B
Gründer · Unternehmer · ICT · Führung · TransformationFounder · Entrepreneur · ICT · Leadership · Transformation
Persönliche & unternehmerische Website · Nicht verbunden mit der Gemeindeverwaltung Pratteln Personal & entrepreneurial website · Not affiliated with the municipal administration of Pratteln

Jack Bralig

Komplexität braucht Haltung.Complexity requires conviction.

Technologie. Führung. Transformation.Technology. Leadership. Transformation.

30+
Jahre ErfahrungYears Experience
5
Marken im ÖkosystemBrands in Ecosystem
2003
GegründetFounded
Jack Bralig – Gründer SecRec GmbH

Thesen.
Was ich glaube.
Theses.
What I believe.

Wiederkehrende Überzeugungen, die meine Arbeit leiten. Keine Marketingbotschaften. Haltung.Recurring convictions that guide my work. Not marketing messages. Stance.

1
Komplexität braucht Haltung.
Nicht mehr Technik.
Complexity requires conviction.
Not more technology.

Die meisten Probleme in Organisationen entstehen nicht durch fehlende Technologie, sondern durch fehlende Klarheit. Wer komplexe Systeme führen will, braucht zuerst eine Haltung – eine Überzeugung davon, was zählt und was nicht. Technik ist Werkzeug. Haltung ist Fundament.Most problems in organizations don't arise from missing technology, but from missing clarity. Those who want to lead complex systems first need conviction – a belief in what matters and what doesn't. Technology is a tool. Conviction is the foundation.

2
Technologie ist nur wirksam,
wenn Führung sie trägt.
Technology is only effective
when leadership carries it.

Systeme scheitern nicht an der Software. Sie scheitern an Führungskräften, die Technologie einführen ohne zu verstehen, was sie verändert. Digitale Transformation ist kein IT-Projekt. Es ist eine Führungsaufgabe.Systems don't fail because of software. They fail because of leaders who introduce technology without understanding what it changes. Digital transformation is not an IT project. It is a leadership task.

3
Systeme scheitern selten an Technik,
sondern an Verantwortung.
Systems rarely fail because of technology,
but because of responsibility.

Jeder Vorfall hat eine technische Ursache. Aber fast jeder hat auch eine menschliche. Jemand hat eine Entscheidung nicht getroffen, eine Verantwortung nicht übernommen, ein Risiko nicht benannt. Systeme brauchen Technik – aber sie brauchen zuerst Menschen, die Verantwortung leben.Every incident has a technical cause. But almost every one also has a human one. Someone didn't make a decision, didn't take responsibility, didn't name a risk. Systems need technology – but they first need people who live responsibility.

4
Transformation beginnt dort,
wo jemand Ordnung schafft.
Transformation begins where
someone creates order.

Nicht dort, wo Konzepte geschrieben werden. Nicht dort, wo Budgets freigegeben werden. Sondern dort, wo jemand hinsteht, Verantwortung übernimmt und anfängt, Dinge in eine tragfähige Ordnung zu bringen. Transformation ist kein Prozess. Es ist eine Entscheidung.Not where concepts are written. Not where budgets are approved. But where someone steps up, takes responsibility and starts putting things into a sustainable order. Transformation is not a process. It is a decision.

5
Sicherheit ist ein Teil von Führung,
nicht nur von ICT.
Security is part of leadership,
not just ICT.

Solange Sicherheit als reines IT-Thema behandelt wird, bleibt sie im Keller. Sicherheitskultur entsteht in der Führungsetage, nicht im Serverraum. Wer Verantwortung trägt, trägt auch Verantwortung für die Widerstandsfähigkeit seiner Organisation.As long as security is treated as a pure IT topic, it stays in the basement. Security culture is created in the boardroom, not the server room. Those who bear responsibility also bear responsibility for the resilience of their organization.

10 Sätze,
die wehtun.
Weil sie wahr sind.
10 sentences
that sting.
Because they're true.

Was andere vermeiden auszusprechen. Was Organisationen lieber nicht hören. Was trotzdem gesagt werden muss.What others avoid saying. What organizations would rather not hear. What needs to be said anyway.

01
Die meisten Unternehmen kaufen sich Beruhigungspillen –
und wundern sich dann im Tal der Tränen.
Most companies buy themselves sedatives –
then wonder why they end up in the valley of tears.

Ein ISO-Zertifikat, ein Firewall-Abo, ein jährliches Awareness-Training. Fertig. Bis der Anruf kommt. Sicherheit ist kein Produkt, das man kauft. Sie ist eine Kultur, die man lebt.An ISO certificate, a firewall subscription, an annual awareness training. Done. Until the call comes. Security is not a product you buy. It is a culture you live.

LinkedInVortragSecRec
02
Wer Cybersecurity dem IT-Team überlässt,
hat das Problem nicht verstanden.
Whoever leaves cybersecurity to the IT team
has not understood the problem.

IT schützt Systeme. Sicherheit schützt Organisationen. Das ist nicht dasselbe. Solange der CEO das eine mit dem anderen verwechselt, ist die Organisation verwundbar – egal welche Technologie sie einsetzt.IT protects systems. Security protects organizations. That is not the same thing. As long as the CEO confuses one with the other, the organization is vulnerable – regardless of what technology it uses.

LinkedInFührungskräfteMedien
03
Ein Penetrationstest ohne Konsequenzen
ist Geldverschwendung.
A penetration test without consequences
is a waste of money.

