Eitan Rafael
GRC · DPO · AI Automation & Governance
🇮🇱 עברית Book a call
For companies required to comply — by law, clients, or regulation

Compliance questionnaire? GDPR readiness? EU market entry? — Guidance from the field.

Whether it's a client security questionnaire, GDPR obligations, or expanding to European markets — I cover GRC, DPO and AI Governance end-to-end, without coordinating between three separate consultants.

⚡ Works with AI · Not just advises on it
Portrait of Eitan Rafael, senior project manager and Data Protection Officer
Since: 2000 | 2BSecure · National Health Organization
Focus: GDPR · Data Protection · ISO 27001/27032

GRC & Cyber Resilience

ISO 27001 · NIST CSF · BCP/DRP · Zero Trust

DPO & Privacy

Gap Analysis · GDPR · Privacy by Design

AI Governance & Automation

ISO 42001 · EU AI Act · n8n · AI Agents

How I work

I don't just advise on AI — I run it inside the engagement.

Gap mapping, privacy policies, audit reports and documentation — produced with automations on Make and n8n combined with Claude and ChatGPT. What takes weeks takes days.

Make n8n Claude AI ChatGPT WhatsApp Bots AI Agents
Verified field experience
7 years Led annual ISO 27001 & 27032 audit cycles at a national health services org — as Deputy CISO, from preparation through certification, 2015–2022
25+ Years of combined experience in cybersecurity, GRC and compliance — from hands-on technical work to project management
3 domains GRC, DPO & Privacy, AI Governance — end-to-end, without coordinating between three separate consultants
Who reaches out

Three situations that bring clients to me

It doesn't always start with a questionnaire. Sometimes it's a legal requirement, sometimes it's the market you want to enter.

Received a questionnaire or a request?

An enterprise client, bank or regulator is asking you to fill out a compliance questionnaire — ISO 27001, GDPR, EU AI Act. You need it answered professionally, accurately and defensibly.

The law requires it

GDPR doesn't differentiate by company size. Any organization processing EU personal data must comply — including Israeli SaaS providers, consulting firms and tech companies. Most don't know the full scope yet.

Ready to grow into Europe

You want to enter the European market, land an enterprise deal, or onboard a regulated client — and compliance is the door that needs to open first.

How I help

Three tracks — one point of contact

Not just consulting. I step in, build the framework, prepare the documentation — and deliver audit-ready. No need to coordinate three different consultants.

GRC & Cyber Resilience

Gap mapping, GRC framework, policies and audit preparation — ISO 27001, NIST CSF, NIS2. Including actual control implementation: Zero Trust, XDR, BCP/DRP.

DPO & Privacy

External DPO under GDPR, Gap Analysis, documentation and ongoing reporting to the data protection authority — from day one through the audit.

AI Governance

AI usage policy, EU AI Act & ISO 42001 compliance, AI risk management as critical infrastructure — Human in the Loop, Security by Design.

Initial discovery call — 20 min, no charge

Engagement types: one-time project  ·  monthly retainer  ·  external DPO

From the field

From a Ministry of Health audit to a real remediation plan

80% of audit findings closed within one month

A large healthcare organization received a comprehensive audit report with dozens of findings. The internal team knew there was a problem — they didn't know where to start.

We triaged findings into two tracks: Quick Wins for immediate closure, and a structured work plan for the rest. Within one month, 80% of findings were closed — MFA rollout across critical systems, removal of admin and privileged access org-wide, SaaS SIEM and log implementation. The remaining 20% — complex findings requiring procurement and approvals — were shaped into a structured work plan with clear timelines.

A similar approach was applied across several large clients — both in project management capacity and as an independent consultant.

National Health Organization · ISO 27001 & 27032

ISO findings — from audit results to an annual implementation plan

In every annual audit cycle, findings required both immediate action and longer-term remediation. Same model: Quick Wins closed up to 80% of findings rapidly — the remainder shaped into a structured plan covering procurement, version upgrades and system changes coordinated with vendors.

7 years of continuous engagement (2015–2022) as Deputy CISO — audits, findings, audit committee and management reporting.

What they say

Colleagues & clients

"

"You represented the company you worked for with professional dedication and great grace. I'm sure our paths will cross again many times."

Alberto (Deto) Hasson
VP CISO · ICL Group  ·  Former Head of National CERT
"

"You always gave 200% — a true professional."

Moshe Ben Simon
CPO · Axonius
"

"Always a professional — and above all, a mensch and a friend."

