Team and credentials

    The person who scopes your engagement is the person who delivers it. We publish what our people can do and what they hold, rather than photographs and job titles.

    Why this page has no photographs

    Most consultancy team pages are a wall of faces, and they answer none of the questions a buyer actually has: who will do the work, what have they done before, and will they still be here in six months. We publish capability by location and credentials by discipline instead. If you want to know precisely who would run your engagement, ask — we will introduce them before you sign anything, which is a more useful answer than a photograph.

    What sits where

    Capability is organised around the two entities and the markets they serve. Engagements are staffed from wherever the right discipline sits, not from wherever the contract was signed.

    Amsterdam — in person and remote

    AI governance and AI architecture are led from Amsterdam, working in person and remotely, with business support alongside. This is where the European regulatory work sits: EU AI Act positions, ISO/IEC 42001 management systems, NIS2 and Cyberbeveiligingswet readiness, and the architecture decisions that follow from a data sovereignty constraint. Some of this team works remotely from outside the Netherlands, which we mention because it is true and because it is how we get the people we want.

    Casablanca

    Casablanca carries the largest share of delivery. Cloud and cybersecurity are directed from here, alongside AI transformation and governance, IT strategy and governance advisory, cloud architecture, data and AI consulting, and the SOC's first and second line. The African and Francophone engagements are led from here, and a substantial part of the European delivery capacity sits here too — including, at any time, a small number of interns and short-term contractors in cloud, cybersecurity and AI, who work under supervision and never carry client-facing analysis on their own.

    Portugal — associates, engaged on demand

    Seasoned associates in AI governance, cloud architecture and data science, brought in for specific engagements rather than carried on the bench. We are explicit that this is an associate arrangement rather than an office, because the difference matters when you are asking who will be available in month four.

    Certifications held in the team

    Personal credentials, earned and maintained by individuals — the only way certifications of this kind exist. We list what is held, not what we have read about.

    • ISO/IEC 42001 Senior Lead Implementer
    • ISO/IEC 27001 Lead Implementer and Lead Auditor
    • ISO/IEC 27005 Risk Manager
    • EBIOS Risk Manager
    • ISO/IEC 20000 Lead Implementer
    • Microsoft data and business intelligence certifications
    • PECB Certified Partner, with an accredited trainer in the team

    Frameworks we work in

    These are not certifications and we do not present them as any. They are bodies of practice our consultants work in daily, and the distinction between holding a credential and knowing a framework is one we would rather draw ourselves than have a client draw for us.

    • COBIT
    • TOGAF
    • ITIL
    • Zachman
    • NIST AI Risk Management Framework

    Our trainers consult. The person teaching ISO/IEC 27001 Lead Implementer this week is implementing a management system the next, which is the only reliable source of the examples that make a five-day course survivable.

    How an engagement is staffed

    Four rules, and we hold to them because they are the reason clients come back rather than a policy on a wall.

    1. 1.

      The person who scopes it delivers it. There is no handover from the senior who sold the work to a team you have not met. If that is going to be impossible for a particular engagement, we say so while you are still deciding.

    2. 2.

      Analysis is senior work. Assessments, audits, architecture and governance design are done by senior consultants. We do not have a pyramid to feed, which is the usual reason this work ends up with someone two years out of university.

    3. 3.

      The SOC is tiered on purpose. First-line analysts triage and escalate against a defined runbook; second-line investigates and responds. That tiering is how monitoring stays affordable, and it is honest work — the alternative is either an unaffordable service or a queue nobody reads.

    4. 4.

      Associates are named before they start. Where an engagement needs a specialist we do not carry, we bring one in and tell you who and why. Subcontracting without telling the client is common in this industry and we regard it as a breach.

    5. 5.

      Interns learn on supervised work, never on your analysis. We hire and train junior people in Casablanca, because that is how the discipline continues and because we would rather grow specialists than rent them. What they do not do is produce the assessment, the audit finding or the architecture you are paying a senior to produce.

    Experience

    More than fifteen years of practice across the team, in Europe and in Africa. Our founder has been working in enterprise technology and architecture for over twenty-five years. We deliberately do not publish headcount: the number changes, and it answers a question no client has ever actually needed answered. What matters is whether the discipline you need is present and who will be accountable for it, and both of those we will tell you by name before you commit.

    Questions buyers ask

    Who will actually do the work?

    The people you meet in scoping. We will introduce the named consultants before you sign, and if that is not possible for a particular engagement we will tell you why rather than let you discover it at kickoff.

    Can we see CVs?

    Yes, on request. We do not publish them, because a public CV is a recruitment target and our clients benefit from us keeping the people we have.

    What happens if the consultant on our engagement leaves?

    Documentation is a deliverable in every engagement, specifically so that the answer is not 'start again'. Continuity is the reason we hand over written method rather than personal knowledge — that discipline exists for your benefit, and occasionally for ours.

    Do you subcontract?

    Sometimes, for specialist work, and we always name who and why in advance. What we do not do is present another firm's consultant as ours.

    You are smaller than the firms we usually use. Why is that not a risk?

    It is a fair question and the honest answer has two halves. You get senior people on the actual work rather than a partner at the kickoff and juniors afterwards. In exchange, we are not the right supplier for a programme needing thirty consultants simultaneously, and when that is what you need we will say so rather than stretch.

    Is GSNA Solutions itself ISO 27001 certified?

    Not yet, and we will not imply otherwise. The company was founded in April 2024 and we have spent that time building the practice rather than our own management system — a trade-off we are explicit about rather than defensive about. We are implementing ours now, to the standard we implement for others, and we will say so here when the certification audit is booked. What we can evidence today is set out on the trust page.

    Leave with your top three risks documented

    Thirty minutes with a senior practitioner. No slideware, no sales engineer.