ISO/IEC 27001:2022 Lead Auditor (TÜV).
Certified qualification to conduct ISMS audits under the current ISO/IEC 27001:2022 standard.
Certificates are only worth as much as the practice behind them. Here's the professional background of Josef Floesser, founder of JF Agency — a reference point before you decide on an ISO 27001 or TISAX® consultant.
Certification is a trust business — verifiability matters more than marketing claims.
A consultant should disclose their own qualifications as transparently as they expect from your ISMS.
There's often a gap between audit paperwork and real system administration — practical Head of IT experience closes it.
Many consultants are platform-agnostic generalists — specific expertise in Apple MDM environments is rare and relevant for Mac-first companies.
Experience with international teams and locations helps with globally operating clients, such as in the automotive industry.
The facts, verified from the current CV — no embellishment.
Certified qualification to conduct ISMS audits under the current ISO/IEC 27001:2022 standard.
Certified qualification to advise companies preparing for TISAX® assessments.
Independent consulting practice in information security and Apple Enterprise Architecture.
Hands-on IT leadership for an architecture firm (since 2024) and a film production company (since 2021) — both documented as references on this site.
Studied Information Technology and Media Studies at the University of Offenburg, complemented by exchange semesters at the University of Liechtenstein and Universidade Europeia in Lisbon (PROMOS scholarship). Afterwards Scientific Assistant (2019–2022) and Research Fellow at the Affective & Cognitive Institute (2022–2024).
Yes — the ISO/IEC 27001:2022 Lead Auditor certification (TÜV) is complete. He additionally holds certification as an Information Security Consultant for TISAX® with the TÜV Rheinland Group.
The combination of formal auditor certification and hands-on Head of IT experience at real companies (UNDPLUS, Rekorder) — not just advisory work but actual implementation practice, plus specialization in Apple enterprise environments.
Yes, ISO 27001 and TISAX® consulting is fundamentally platform-agnostic. The Apple enterprise focus is an additional specialization, not a requirement for other environments.