Lucio Patone

Expertise

Regulation built into the software

Obligations and traceability built into the digital processes, not into a folder of procedures nobody opens.

Compliance is almost always handled as a separate project: the deadline arrives, a consultancy is bought, a binder of policies is produced, the audit is passed. Six months later the binder no longer describes what the company actually does, and at the next inspection it starts over. It is expensive and it protects nobody, because a measure that lives on a document is not a measure: it is a statement of intent.

The alternative is to put it inside the systems. If the access log produces itself, there is nothing to reconstruct afterwards. If the traceability of a movement is a side effect of how the movement gets recorded, nobody has to chase it. Regulation stops being an obligation and becomes a property of the software.

What I handle

  • NIS2. Working out whether and how it applies to you, translating the requirements into concrete technical and organisational measures, and building them into the systems: access management, logging and retention, continuity, supply chain, an incident notification procedure somebody can actually execute at three in the morning.
  • Sector regulation. Regulated documentation, traceability of movements, deadlines and renewals: the case I know best is environmental services, where every movement produces a document that has to be able to resurface years later.
  • Traceability and archiving. Documents indexed and retrievable in seconds, by record, by party, by date. The difference between an inspection that lasts an hour and one that lasts a week.
  • Vendor governance. Knowing who touches your data, with what rights, and what happens the day one of them stops.
the criterion · if a measure needs someone to remember to apply it, sooner or later it will not be applied: it belongs inside the system that runs the process

What I do not do

I am not a lawyer and I do not sign legal opinions: on the regulatory perimeter I work alongside your consultant or your counsel. What I bring is the other half, the one usually missing: translating the requirement into software that works, and doing it in a way that holds when the company changes.

Related reading: NIS2 without panic · A hundred and ten documents a day, untouched

How it starts

With a short and honest survey: what applies to you, what you already do without knowing you do it, what is genuinely missing. Out of it comes a short list of interventions ordered by risk, not by how easy they are to present. Then you build, one piece at a time, inside the processes you already have.

An incoming regulatory deadline is a good moment to fix processes that needed fixing anyway.

Get in touch