Professional Profile · Ticino / Svizzera

Marco
Rovatti

CISO & Data Protection Officer  ·  Cybersecurity · Privacy · AI Governance

ISO 27001 / NIST GDPR · LPD Svizzera · nLPD AI & Agenti Intelligenti DPO · Risk Management
Profilo professionale

CISO e Data Protection Officer con oltre 15 anni di esperienza nella sicurezza delle informazioni, governance IT e protezione dei dati personali. Attualmente in carica presso Cassa Disoccupazione OCST (Lugano, Ticino), dove guida la strategia di cybersecurity e la conformità normativa ai sensi della LPD svizzera, del GDPR europeo e delle direttive del Garante italiano. Esperto di gestione del rischio secondo i framework ISO 27001/27005 e NIST, sviluppatore di agenti AI applicati alla compliance e alla formazione organizzativa. Pubblicista su tematiche di intelligenza artificiale, privacy e sicurezza informatica per TopTrade, Data Management e altre testate specializzate.

International Profile
English · Professional Summary

Chief Information Security Officer
& Data Protection Officer

Senior cybersecurity executive and certified Data Protection Officer with over 15 years of hands-on experience in information security governance, regulatory compliance, and IT risk management. Currently serving as CISO & DPO at Cassa Disoccupazione OCST (Lugano, Switzerland), where he leads the organisation's security strategy, incident response framework, and data protection programme under Swiss and EU law.

Holds advanced credentials from Harvard University, 24 ORE Business School, EC-Council, and the U.S. Department of Homeland Security. Deep expertise spans ISO 27001/27005, NIST Cybersecurity Framework, GDPR, Swiss nFADP (nLPD), and the Italian Garante della Privacy. Recognised author and commentator on AI governance, privacy law, and digital transformation for Italian and Swiss specialised media.

Currently developing AI-powered compliance tools and intelligent agents for SMEs operating in Switzerland and Italy, with a focus on automated GDPR/nFADP documentation, risk matrix generation, and organisational data mapping.

Location
Lugano, Ticino · Switzerland
Languages
Italian (native) · English · French
Frameworks
ISO 27001 · ISO 27005 · NIST CSF · CIS Controls
Regulations
GDPR · Swiss nFADP · Garante della Privacy
Specialisations
DPO · Threat Modelling · Network Security · AI Agents · Web Application Security
Publications
TopTrade · Data Management · Swiss specialised media
Aree di competenza
Cybersecurity
CISO, offensive/defensive, network security
Data Protection Officer
GDPR, LPD CH, nLPD, Garante italiano
Risk Management
ISO 27001/27005, NIST, analisi del rischio
AI & Agenti Intelligenti
AI governance, AI agents, automazione
Governance IT
Compliance, audit, policy e procedure
Digital Transformation
Infrastrutture IT, PWA, CRM, automazione
Formazione & Comunicazione
Training, pubblicistica, radio, coaching
Web & AI Development
SPA, HTML/CSS/JS, API, agenti Claude
Certificazioni e formazione
★ Master Certificate 2023
Data Protection Officer (DPO) e Privacy
Part-time Master — 24 ORE Business School · Sistema qualità UNI EN ISO 9001:2015
Harvard / HarvardX 2022
Cybersecurity: Managing Risk in the Information Age
Harvard University — Office of the Vice Provost for Advances in Learning
FedVTE · U.S. DHS 2022
Cyber Essentials
Federal Virtual Training Environment — U.S. Department of Homeland Security
EC-Council 2022
Information Security Risk Management
CodeRed from EC-Council — Jay Bavisi, President
EC-Council 2022
Mastering Network Security
CodeRed from EC-Council — Jay Bavisi, President
EC-Council 2022
Hands-on Network Security
CodeRed from EC-Council — Jay Bavisi, President
EC-Council 2022
Hacking Web Applications
via PDFs, Images & Links — CodeRed from EC-Council
Google · IAB Europe 2020
Fondamenti di Marketing Digitale
Google Digital Training — IAB Europe & The Open University endorsed