Kofi Osae-AttahSecurity · Privacy · A point of view
Hello — I’m Kofi

Kofi.Osae-Attah.

I build security programs people can actually understand and use.

I was born in New York, grew up in the States, and my parents are from Ghana. I now work in information security and privacy in Germany. I like the part of the job where a complicated requirement meets a very ordinary question: “So what do we do?”

Hand-drawn portrait of Kofi, wearing round glasses and a dark sweater
New York · Ohio · GermanyCurious by default · Clear by design
01 / About me

I tend to ask one more question.

Where did that number come from? Who will own this control next month? What changes if the first account of an incident turns out to be incomplete?

Those questions are how I work. I’m interested in the point where security stops being a document and starts shaping a real decision.

At Link11, I’ve helped extend a program centered on ISO 27001 into work across SOC 2, PCI DSS, BSI C5, and NIS2. That also means privacy questions, customer assurance, incidents, and translating between people who see the same problem from different sides.

I care about how the answer is communicated. A good control can still fail if nobody understands why it exists or what to do when it breaks.

02 / Work in practice

Here’s what that looks like.

01

One program, five lenses.

I work across ISO 27001, SOC 2 Type II, PCI DSS, BSI C5, and NIS2. The interesting work is finding the common control underneath different requirements, then making ownership and evidence repeatable.

02

Risk with the assumptions showing.

I’ve built a risk methodology and register to make judgments easier to explain and challenge. A score should start a useful conversation about exposure and action, not end one.

03

Tools that save attention.

I build practical tooling too: Python checks for exposed secrets and personal data, automation around evidence, and an internal GRC platform. I want people spending their time on judgment rather than copying facts between systems.

04

Clarity when facts move.

In incident and privacy work, I try to say what we know, what we don’t, and what we’re doing next. That sounds simple. It gets much harder once people are waiting for an answer.

03 / On my mind

Things I’m still working through.

Security communication

Can someone act on this?

I’m drawn to the way security is explained: to an engineer, a customer, an executive, or someone caught in an incident. The right detail changes, but honesty should not.

Measuring risk

What does the number mean?

I’m interested in methods that expose the reasoning behind a score. If we can’t explain why it moved, it probably isn’t helping us decide.

AI and privacy

Where is the boundary?

New tools make old questions sharper: what data is involved, who has control, what can be checked, and who is accountable when the system surprises us?

I also host conversations about security on Link11’s English-language Follow the White Rabbit podcast. Talking through a question with someone else often gets me further than another slide deck.

The podcast ↗
04 / Beyond the job title

I’m more than the frameworks.

Outside work, I can turn a Ghana match into a very detailed conversation about midfield balance, pressing triggers, and who should start. I run, work on my German, and am slowly learning French.

I like learning the system underneath something—whether it’s a language, a football press, or a security program—and then finding a way to explain it simply.

Still asking the next question.