Skip to content

Founder · Group CEO · Strategist

I build systems,
not heroes.

Strategy · Cyber Resilience · Governance · M&A · Technology

More than 20 years across technology, operations, cybersecurity and executive leadership — helping organizations strengthen cyber resilience, build governance that works in practice, navigate international growth and prepare for critical transactions.

Strategy matters when it survives contact with operational reality.

Christian de Coster, Founder and Group CEO of Mahoney IT Group

Christian de Coster — Founder & Group CEO, Mahoney IT Group

United States · Europe · Asia-Pacific
Years professional experience
20+Years professional experienceAcross international operations, technology, cybersecurity and executive leadership.
Years company building & leadership
10+Years company building & leadershipBuilding and leading an international technology and cybersecurity organization.
Customer environments supported
3,000+Customer environments supportedSupported by my teams across managed IT, MSSP services, cybersecurity, consulting and governance initiatives.
Aggregate M&A transaction value supported
€1.3B+Aggregate M&A transaction value supportedApproximate aggregate transaction value supported across buy-side and sell-side engagements.
Cumulative budget responsibility
€100M+Cumulative budget responsibilityCumulative budget responsibility across professional experience.
Global operating regions
3Global operating regionsUnited States, Europe and Asia-Pacific.

Strategy over heroics

I am not here to become the dependency.

My work has rarely been about solving one isolated technical problem. It is about helping an organization define where it needs to go, understand what stands in the way, and build the structure required to get there.

  • Define the target state and what it is worth
  • Identify what actually prevents the organization from reaching it
  • Make business and technology risk visible in the same language
  • Establish responsibility and clear ownership
  • Create operating structures that survive personnel changes
  • Build and develop the teams that run them
  • Make controls measurable rather than declarative
  • Connect cybersecurity to business objectives, not to a checklist
01

Operator

Understands how systems, teams and processes behave under real operational pressure — because I have run them.

02

Entrepreneur

Understands customers, capital, risk and execution, and what it costs to build an organization that lasts.

03

Strategist

Connects technology, cyber resilience, governance and business objectives into a single operating model.

04

Integrator

Brings management, security, operations, finance and technology around the same target state.

The goal is not to make an organization dependent on one expert. The goal is to build ownership, measurable controls and a team capable of operating them.

20+ years

The two experiences that shaped the method.

A list of employers explains very little. Two things explain most of it: learning to turn information into decisions, and carrying the full risk of building a business across borders.

Staff function S2

Collect. Evaluate. Use strategically.

Information is worth nothing until it is structured, assessed and turned into a decision someone can act on. Gather, verify, weigh, prioritize, prepare the decision — that discipline is still the core of how I approach risk, governance and strategy, and it is why I insist that evidence be a by-product of the work rather than an exercise before an audit.

Entrepreneurship

Building a business internationally.

Since 2018 I have built and led Mahoney IT Group: customers, capital, risk, teams, technology, partnerships and international operations, with the outcome on my own side of the table. Building an international business is not something everyone does — and having done it changes how you assess someone else's.

2018 — Present · Mahoney IT Group

The ground underneath

Before that, and alongside it, the layers that make the strategy work credible — because I have operated each of them.

The result is fluency across every layer of the conversation:

  • Technical
  • Operational
  • Management
  • Commercial
  • Customer
  • Budget
  • Risk
  • Transactions
  • Governance
  • International
  • International operations

    Time-critical execution

    International logistics, freight, aviation logistics, customs and export — where a delay is not an inconvenience but a failure.

    Nippon Express · Group7 · Fraport Cargo Services · in time Kuriersysteme

  • Technology

    IT & infrastructure

    Windows and Microsoft environments, Active Directory, Windows Server, networking, ERP, support, infrastructure and IT projects — hands-on.

    WETROPA · LDI Rheinland-Pfalz

  • Leadership

    Operations management

    Technical and commercial operations, process design, personnel, reporting, contract negotiations and organizational development.

    cde GmbH

  • Transformation

    Public-sector digitalization

    Digital strategy, process analysis, workflow transformation, document management, procurement and executive stakeholder work.

    City of Schwalbach am Taunus

Speaking & industry presence

Speaking at the Deutsche Bundesbank.

Strategy and governance only travel if they can be explained to the people who have to live with them — management, engineers, auditors and customers in the same room. That is also where an approach is tested: an institution decides very quickly whether the reasoning holds.

Speaking engagement

Deutsche Bundesbank

Germany

Germany's central bank — an audience that does not take a claim on trust. That is the standard the rest of this page is written to: a position has to survive the question behind it.

