Systems don't fail at the controls you see.
They fail at the assumptions no one tested.

0DCyber Sagl is a Switzerland-based cybersecurity and GRC consultancy built on forty years across the full stack: from writing code to running boards. We work as an external advisor, and as fractional C-level security leadership for organisations that need senior authority without a full-time hire.

Beyond Checklists

Forty years across the full stack, from writing code to running boards, taught one thing: real risk hides in flawed assumptions and in the relationships between systems, not in isolated technical flaws. Checklists catch what was already anticipated. They don't catch what nobody thought to ask.

0DCyber brings offensive insight, defensive capability, and governance into one coherent view. We design controls grounded in how attackers actually operate and in how risk propagates through an organisation, not in checklist theory. The name reflects the arc the work is built on: from the lowest layer of the stack to the boardroom. Right now that means particular depth in two areas: blockchain and crypto-asset risk, and how organisations actually use AI, the two surfaces changing fastest.

How this practice was built

A point of view formed by having actually built, broken, investigated, governed, and navigated new terrain, in that order.

01

Builder

Built from the ground up in software development: C/C++, assembly, Unix, networking. Working at the lowest layers of the stack taught the core lesson early: systems rarely fail at visible controls, they fail at flawed assumptions.

02

Breaker

Adversarial analysis came next: understanding how systems are actually exploited, not how they're assumed to be secure. A direct grasp of attacker methodology has driven a defensive-by-design approach ever since.

03

Investigator

Digital investigations and forensics work, including consulting for law enforcement, added a third discipline: treating data as evidence that requires integrity and traceability, not just availability.

04

Guardian

All three disciplines consolidated into governance leadership: vCISO for a Tier-1 international bank, group-wide security risk governance in healthcare, and board-level reporting that translates technical risk into business decisions.

05

Navigator

The same rigor extended to the newest attack surface: on-chain forensics for crypto assets and smart contracts, and risk controls for how organisations actually use AI. Same discipline, applied to terrain that didn't exist when this arc started.

Precision Instrument

Services

Light Refraction Prism

Blockchain & Crypto Asset Forensics

Wallet and asset verification before deals, mediation, or escrow closes. Broader on-chain fraud investigation (rug pulls, fake tokens) and technical litigation support with chain-of-custody discipline.

Precision Lock Mechanism

Smart Contract Review

Deep technical audits of smart contract logic to identify vulnerabilities before deployment, ensuring assumptions match mathematical reality on-chain.

Water Ripples

AI Usage & Data Leak Risk

Assessing how teams use LLMs and AI tools. Implementing guardrails to prevent proprietary data or source code from becoming public training data.

Security & Compliance Assessment

Mapping the reality of your infrastructure against frameworks like ISO 27001 or NIS2. Identifying gaps between written policies and actual technical implementations.

Fractional CISO

Senior security leadership on an ongoing, part-time basis. Translating technical risk into business terms for the board, managing incident response, and steering security strategy.

Compass Needle

Security Awareness Training

Practical, non-theoretical training programs designed to change behavior, not just tick compliance boxes. Built on experience training over 20,000 employees.

This isn't theoretical.

In 2026 I was personally targeted by a social-engineering campaign built around a fake job interview: a convincing counterfeit of an AI coding-assistant installer as the delivery vector, aimed at reaching cryptocurrency wallet data. I caught it early, verified exactly what it touched against threat-intel reporting on the same campaign, confirmed no persistence, and closed it out without loss. Human trust, AI tooling, and crypto custody: the same three pressure points are where most organisations are least prepared, because most people assume this only happens to someone else.
Founder, 0DCyber

Track record

40 Yrs
Roughly 40 years in IT, 25+ in cybersecurity.
vCISO
Fractional or full-time vCISO leadership for a Tier-1 international bank, an ongoing engagement maintained for as long as the mandate requires, not a fixed term.
20k+
Group-wide security risk governance across roughly 50 facilities and 20,000+ employees, spanning multiple countries, from board-level reporting to on-the-ground incident response.
Sectors
Security leadership spanning banking, healthcare, energy, fintech, and telecom (CH, IT, MT).
Forensics
Digital and blockchain forensics, including wallet/asset investigations and consulting work for law enforcement.
Discreet
Confidential personal-brand and reputation-protection for high-profile individuals.

How we work together

0DCyber works two ways: as an external advisor brought in for a defined engagement, and as fractional or contract C-level security leadership for organisations that need senior authority on an ongoing basis without a full-time hire.

Every engagement starts with a short scoping conversation: what's actually at stake, what the board or counterpart needs to see, and what a realistic outcome looks like, before any scope or commitment is fixed.

Contact

To start a scoping conversation, send us a message.