Tal Lazarov
CIO
How it works

Three steps — from first call to delivery

We don't start with paperwork. We start by understanding what you actually need — then we build the plan.

01

Initial discovery call

20 minutes, no charge. We map the requirement, the timeline and the gaps to close. You leave with a clear picture — whether we proceed or not.

02

Tailored work plan

A focused proposal with clear ownership, deliverables and timeline. Not generic — tailored to your organization's size, the specific regulation, and what you already have in place.

03

Hands-on delivery

I step into the process — building documents, training the team, representing you in audits. I deliver a project that meets the requirements — not just advice on paper.

Book your free initial discovery call
About

What's behind the engagement

I started on the ground — systems, networking and hands-on cyber at integration firms. At Comsec Global I ran risk assessments and penetration tests — that's how I entered GRC from the technical side. Then 16 years at 2BSecure: project management, account management, and leading annual ISO 27001 & 27032 cycles at Israel's National Health Organization as Deputy CISO.

360°Technical cyber + regulation + project management
ComsecRisk assessments & penetration tests — GRC entry from the technical field
25+years of experience in cyber & GRC
ISO · GDPRStandards and regulation implementation
16years at 2BSecure — managing security from the project and business side. Now bringing that depth to the regulatory world
7 yearsLeading ISO 27001+27032 at the National Health Organization as Deputy CISO

Most GRC consultants come from law or compliance. I came from technology — and spent 7 years leading ISO audits at the National Health Organization as Deputy CISO. I know both worlds from the inside: I can talk to the CISO, the legal team and IT at the same time.

For recruiters

Open to a senior role in cyber & privacy

DPO / Compliance · Project Management · CSM / Account Manager
Available immediately. 25+ years of experience — from technical operations to management and regulation.

Full profile → CV (PDF) LinkedIn
FAQ

Questions & answers by topic

Direct questions — direct answers. No marketing fluff.

DPO & Data Protection

What is an external DPO and why does an organization need one?

An external DPO (Data Protection Officer) is a professional who guides an organization through compliance with GDPR. GDPR Article 37 mandates DPO appointment for certain categories of processing. An external DPO offers flexibility and lower cost than a full-time hire, with immediate availability and broad expertise.

What does a GDPR gap analysis cover?

A GDPR gap analysis covers: mapping personal data processing activities, checking the legal basis for each processing operation, reviewing vendor agreements (DPA), assessing retention and deletion processes, and evaluating DPIA requirements. The process ends with a findings report and a clear remediation plan.

What is the difference between GDPR and Israeli privacy law?

GDPR applies to any organization processing data of EU citizens, regardless of the organization's location. Israeli Privacy Protection Law (Amendment 13) applies to organizations operating in Israel. Both require DPO appointment, the right to erasure and breach notification. Israeli organizations serving European clients are subject to both simultaneously — which requires professional guidance to avoid falling through the cracks.

Does a small vendor serving EU customers need to comply with GDPR?

Yes — company size does not exempt from compliance. GDPR applies to any organization processing personal data of EU citizens — including SaaS vendors, consulting firms and Israeli tech companies. Vendors receiving compliance questionnaires from European clients must present DPA agreements, a privacy policy, and documentation of the legal basis for their data processing.

What is a DPA (Data Processing Agreement) and when is it required?

A DPA is a data processing agreement between a customer (Controller) and a vendor processing data on their behalf (Processor). It is required whenever a vendor accesses personal data of the customer's clients — including cloud providers, CRM tools, support systems and more. Large enterprise clients require a signed DPA as a condition of engagement, and vendors without one risk losing deals.

How long does it take to reach basic GDPR compliance?

For a small-to-mid vendor receiving a compliance questionnaire from a client, basic compliance (privacy policy, records of processing, DPA, data subject rights responses) is achievable within 4–8 weeks. Full compliance including DPIA, business continuity planning and building a privacy culture typically takes 3–6 months on average.

GRC & Cyber Risk Management

What is GRC and why do vendors need it?

GRC (Governance, Risk & Compliance) is a framework for managing governance, risk and regulatory compliance. For small and mid-size vendors, GRC is mainly what your enterprise customer requires — risk management documentation, evidence of ISO 27001 or NIST CSF alignment, and structured security incident processes. A vendor without a GRC framework won't pass a strategic client's TPRM questionnaire.

What is the difference between ISO 27001 and NIST CSF?

ISO 27001 is an international standard for information security management (ISMS) that leads to a formal certification — mandatory in some contracts. NIST CSF (Cybersecurity Framework) is a risk-based American framework, less formal, suited to organizations that want to adopt a security culture without immediate certification. European clients tend to require ISO 27001; US and defense clients — NIST CSF.