Christian de Coster presenting at a speaking engagement

The same session — and elsewhere

Audience at a speaking session with Mahoney IT on screen
From the back of the room
Christian de Coster with a colleague at the Mahoney IT stand
Biz-to-Biz, Fort Lauderdale, Florida

Cybersecurity & cyber resilience

Controls are designed differently when you have operated them.

I am not a compliance consultant who discovered security through a framework. The security work came first — operations, endpoints, identity, incidents, recovery — and that changes what a control is allowed to be.

Practical domains

  • Security Operations
  • SOC / NOC
  • SIEM
  • Microsoft 365
  • Azure
  • Active Directory
  • Endpoint Security
  • XDR / EDR
  • Incident Response
  • Vulnerability Management
  • RMM
  • Backup & Recovery
  • Vendor Management
  • Zero Trust
  • ITSM
  • Business Continuity
  • Operational Resilience

A control has to be

Realistic
It can be performed by the people who actually own it, in the time they actually have.
Technically enforceable
The platform can enforce it, not merely document that it should happen.
Operationally sustainable
It survives the second quarter, staff turnover and a busy month.
Measurable
Its status can be read as a state, not reconstructed from memory.
Auditable
It produces evidence as a by-product of being executed.

Governance philosophy

From requirement to evidence.

Governance is not a stack of policies. It is the translation of a requirement into ownership, an operational process, execution, evidence, validation and a decision management can actually make.

The chain

  1. 01Requirement
  2. 02Control
  3. 03Owner
  4. 04Process
  5. 05Operational execution
  6. 06Evidence
  7. 07Validation
  8. 08Management visibility
  9. 09Audit / decision

What a control becomes in practice

  • A defined responsibility
  • A recurring process
  • A ticket workflow
  • A technical control
  • An approval
  • A documented exception
  • A remediation task
  • Retained evidence
  • A management report

Evidence should be the natural output of a working process — not something an organization has to reconstruct before an audit.

Governance has to survive contact with reality.

Framework experience

One operating model. Multiple requirements.

Most organizations are not subject to one framework — they are subject to several at once, from different regulators and different customers. The work is to build one operating model that answers all of them, rather than one binder per requirement.

ISO/IEC 27001

ISMS design, control implementation, evidence and certification readiness.

SOC 2 Type I / II

Type I and Type II readiness, control mapping and evidence preparation.

NIS2

Cybersecurity governance, risk management and management accountability.

DORA

ICT risk, operational resilience and third-party governance.

HIPAA

Security and privacy control alignment where applicable.

NIST

Cybersecurity framework and maturity-oriented control design.

Zero Trust

Identity, access and segmentation principles applied operationally.

GDPR

Data protection expectations translated into technical and organizational controls.

Vendor Risk

Third-party oversight, evidence and accountability across the supply chain.

Business Continuity

Continuity and recovery planning that has been tested, not filed.

Incident Governance

Incident governance, escalation, reporting obligations and lessons learned.

AI Governance

Oversight, traceability and accountability for AI-supported processes.

The focus is readiness, control design, control implementation, control mapping, evidence, remediation, audit preparation and certification preparation. Independent certification and attestation remain with the relevant certification body or auditor.

Governance in operations

A control that lives in the ticket system is a control that runs.

This is what it looks like when a governance requirement stops being a document. One example, end to end.

Example control: Quarterly privileged-access review

  1. 01

    Control

    Quarterly privileged-access review.

  2. 02

    Recurring task

    Scheduled automatically, not remembered.

  3. 03

    Control owner

    A named person, not a department.

  4. 04

    Access review

    Performed against the live directory.

  5. 05

    Exceptions

    Recorded with a reason and an expiry date.

  6. 06

    Approval

    Documented by someone accountable.

  7. 07

    Evidence retained

    Produced by the work, not for the audit.

  8. 08

    Control status updated

    The control reports its own state.

  9. 09

    Management & audit visibility

    Visible before anyone asks.

Nothing here is reconstructed at year end. The evidence exists because the work happened.

M&A · Due diligence · Integration

Both sides of the table matter.

Experience supporting both buy-side and sell-side engagements creates a different perspective on cyber risk, technology debt, operational resilience and the integration that follows a transaction.

€1.3B+Approximate aggregate transaction value supported across buy-side and sell-side engagements.
2 perspectivesBuyer and seller experience — assessment before the transaction, integration after it.

Buy-side

What are we actually acquiring?

  • Cyber risk
  • Technology debt
  • Software and licensing exposure
  • Governance maturity
  • Architecture and data
  • Operational resilience
  • Supplier dependencies
  • Contracts and unsupported systems
  • Security weaknesses
  • Integration complexity
  • Organizational dependencies

Sell-side

What will the buyer discover?

