Skip to content
František Kopl

External Cybersecurity Architect

František Kopl

Ing. František Kopl, CISSP - cybersecurity architect with 20+ years of experience in IT and security.

About me

I am an experienced IT manager and Enterprise Solution Security Architect. For more than two decades I have helped large organizations design, build, and operate secure IT environments - from strategy through architecture to hands-on implementation.

I have worked both on the customer side (ČEZ ICT Services, W.A.G. payment solutions, Adecco Group) and the vendor side (Microsoft Consulting Services, Anect, Trustsoft, KPCS). This dual perspective lets me understand both the business needs of regulated companies and the realities of the supplier ecosystem.

Since 2022 I have been working as an independent consultant and external architect. I specialize in companies that need to meet the requirements of the new Czech Cybersecurity Act and NIS2 - and want to invest meaningfully, not just for the sake of looking compliant.

How I work

Plain language for management

The board needs decision input, not paragraphs. I talk about risk, cost, time, and impact - not acronyms.

Technically sound for IT

Architecture recommendations are implementable, tested in practice, and respect operational reality.

Pragmatic, step by step

No big bangs. We start where the risk is highest or the deadline is closest, and gradually build maturity.

Independent and transparent

I have no interest in selling you a specific vendor or product. I recommend what makes sense for your situation.

Certifications

  • CISSP - Certified Information Systems Security Professional (#338528, since 2009)
  • AWS Solutions Architect - Associate
  • Microsoft Certified: Azure Solutions Architect Expert (AZ-305)
  • MCSE: Cloud Platform and Infrastructure
  • MCSA: Windows Server 2016
  • Microsoft Certified: Fabric Analytics Engineer (DP-600), Fabric Data Engineer (DP-700)
  • ITIL Foundation V3

Areas of expertise

  • Enterprise security architecture
  • NIS2 / Czech Cybersecurity Act compliance
  • Cloud security (AWS, Azure, hybrid)
  • Identity & Access Management
  • Risk assessment & management
  • IT/OT convergence
  • Audit and governance (ISO 27001, NIST, CIS)
  • TOGAF / enterprise architecture

Selected projects

IoT architecture for 50,000 industrial devices

2025

External Lead Architect. Migration of a 10+ year old IoT solution (Europe, APAC). Assessment of existing state, business and security requirements, target design (Azure, Kubernetes, microservices, multitenant). Delivery plan for 19 people. Update of cloud operations standards (Azure landing zones). CxO communication.

NIS2 exit strategy for Microsoft 365

2025

Assessment of M365 usage in an oil/gas company under NIS2. Three exit scenarios, migration plan, governance and schedule, risk and mitigation analysis, test scenarios, exit initiation criteria. Data inventory and export scripts.

Security governance & risk assessment

2025

Global agency searching for CxO roles for Fortune 500 companies. Security assessment of HQ and 80 branches, 600 employees. Security policies, risk analysis, GDPR, NIS2, ISO 27001/2.

Incident response plans (IT + OT, NIS2)

2024–2025

Global chemicals manufacturer. Expansion of existing guidelines and standards for IRP and DR procedures (roles, functions, communication plans, DR steps, infrastructure priorities).

Banking apps migration to AWS - Raiffeisen CZ

2024

Preparation of selected applications for migration to AWS. Business requirements (RTO, RPO), target architecture, TCO. Security baselines for main building blocks (EC2, S3, ECS, RDS). Remediation of security findings.

Banking apps migration to AWS - Tatra Banka SK

2023–2024

Migration of 14 Tatra Banka applications to AWS. Initial analysis, target design, cost calculations, approval management (security, operations), infrastructure modeling, stakeholder communication, delivery support.

PKI in the post-quantum era

2025

Review of hardening options for Microsoft PKI to support post-quantum cryptography in fintech. Research, proposal of next steps.

International web platforms - Adecco Group

2018–2024

Design and delivery of integrated web solutions (CRM, integrations, websites) for 57 countries, 3 regions, 4 brands, ~10M visits per month. Sitecore WCMS, high availability, integrations to CRM and tracking platforms.

home.finalCta.title

Free 30-minute consultation. We assess your current state and propose concrete steps to reach your target state.

Free consultation