Skip to content
Peter Annink LinkedIn

Interim Security Leadership · IT Risk & Governance

Someone gave you my name.

A colleague perhaps, an auditor, a board member. The reason varies: a new regulation on the way, a cyber security incident that should not repeat, audit findings that keep staying open, an assurance report or ISO 27001 certification a customer requires, or a cyber security programme that has simply stalled. The work underneath is the same: making security work at every level of the organisation, so nothing falls through the gaps. Consider this page the longer version of that conversation.

Peter Annink, portrait in a blue double-breasted jacket
Peter Annink, interim security leader

Who this is for

Written for those who carry the responsibility.

CFO · CRO · Board

You own the risk.

Regulation now places accountability with management personally; NIS2 and DORA are explicit about it. Meanwhile the findings recur, the dashboards multiply, and the board report still struggles with the one question that matters: are we safer than last quarter? Another tool will not change that. What changes it is the machinery around the tools: ownership, decisions, follow-through, and reporting honest enough to put your signature under.

CTO · CIO

You own the technology.

Your estate is wider than software: cloud and on-premise infrastructure, ITIL operations, identity, data, and now AI arriving faster than any review cycle. Security that speaks only one of those languages becomes friction. I have governed the whole span, from infrastructure and change management to application security alongside 1,500 developers at Nike. Risk and friction concentrate at the seams between domains, where no specialist has the full picture; a security lead who understands both sides of every seam is what keeps delivery moving.

Where security programmes actually break:

Controls are people, process and technology, not products on a shelf. Tools produce findings; risk only falls when controls are owned, implemented, validated continuously by a second line, and reported honestly. AI has made the paperwork side genuinely easier; a framework or a policy can be drafted in an afternoon now, and that is fine by me. The difference is made in implementation, with people and the way they actually work together. That part is human, and that is where I earn my place, often closer to coaching than consulting. No paperwork for its own sake and no meetings about meetings: the scarce resource is rarely budget but the attention of a few key people, and it should go to what genuinely makes the organisation safer. Compliance follows as a consequence.

What I do

Three ways I step in, usually where things are stuck.

The trigger differs. Sometimes a regulation is approaching, sometimes there has just been an incident, sometimes the audit findings keep returning, and sometimes a customer will not sign without ISO 27001 or an ISAE report. The work underneath is remarkably similar.

Interim security leadership

A CISO-shaped gap is a risk with a clock on it. I step in quickly, take ownership of the agenda, give the board reporting it can trust, and build a routine that outlasts me. Defined start, defined exit; success is that you no longer need me.

Governance that actually governs

Fifteen-plus years across all three lines of defence. I make the machinery work: who owns, who decides, who escalates, so the tools you have already bought start paying for themselves.

Certification without theatre

ISO 27001 and NEN 7510 shaped to how you actually run: a management system that passes the audit because it is true. The regulatory floor follows: GDPR, NIS2, DORA, the rules of your sector, and the Cyber Resilience Act prepared well before its 2027 deadline.

Excellence is a system, not a mystery.

Every organisation is a machine producing outcomes. When the outcomes disappoint, look at the design before blaming the people: how work is owned, decided and followed up. Designs can be changed, and so can habits; what resists longest are the beliefs. That there is never time. That the right people cannot be found. That the findings will always come back. That this company, this industry, is too unique for any of it to apply. It rarely is. Clear ownership, honest measurement, disciplined follow-through, repeated until they become culture: that is the whole recipe. What it asks of leadership is the willingness to take responsibility for it. What it returns, beyond a stronger organisation, is the quiet satisfaction of work done properly.

The record

What this looks like in practice.

Three lines of defence, dozens of sectors. What follows is a selection from the record.

HumanTotalCare, a security function built to outlast me

Healthcare · Interim CISO
Situation
The largest occupational-health provider in the Netherlands needed a security function stood up, certified, and made ready for NIS2.
Approach
Built a new information security team, modernised the ISMS to ISO 27001:2022 while maintaining NEN 7510 and aligning ISO 27701 for GDPR, and led a security transformation prioritising vulnerability management, immutable backup and SOC/SIEM.
Outcome
A certified, staffed, self-sustaining security function, ready for NIS2 before the rules took effect.