What does a TPRM questionnaire from an enterprise client typically cover?

A TPRM (Third Party Risk Management) questionnaire typically covers: information security policy, access and privilege management, data encryption, security incident management and reporting, business continuity and DR, sub-vendor management, and in some cases — AI usage policy. Proper TPRM preparation can save weeks of stalled sales cycles.

What is NIS2 and who must comply?

NIS2 (Network and Information Security Directive 2) is an EU directive that entered into force in October 2024 and requires organizations in 18 critical sectors to meet stringent information security requirements. It also applies to service providers for EU organizations. Israeli vendors serving EU clients may be subject to NIS2 indirectly through vendor agreements.

What does hands-on cyber configuration for small businesses include?

Hands-on cyber configuration for small-to-mid businesses includes: firewall setup and policy management, Zero Trust for remote access, XDR for threat detection, MFA and Conditional Access configuration, and securing Microsoft 365 or Google Workspace environments. Unlike consulting — the work is done directly on your environment, not just in documents.

How much does ISO 27001 audit preparation cost?

ISO 27001 audit preparation for a small-to-mid business (50–200 employees) typically takes 6–12 months depending on current maturity level. Cost depends on existing gaps and the scope of guidance required. Certification audit by an accredited third party (such as BSI, SGS) is a separate cost. Vendors regularly receiving compliance questionnaires will find certification a sound business investment.

AI Governance & Automation

What is the EU AI Act and when does it apply to non-EU vendors?

The EU AI Act is Europe's first comprehensive AI regulation, in force since August 2024. Vendors outside the EU who supply AI systems to EU clients, or whose products affect EU citizens, are subject to it. From March 2026 — Prohibited AI bans apply. From August 2026 — GPAI (General Purpose AI) obligations. From August 2027 — High-Risk AI Systems requirements. A vendor that hasn't prepared risks losing EU clients.

Can using ChatGPT at work violate GDPR?

Yes. When an employee pastes clients' personal data into ChatGPT, OpenAI becomes a Processor of that data — which requires a DPA with OpenAI and explicit authorization from the client. ChatGPT Enterprise includes a built-in DPA; the free version does not. An organization that allows AI use without a clear policy is exposed to GDPR complaints and loss of client trust.

What is ISO 42001 and why does it matter?

ISO 42001 (2023) is the first AI Management System standard — the counterpart of ISO 27001 but for AI governance. It defines requirements for responsible use, transparency and minimum risk in AI system deployment. Organizations supplying AI to regulated clients (healthcare, finance, government) are starting to receive ISO 42001 questionnaires. Expect rapid adoption as the EU AI Act and ISO standards converge.

What does an organizational AI use policy include?

An AI Use Policy covers: approved AI tools list, rules for transferring data to AI tools (what is and isn't permitted), a process for approving new AI tools, DPA requirements from AI vendors, employee training, and audit and control processes. Enterprise clients are starting to require AI policies in their vendor questionnaires — this is the next wave after GDPR.

What is the difference between process automation and an AI Agent?

Process automation (RPA/Workflow Automation) executes predefined actions based on fixed rules — like transferring data between systems. An AI Agent can make decisions, plan actions and solve undefined problems autonomously. From a compliance perspective — an AI Agent requires a clear governance policy, DPIA and sometimes regulatory approval; simple automation requires considerably less.

How does a small vendor start implementing compliance-aware AI?

The recommended approach: first, map AI tools already in use in the organization (including unofficially adopted tools). Second — establish a clear AI Use Policy. Third — DPA with every AI vendor. Fourth — employee training. Only then expand AI usage. A vendor that approaches enterprise sales with a structured AI policy and signed DPAs with AI providers significantly reduces the risk of stalled sales processes.

Get started

Let's talk about your needs

LOCATION
Ra'anana area, Israel
Accessibility

Accessibility Statement

This site is built to conform with WCAG 2.1 Level AA. Adaptations include:

  • Full keyboard navigation, including a skip-to-content link and visible focus indicator on every element.
  • Hierarchical heading structure (H1–H4) and descriptive alt text for all images.
  • Dedicated accessibility menu (the round button in the corner) for text enlargement and high-contrast mode.
  • All areas of the site, including the contact form, are accessible at both mobile and desktop viewport sizes.

Accessibility contact: Eitan Rafael · [email protected] · +972-54-6636207

Last updated: August 2026. Found an accessibility issue? Please contact us directly — we'll fix it.