  • Unresolved risks
  • Missing evidence
  • Unclear ownership
  • Weak controls
  • Technical debt
  • Compliance gaps
  • Undocumented dependencies
  • Unsupported systems
  • Cybersecurity findings

On the buy-side, the objective is to understand risk before it becomes acquisition risk. On the sell-side, the objective is to identify and resolve weaknesses before they become valuation arguments.

Post-merger integration

The deal does not end at closing.

Due diligence identifies issues. Integration determines whether the transaction delivers value. Technology integration is never only technology — it moves people, suppliers, licenses, contracts, data, controls, processes, teams, security and governance at the same time.

  1. DAY 0

    Understand

    Assess the environment, prioritize risk and agree the target state.

  2. DAY 1

    Secure & stabilize

    Contain immediate exposure and establish ownership from the first day.

  3. DAY 30

    Integrate

    Standardize, remediate and align operations across both organizations.

  4. DAY 100

    Measure & govern

    Report against the target state, close gaps and optimize execution.

  5. TARGET STATE

    Resilient operating model

    A structure that outlasts the transaction and the people who ran it.

What actually has to be integrated

  • People
  • Suppliers
  • Licenses
  • Contracts
  • Data
  • Controls
  • Processes
  • Teams
  • Security
  • Governance

International strategy

From local operations to international structures.

Crossing a border multiplies requirements rather than adding them. Security expectations, technology standards, regulation, privacy, supplier dependencies, governance expectations, enterprise customer requirements, data flows and operational responsibility all overlap — and they rarely agree with each other.

Christian de Coster, executive portrait
  • United States

    Scale & market readiness

    Enterprise security expectations, SOC 2, NIST, procurement requirements and sector-specific obligations.

  • Europe

    Governance & regulation

    ISO standards, NIS2, DORA, data protection, supplier governance and cross-border operations.

  • Asia-Pacific

    International operations

    Cross-border technology operations, suppliers, delivery models and regional complexity.

I have built and operated internationally myself. That is the perspective I bring: practical experience of running an organization across regions — not legal advice for every jurisdiction.

Scale of exposure

Experience across
3,000+ customer environments.

Throughout my entrepreneurial career, my teams and I have supported more than 3,000 customer environments across managed IT, MSSP services, cybersecurity, consulting and governance-related initiatives.

The value of that number is not the number itself. It is the exposure to thousands of different environments, technology stacks, operating models, priorities and levels of maturity.

Christian de Coster in conversation

Strategy needs execution

I do not work alone.

Behind the strategic work is an experienced and loyal international team covering cybersecurity, operations, governance, engineering, implementation, remediation and support — supported by Mahoney Control as the measurement and evidence layer.

Christian

Strategy & executive leadership

  • Strategy
  • Executive leadership
  • Risk
  • Governance
  • Target state
  • Stakeholder alignment

Team

Execution & operations

  • Implementation
  • Cybersecurity operations
  • Control execution
  • Evidence
  • Remediation
  • Follow-through

Mahoney Control

Measurement & automation

  • Measurement
  • Automation
  • Evidence
  • Framework mapping
  • Gap analysis
  • Continuous governance

Strategy → Execution → Evidence

I can define the target state. My team helps turn it into the operating state.

Background

Military Police

Staff functions S2 / S4

Experience in structured operational environments involving situational assessment, planning, logistics and resource coordination.

This background shaped an approach centered on structured information, traceability, evidence, accountability and decision preparation.

Further details are intentionally limited.

Mahoney Control

From methodology to software.

Mahoney Control is the Cyber Business Intelligence platform built out of this methodology. It exists because the same question kept repeating in every engagement: what is the distance between the state we agreed and the state we are actually in?

Target state

SOLL

SOLL — what was agreed, required or committed.

Operational state

IST

IST — what the environment is actually doing today.

The delta is the work

What the delta makes visible

  • Governance gaps
  • Missing evidence
  • Control weaknesses
  • Operational exceptions
  • Inconsistencies across sources
  • Remediation requirements

Areas covered

  • Operations
  • Security
  • Governance
  • Financials
  • Executive information

Capabilities

  • Framework mapping
  • Evidence management
  • Control management
  • Governance workflows
  • Operational integrations
  • Gap identification
  • Executive reporting
  • Recurring control monitoring
  • Audit readiness

On artificial intelligence

Built with AI.
Not through AI.

AI is genuinely useful for analysis, classification, correlation and automation. It shortens the distance between a signal and a decision.

It does not change what governance requires. A control still needs an owner, an execution record and evidence that a human can follow. Where AI contributes to a finding, the finding still has to be traceable and verifiable — otherwise it is an opinion with a confidence score.

Discuss an initiative

Understand the business problem before choosing the framework.

For U.S. technology, cybersecurity and governance engagements, services are delivered through Mahoney IT Group. The objective is not another policy binder — it is a resilient operating model that can be measured, evidenced and improved.