in security · CISSP · CSSLP · CCSP · ISO 27001 Lead Auditor

Who I Am

Nila Löber

I’m Nila Löber, working in IT since 1996. Long enough to have seen every hype cycle from dot-com to LLMs.

Information security since 2010, cloud since 2017, AI-assisted development since 2022. I’ve been hired as both the hip tech innovator and the adult in the room, sometimes on the same project. My background in Cultural Anthropology, Philosophy, and Computer Science doesn’t make me smarter than anyone — but it does mean I talk about things most technologists don’t. Like why your security measures aren’t failing because of the tech, but because the organization isn’t coming along for the ride.

The security industry runs on fear. I’d rather tell you where you actually stand — even if it’s not what you wanted to hear. Informed decisions over horror stories.

Berlin-based, working across Europe. Currently open to part-time engagements.

What I Do

Security Architecture & Risk Management

Threat modeling, risk assessments, architecture reviews. The goal is a clear picture of where things actually stand — not a dramatic reveal of how doomed everyone is.

Secure Software Development

SSDLC process design, secure code practices, DevSecOps. Security bolted on at the end is theater. I help build it in from the start.

AI & Coding Agent Security

Most teams are already writing code with AI assistants. The question isn’t whether to allow it — it’s whether anyone knows what’s actually happening. Assessment, policy, awareness training, implementation guidance.

Compliance & Certification

ISO 27001 internal audits, NIS2 readiness assessments, CRA compliance support. Compliance done well is a mirror — it reflects how an organization actually operates. Done badly, it’s a painting of how they wish they did.

Also happy to take on sector-specific compliance, e.g. BSI TR-03109 (smart metering), BSI TR-03187, aviation cybersecurity (DVO 2019/1583).

Vibe Coding Cleanup

Your business team built something with AI tools and now they’re stuck — it half-works, IT hasn’t signed off, and compliance has questions. I take what they’ve built, make it production-ready, and get everyone aligned: the team that built it, the IT department that has to run it, and compliance that has to approve it.

vCISO

Security leadership on retainer. Strategic oversight without the full-time headcount. For organizations that need the expertise on call, not on payroll.

Packages

AI Agent Security Package

Starting at €3,000

Assessment · Policy Framework · Awareness Training · Implementation Guidance

Most teams are already writing code with AI. Having a plan for that wouldn't be a bad idea.

SSDLC Foundation

Starting at €5,000

Maturity Assessment · Process Design · Developer Security Training

So there's something concrete to show when enterprise clients ask about secure development practices.

Compliance Kickstart

Starting at €7,000

Technical Gap Analysis · Remediation Roadmap · Internal Audit Preparation · Legal Partner Referral

ISO 27001 or NIS2 deadline looming? This turns 'we should probably do something' into a concrete plan.

AI Literacy Training (EU AI Act Art. 4)

Starting at €2,500

Regulatory Framework · Technical AI Literacy · Risk & Security · Governance

Legally required since February 2025. Most companies haven't done it yet. You probably haven't either.

Credentials

CISSP CSSLP CCSP ISO 27001 Lead Auditor AZ-500 SC-100
  • 15+ years in information security
  • Security architecture for automotive OEMs, IoT platforms, insurance, eHealth, privacy tech
  • Speaker on coding agent security, secure software development, and security architecture
  • Things I've built: JCE providers, PKI systems, SSO solutions, Common Criteria documentation, CI/CD pipelines, automated security tests, AuthZ implementations

From the blog

Checking the Receipts: July

Published 1 Jul 2026

What tech leaders said about AI in July 2022-2025, and what actually happened. Month four of the accountability series.

Checking the Receipts: June

Published 1 Jun 2026

What tech leaders said about AI in June 2022-2025, and what actually happened. Month three of the accountability series.

All posts →

Get In Touch

Whether you need a second opinion on your security architecture, want to get your AI agent usage under control, or just for getting to know each other — I'd love to hear from you. No contact form, because I practice what I preach.