About

NoFuss Consulting is an independent consultancy specialising in risk and security governance. We help organisations identify gaps and build management systems that enable due diligence through transparency and clarity.

Risk is a foundational concept in rational decision-making. Communicated clearly, it becomes a shared language that lets leaders across domains compare priorities and allocate resources with confidence. We treat risk management as a decision-making tool, not an audit formality.

Information security goes beyond securing the network. Information is among the most valuable assets a contemporary organisation holds, and protecting it is a management concern as much as a technical one. Integrated with strategic decision-making, security governance aligns everyday practice with business objectives. It turns security into something the organisation does for its purpose, not despite it.

Profile picture

Your consultant

I’m Pece — founder and practitioner at NoFuss Consulting. I started my career about two decades ago as a software engineer, moved into information security halfway along, and eventually specialised in security and risk management systems. If you are interested in my story and how I ended up here, read my professional journey below.

Professional journey

An itch for a good challenge has defined most of my academic and professional life. From exploring neural networks and their application to speech recognition, to optimising algorithms for data transformation and database migration, my early days as an engineer provided a steady supply of exactly that.

A major milestone came around 2010. As an early adopter of iOS and Android and a senior engineer at Netcetera , a company where I would spend over eighteen years, I led the development of the PostFinance mobile app . It was among the first mobile banking apps with payment functionality, built on emerging technology with little to no established security practices to lean on. I still remember my 27-year-old rebellious self standing with serious-looking security engineers who had years of banking experience, trying to crack the architecture of the product we were about to build. Technical challenges aside, one theme kept recurring in those discussions: how do you convince the board to prioritise and fund security?

The success of that product led me to spearhead the development of several more banking apps, and eventually, Netcetera’s own mobile banking product. Launched in partnership with Finnova , it became the leading mobile banking solution in Switzerland, with around sixty banks running on it in just a couple of years.

I was still an engineer on paper, but by this point, information security filled most of my days. I took over Netcetera’s Security Office — an informal team of security-minded engineers helping the rest of the company — and in 2018 I initiated and built the company’s Information Security department, officially putting my software development days behind me.

Security became my profession. The early days were demanding: developing and managing the department by day, and doing technical work in the evenings, from security architectures to threat analysis and testing. Eventually, the team grew into a mature security organisation. Responsibilities could be handed over, and I moved into a more managerial role as deputy CISO, working on policies, strategies, and managing the overall security program.

This is when a pattern became hard to ignore. Whenever we traced a security problem to its root cause, the trail rarely ended at technology. It ended at fragmented processes, unclear ownership, and decisions made on gut feeling. By this time I was a member of multiple professional groups; most managers I talked to, both inside and outside the company, across different domains, kept repeating the theme I had first encountered in those PostFinance architecture meetings: how do you convince the board to invest in a change?

A new challenge — a new itch. I had been managing risks for years by this point, but a self-directed study in the foundations of business administration and the CRISC certification provided my first formal training on the topic. That was when I realised that risk is not a formality, but rather a common language that lets people from different disciplines (such as business management, engineering, finance, and HR) understand each other, prioritise, and allocate shared resources. Exploring decision theory and actuarial science convinced me of something more specific: quantifying risk is the clearest form that language can take, and the only one that can make dry concepts like risk appetite useful.

It was time to put my new belief to the test. A couple of years earlier I had already failed at consolidating several siloed risk assessment practices. We practised qualitative assessments which are notoriously difficult to consolidate without throwing away old results and retraining everyone involved — something we were not ready to do. As a result, the best that could be reported to management was a list of high-level risks that lived in the register for years as LOWs or MEDIUMs and which communicated our collective gut feeling on different aspects of security. This is what most organisations do at best.

I decided to give quantitative methods a chance. There is an overall stigma around them , so if I were to convince myself and my colleagues of their usefulness, they had to do more than consolidate the siloed processes — they had to improve our communication with management. Inspired by the work of well-known practitioners, I developed a methodology that let us quantify already-identified risks and aggregate them under a single umbrella. On the next reporting cycle, something new happened: management engaged with genuine interest and had questions on open issues.

And this is where I stand today. Two decades of experience, spanning from junior engineer to senior management. A professional life filled with challenges and know-how drawn from different disciplines. In a world where most organisations are stuck with the status quo, I’m on a journey to make a difference.

If that resonates, reach out — I would love to hear your story too

Kind words from my peers
CISO at G+D Netcetera

Pece brings a rare combination of deep security expertise, practical consulting experience, and the ability to explain complex topics in a clear and grounded way. What makes him stand out is that he not only helps others understand and navigate security challenges, but can also step in and do the work himself. It can be in ISO 27001, threat modelling, risk management, or the delivery of larger initiatives. I would strongly recommend him for senior consulting, security architecture, and transformation roles where both credibility and hands-on experience matter.

Head of security engineering & Assurance - Netcetera Software matters

I have worked with Pece for over nine years, and his expertise in software security and governance is both broad and practical. Coming from a shared background in software engineering, we approach security from a hands-on perspective, grounded in the reality of designing, developing, and operating secure systems. This gives Pece the rare ability to translate this practical experience into effective and actionable governance and risk practices. He consistently bridges the gap between technical depth and business priorities, making security both understandable for management and actionable for engineering teams.

PECB certificate badge
Issued by PECB
ISO/IEC 27001 Senior Lead Implementer
ISACA CISM badge
Issued by ISACA
Certified Information Security Manager® (CISM)
ISACA CRISC badge
Issued by ISACA
Certified in Risk and Information Systems Control™ (CRISC)
PECB certificate badge
Issued by PECB
ISO 31000 Senior Lead Risk Manager

Our network

Icon representing partnership

We work with a small network of trusted specialists who complement our services and can engage when the scope extends beyond what we cover. These include lawyers focusing on EU privacy and data protection law, as well as IT architects, penetration testers, and security engineers experienced in AI, cloud and application security.