Nike, security leadership at global scale

Retail · Director
Situation
Four years of security leadership at Nike: first as Information Security Governance Lead for EMEA and APLA, then as Director of Application Security for EMEA.
Approach
Built the reporting spine of thirty key risk indicators that gave leadership genuinely actionable insight, drove a strict remediation rhythm with a named owner behind every risk, and as Director grew a new application security team from one to seven, raising secure-by-design maturity from level one to three with 1,500 engineers.
Outcome
Ten-plus critical and major risks retired per month, the most effective remediation record within Nike globally at the time, and a cyber resilience strategy for the global logistics supply chain covering OT, IoT and third parties.

Amsterdam Trade Bank, findings that stayed closed

Banking · Remediation
Situation
A bank under a formal IT remediation programme, with audit issues stacking up faster than they were being resolved.
Approach
Implemented a new IT control framework on COBIT 5 and ISO 27001, and built the governance to carry it: security policy, change management, incident management, third-party risk, plus SIEM monitoring run by an external SOC.
Outcome
Six audit issues resolved per month, closed structurally rather than cosmetically, so they stayed closed.

Fifteen-plus years across

Nike HSBC Rabobank NIBC Bank Amsterdam Trade Bank CGI HumanTotalCare

How I work

Four principles, applied without exception.

Accountability is the first control.

Frameworks do not secure organisations; owners do. Every risk, every control and every escalation traces to a name, offered as clarity rather than blame, with coaching for the people who hold them. Where ownership is missing, leadership hears about it, framed as the opportunity it is.

Clarity is kindness.

Vagueness feels polite and helps nobody. Naming the risk, the owner and the date is a form of respect, for the organisation and for the person doing the work. Security does not ask for politeness; it asks for clarity.

Progress over perfection.

A hundred controls at eighty percent protect more than one polished to a standstill. Momentum carries a security programme further than mandates do, and a good story is how momentum starts.

Whatever works.

Every organisation already has energy moving somewhere. I would rather steer existing momentum than fight it: pragmatic about method, unattached to whose idea wins, loyal only to the outcome.

Credentials

The paperwork, for the record.

  • CISSP ISC2 · Certified Information Systems Security Professional 2021
  • CISA ISACA · Certified Information Systems Auditor 2018
  • CRISC ISACA · Certified in Risk and Information Systems Control 2020
  • CEH EC-Council · Certified Ethical Hacker 2023
  • ISO 27001 LI PECB · ISO/IEC 27001 Lead Implementer 2023
  • NIS2 Security Academy · NIS2 Certified 2025

Also in the drawer: PRINCE2, ITIL, SAFe, M_o_R, Agile Scrum and OCEB 2, on a foundation of International Business (Management of Organisations) at Maastricht University. Security is an organisational discipline; I studied it as one before I practised it as one.

Peter Annink, seated portrait in a dark green turtleneck

About

Direct in speech, gentle in method.

Personality assessments place me near the top of the scale for orderliness and industriousness, and near the bottom for politeness. In practice: disorder genuinely bothers me, I work like a machine, and I will tell you what I see, kindly, without the consultant's fog. Boards tend to find that combination useful. It suits the discipline too: security rewards clarity more than politeness.

The range is deliberate: from the board's risk appetite down to CIS hardening baselines and Conditional Access policies in Entra ID, from challenging a pentest report to weighing a compensating control. I hold an ethical hacking certification for a reason; I prefer to look at a control the way an attacker would, before an auditor does. Complex problems tend to sit between the specialisms, and between the specialisms is where I work best. The method, though, is gentle: I have never unstuck an organisation by standing in front of it, always by finding where the energy moves and steering it.

I grew up in the Dutch countryside, which is where the work ethic comes from, and later spent five years in Singapore and two in Manila, which is where the feel for people and cultures comes from. Based in the Netherlands today, with European and Asian time zones equally workable: remote where that is efficient, on location where it matters, meeting the teams, the sessions that count, whatever the job needs. English and Dutch, interchangeably. Referrals are how I work; whoever pointed you here can tell you whether the style fits.

Next step

The next step is a conversation.

LinkedIn is the fastest way to reach me; I read everything myself. Do mention who sent you: it's a small world and I like knowing the route.

Message me on LinkedIn