# WIRD S.A.S. — IT Strategy, AWS Cloud, Cybersecurity and AI Consulting > Independent IT consulting by Andrea Toso, based in Padua, Italy and working nationwide: AWS cloud, cybersecurity, IT governance, generative AI and IT due diligence for M&A transactions. A single senior point of contact, ISACA CISA certified auditor, over 25 years of experience. This is the structured-text version of , written for AI agents, LLMs and automated tools. The content matches the HTML page. - Original page: - Italian version: · markdown: - Last updated: 2026-08-14 - Language: English (the Italian version is the primary one) - Contact details: not listed in this file; they are available at --- ## Identity | | | |---|---| | Legal name | WIRD S.A.S. (Italian limited partnership) | | Principal | Andrea Toso — Founder, Innovation Advisor & AI Strategist | | Registered office | Via Germania 8, 35127 Padova (PD), Italy | | Operating area | All of Italy (on site and remote) | | VAT number | IT04176210286 | | LinkedIn | | | Experience | Over 25 years | Over 25 years in the field, alongside industrial groups and companies of every size through the challenges of digital transformation. Andrea Toso's job is to close the gap between technical innovation and what management is actually trying to achieve. The underlying principle is that innovation doesn't get improvised: every strategy is balanced by rigorous risk control and regulatory compliance. Technology should be invisible, effective and secure, so the business can stay focused on its core. The approach is *hands-on*: not just theory, but direct participation in defining and executing the strategy, including the management of resources and technology vendors. The best solutions don't come out of a lab — they come from listening closely to what the company actually needs. **Positioning.** Executive partner for CEOs, CIOs and CISOs at companies where an hour of downtime, a failed audit or a botched migration costs far more than the consulting does. No project starts without a business case that still holds up at twelve months. --- ## Services Six areas that overlap far more than companies expect: a security incident is almost always a governance problem too, and an AI project that ignores cloud spend never makes it to production. ### 1. Cloud Strategy & AWS Cloud migration, serverless architecture and infrastructure cost optimisation (FinOps) on AWS. ### 2. AI & LLM Consulting Generative AI integration, RAG systems over internal knowledge bases and intelligent process automation. Google AI Essentials certified (Data Analysis, Content Creation, Research, Planning, Gemini). ### 3. Cybersecurity Security audits following ISACA CISA methodology, PCI-DSS and ISO 27000 compliance, and data protection in enterprise environments. ### 4. IT Governance Project management (PMI/ITIL), vendor management and IT process re-engineering. ### 5. IT Due Diligence & M&A IT and security posture assessment of target companies, for investment funds and acquirers: as-is analysis, gap to the required to-be, and CapEx/OpEx estimates backed by verifiable data. ### 6. Fractional CTO / CISO Executive leadership on demand. Strategic direction to align technology with business objectives, without carrying the fixed overhead. --- ## Certifications ### Active | Certification | Body | Notes | |---|---|---| | Certified Information Systems Auditor (CISA) | ISACA | Verifiable at | | ITIL 2011 Foundation | APMG International | Earned Mar 2013 | | Project Management Foundations | PMI | Earned Apr 2020 | ### Certification track record (earned, not renewed) | Certification | Body | Valid | |---|---|---| | AWS Certified Solution Architect – Associate | Amazon Web Services | 2013–2016 | | PCI Professional (PCIP) | PCI Security Standards Council | 2015–2018 | | ICT Security Specialist UNI 11506:2013 | Kiwa | 2015–2018 | These three were earned and not renewed: the skills are still operational, the formal credential isn't. The distinction is stated explicitly rather than left out. ### Declared competencies Cloud Architecture · Amazon Web Services (AWS) · Cybersecurity · ISACA CISA · IT Governance · ITIL · Project Management · IT Due Diligence · Mergers & Acquisitions · Generative AI · PCI-DSS · NIS2 Directive · ISO 27001 · Google Gemini --- ## Case studies Clients are anonymised under contractual confidentiality (NDA): company profiles are described generically. Each case also states the obstacle encountered, not just the outcome. ### Smart Tips & Decision Intelligence — AI / Analytics **Client:** multi-brand e-commerce group, 4 owned stores + marketplaces, ~120 employees · **Duration:** 6 months - **The work:** algorithms analysing company data flows in real time, generating proactive "Smart Tips" for management with corrective actions surfaced while they still matter. - **The obstacle:** for the first two months the system threw too many false signals. Sales data arrived from different platforms, with misaligned product taxonomies and orders duplicated between owned stores and marketplaces. The collection pipelines had to be normalised before management started trusting the recommendations. - **Outcome:** once normalised, data-driven decisions in seconds instead of days, with stable adoption across the first two stores by month four. ### Predictive Maintenance & App Generation — Gen AI / Automation **Client:** mid-sized manufacturer, mechanical components, ~150 employees · **Duration:** 4 months - **The work:** machine learning to predict failures on industrial plant, plus LLMs to auto-generate boilerplate code, speeding up in-house application development. - **The obstacle:** the first predictive model, trained on only a few months of historical data, raised too many alerts on noisy sensors. Thresholds were retuned with the experienced maintenance crew in the loop before go-live. On the code-gen side, mandatory human review came in after the first auto-generated bugs. - **Outcome:** −30% unplanned downtime on the monitored lines and +50% development speed on internal applications, measured over the six months after release. ### ISO 27001 Compliance — Governance / ISO **Client:** B2B software house, ~60 employees · **Duration:** 8 months - **The work:** end-to-end consulting through ISO 27001 certification. ISMS scope definition, security policy drafting, risk management and support through the certification body's audit. - **The obstacle:** the certification body's audit surfaced a minor nonconformity in privileged access management. The gap was closed in three weeks so the certification wouldn't slip. - **Outcome:** certified on the first audit cycle, nonconformity closed on time, and security integrated into day-to-day operations. ### NIS2 Directive Compliance — Security / NIS2 **Client:** multinational S.p.A., professional foodservice equipment (HORECA), ~300 employees · **Duration:** 7 months - **The work:** gap analysis and remediation plan for "essential" and "important" entities. Implementation of the technical and organisational measures the EU cyber-resilience requirements demand. - **The obstacle:** the gap analysis turned up more shadow IT than expected, and legacy OT systems never designed for the segmentation required. The remediation plan had to be renegotiated with the industrial plant vendors, adding roughly two months to the original estimate. - **Outcome:** full compliance ahead of the regulatory deadline, with a business continuity plan tested and documented for the board. ### Hybrid & Scalable Cloud — AWS / Hybrid **Client:** highly seasonal e-commerce, ~80 employees · **Duration:** 5 months - **The work:** hybrid architectures connecting on-premise datacenters to AWS, using managed services to guarantee automatic scaling through peak load. - **The obstacle:** during the first production failover test, auto-scaling didn't react fast enough to a simulated spike and checkout slowed briefly. Scaling policies and alert thresholds were revised before final go-live. - **Outcome:** the following Black Friday ran with zero downtime, and infrastructure costs stayed under control thanks to the FinOps monitoring introduced mid-flight. ### IT Due Diligence for an Acquisition — M&A / Due Diligence **Client:** private equity fund, target company assessment · **Duration:** 6 weeks - **The work:** IT and security posture assessment of the target company on the acquiring fund's mandate, across six domains — Governance & Risk Management, Infrastructure & Network, Identity & Access Management, Business Continuity & Disaster Recovery, Applications & ERP, and AI Governance & Shadow AI. Valuation of the existing IT assets and CapEx/OpEx estimates for the investment needed to close the gap between the as-is found and the to-be the fund required. Reporting produced with AI support. - **The obstacle:** in due diligence you get no direct access to production systems — the picture has to be reconstructed from documentation, interviews and indirect checks, in a matter of weeks. The AI Governance domain took unplanned extra work, because AI tools the target's IT function had never inventoried turned out to be in daily use. - **Outcome:** CapEx/OpEx figures backed by verifiable data and an as-is → to-be path documented domain by domain — a financial picture that holds up at the negotiating table. --- ## Engagement criteria Useful for judging fit before making contact. ### This works if - An hour of downtime, a failed audit or a data breach costs more than the consulting does. - You want someone who stands behind what they **advise against**, not just what they sell. - You need senior capability across several fronts — security, cloud, governance, AI — without building an in-house department. - You'd rather talk to the person doing the work than to an account manager. ### Probably the wrong supplier if - The deciding factor is the lowest quote for the same number of days. - You need execution against specs someone else has already locked down, with no room for technical judgement. - The goal is a certificate to hang on the wall, with no intention of changing the processes. - You're looking for a supplier who always says yes. --- ## Frequently asked questions **Does AI deliver measurable ROI right away, or is it just hype?** Generative AI isn't there to play with, it's there to cut waste. Solutions (RAG assistants, predictive analytics) get implemented only when the business case shows a return within 6–12 months. No experiments, just operational efficiency. **If we get hit by ransomware, is the company legally covered?** Criminal and civil liability usually lands on the board. Aligning to the NIS2 directive and running ISO 27001 audits doesn't just lock down the data: it shields management from legal exposure and keeps the business running even under attack. **Is AWS cloud spend predictable, or are surprises on the invoice a risk?** Pay-as-you-go cloud gets away from you without governance. Strict FinOps practice applies: real-time monitoring and intelligent auto-scaling. You pay for the resources that generate value, and the infrastructure waste goes away. **Can IT be modernised without stopping production?** An hour of downtime costs thousands. The migration strategy used (hybrid cloud) is designed to run in parallel: the technology stack gets modernised while the company keeps invoicing, with no operational interruption. **Why an external partner instead of hiring an in-house IT manager?** Hiring a CISO, a cloud architect and an AI specialist would run north of €200k a year in fixed salary alone. With WIRD you talk to Andrea Toso directly — ISACA CISA certified auditor, with hands-on experience across AWS, governance and AI — a single point of contact covering all of it, with a network of specialists brought in when a project needs extra capacity, and you pay only for the time actually required. **How is confidentiality handled around data and sensitive business information?** An NDA is signed before any data is shared or any system access is granted, and the same least-privilege principle recommended to clients applies here too: access only to what the project requires, for as long as the project requires it. Nothing relating to a client is shared with third parties — not even anonymised — without explicit authorisation. **If we use generative AI, does our company data end up in someone else's model?** No. For every AI project, what data can leave the company perimeter is assessed first, and under what contractual guarantees (training opt-out, EU-region hosting). Where confidentiality is critical the direction is towards self-hosted models or enterprise APIs with explicit no-training clauses: the same care applied to security and governance applies to AI. **How does the engagement work — fixed contract, project-based or pay-as-you-go?** It depends on the objective. An audit or a certification (ISO 27001, say) is typically project-based, with defined milestones and deliverables; a fractional CTO/CISO role is a retainer with an agreed, reviewable number of days per month. Either way you deal directly with the person doing the work, not an account manager — and it's the first conversation that settles which model fits. --- ## Contact Phone and email are **deliberately not listed in this file**: they are published at , where they are revealed on explicit request. - Website: - Office: Via Germania 8, 35127 Padova (PD), Italy - LinkedIn: Working language: Italian and English. The Italian version of this site is at . --- ## About this site The site is a static two-language page, with no profiling cookies, no user tracking and no third-party requests. This markdown file is its machine-readable representation. *Content © 2026 WIRD S.A.S.*