I help organisations secure the systems their operations depend on — and adopt AI without adding new risk. Application security, DevSecOps and production-critical IT/OT environments, plus AI agents that make information findable.
Göran Norell · CISSP · Sandviken, Gävleborg · Remote and on site
Who I work with
Manufacturing and industrial organisations running production-critical IT and OT environments, and development organisations that need security built into how software is written and shipped rather than bolted on afterwards.
Organisations working through what NIS2 and the Cybersecurity Act mean in practice, putting an ISO 27001 way of working in place, and deciding how to use AI responsibly under ISO/IEC 42001.
Services
How I work
You describe the situation. I tell you whether I'm the right person for it, and what I'd suggest as a first step. No cost, no obligation.
A scoped look at the systems, the way of working, or the regulatory requirement in question — ending in findings and a risk-based order of priority.
The work gets done with your people rather than around them, so the capability stays in the organisation after I leave.
About
I've spent my career on the inside of large industrial IT: first as a systems developer, then as an agile team lead and project manager, and most recently as a security lead securing Manufacturing Execution Systems at Sandvik Coromant. I hold a CISSP and an MSc in Computer Science, and I've built AI agents that make large document sets searchable. I work from Sandviken, remotely and on site.
More about me →Describe the situation and I'll tell you whether I can help. I reply within [X business days].