I work at the intersection of:
- Information Security
- Governance, Risk & Compliance
- Organisational design
- Automation & GenAI
- Culture change at scale
C-level security & GRC leader
C-level security & GRC leader building systems that reduce real risk — not just audit anxiety.
I design threat-driven security programs, scale governance in complex organisations, and turn compliance into engineering. Currently building daVera and helping shape the future of GRC and Governance Engineering.
Calm by nature. Opinionated by experience. Always hands-on.
About
I work at the intersection of:
My focus is simple:
Build security programs that actually reduce risk.
Not slide decks. Not checkbox factories.
Real controls. Real data. Real ownership.
I believe GRC is an engineering problem — and should be treated like one.
Current work
AI-powered Governance Engineering platform
daVera is my current venture: a new kind of GRC platform that treats governance as infrastructure.
It’s built around three principles:
The goal is to give organisations a way to build security programs instead of performing them.
Community-driven GRC events
CtrlCon is a global, practitioner-led event series for people who are done with compliance theatre.
It’s where security engineers, GRC practitioners, and builders meet to talk about:
No vendor theatre. No buzzword bingo. Just real conversations.
Experience
2022–2025
Built during a period of extreme organisational change and downsizing.
2024–2025
2021–2022
2018–2021
Earlier roles at IAEA, Accenture, and Maastricht University shaped my engineering mindset.
How I Think
A few principles that guide my work:
I optimise for risk reduction, not audit performance.
Education & Credentials
Fluent in Dutch, English, and German.
Professional working knowledge of French and Italian.
Contact
Email: niek@nigg.nl
LinkedIn: linkedin.com/in/nieknigg
I’m always happy to talk.