Jedes Jahr bestellen Unternehmen Pentests, bekommen Berichte, legen sie in Ordner – und machen weiter wie bisher. Der Test war nicht das Problem. Der fehlende Wille zur Änderung ist es.Every year, companies order pentests, receive reports, file them away – and carry on as before. The test was not the problem. The missing will to change is.

LinkedInKundenSecRec
04
Der gefährlichste Mitarbeiter ist nicht der Hacker draussen.
Es ist der Ahnungslose drinnen.
The most dangerous employee is not the hacker outside.
It's the clueless one inside.

Insider-Risiken entstehen selten durch böse Absicht. Sie entstehen durch Unwissenheit, Überforderung und fehlende Kultur. Wer das ignoriert, schützt die falsche Seite der Tür.Insider risks rarely arise from malicious intent. They arise from ignorance, overwhelm and missing culture. Those who ignore this are protecting the wrong side of the door.

LinkedInAlethisLumerus
05
Compliance ist nicht Sicherheit.
Es ist Sicherheit auf dem Papier.
Compliance is not security.
It is security on paper.

NIS2, ISO 27001, DSG – wer all das erfüllt, darf sich sicher nennen. Bis zum nächsten Angriff. Vorschriften beschreiben Mindeststandards. Angreifer interessieren sich nicht für Mindeststandards.NIS2, ISO 27001, GDPR – whoever fulfills all of that may call themselves secure. Until the next attack. Regulations describe minimum standards. Attackers are not interested in minimum standards.

LinkedInBehördenVortrag
06
Digitale Sicherheit beginnt nicht im Serverraum.
Sie beginnt im Kopf.
Digital security does not begin in the server room.
It begins in the mind.

Technologie ist nie das eigentliche Problem. Menschen sind es. In ihrer Neugier, Leichtgläubigkeit, Überforderung. Wer das nicht versteht, baut die teuerste Alarmanlage der Welt – und lässt die Hintertür offen.Technology is never the actual problem. People are. In their curiosity, gullibility, overwhelm. Those who don't understand this build the most expensive alarm system in the world – and leave the back door open.

LinkedInLumerusSchulen
07
Wer auf den Angriff wartet,
hat bereits verloren.
Whoever waits for the attack
has already lost.

Reaktive Sicherheit ist ein Geschäftsmodell für Krisenmanager. Wer Risiken sichtbar macht, bevor sie Schaden anrichten, schützt nicht nur Systeme – er schützt Existenzen.Reactive security is a business model for crisis managers. Those who make risks visible before they cause harm protect not just systems – they protect livelihoods.

LinkedInSecRecVortrag
08
Reputation ist das wertvollste digitale Asset.
Und das am schlechtesten geschützte.
Reputation is the most valuable digital asset.
And the least protected one.

Firewalls schützen Daten. Wer schützt den Ruf? Digitale Angriffe auf Personen, Führungskräfte und Unternehmen nehmen zu. Die meisten merken es erst, wenn der Schaden bereits da ist.Firewalls protect data. Who protects the reputation? Digital attacks on individuals, executives and organizations are increasing. Most only notice when the damage is already done.

LinkedInVorisFührungskräfte
09
Sicherheitskultur entsteht nicht im Seminarraum.
Sie entsteht im Alltag.
Security culture does not emerge in the seminar room.
It emerges in everyday life.

Ein jährliches Awareness-Training vergisst man in zwei Wochen. Was bleibt, ist das Verhalten des Chefs, der selbst auf den Link geklickt hat. Vorbilder schaffen Kultur. Schulungen füllen Stunden.An annual awareness training is forgotten within two weeks. What remains is the behavior of the boss who clicked the link himself. Role models create culture. Trainings fill hours.

LinkedInLumerusAlethis
10
Die Schweiz gilt als sicher.
Digitale Sicherheit ist kein Exportgut, das wir automatisch haben.
Switzerland is considered safe.
Digital security is not an export good we automatically possess.

Schweizer Qualität, Präzision und Verlässlichkeit – das stimmt in vielen Branchen. In der Cybersecurity ist die Schweiz so verwundbar wie jedes andere Land. Vielleicht verwundbarer, weil das Bewusstsein fehlt.Swiss quality, precision and reliability – that holds true in many industries. In cybersecurity, Switzerland is as vulnerable as any other country. Perhaps more so, because the awareness is missing.

LinkedInMedienPolitik

Auf der Bühne.
Und daneben.
On stage.
And beside it.

Haltung lässt sich nicht delegieren – sie muss vermittelt und vorgelebt werden. Als Speaker und Coach gebe ich weiter, was drei Jahrzehnte in komplexen Organisationen geprägt haben.Conviction cannot be delegated – it must be conveyed and lived. As a speaker and coach, I pass on what three decades in complex organizations have shaped.

SpeakerSpeaker

Vorträge & KeynotesTalks & keynotes

Klar, unbequem und ohne Folienfriedhof. Vorträge, die eine Haltung hinterlassen – nicht nur Informationen.Clear, uncomfortable and without slide graveyards. Talks that leave a stance behind – not just information.

  • Cybersecurity & digitale SicherheitCybersecurity & digital security
  • Führung & TransformationLeadership & transformation
  • Sicherheitskultur & Human RiskSecurity culture & human risk
  • Komplexität & EntscheidungComplexity & decision-making
Coach & SparringCoach & Sparring

Sparring für FührungSparring for leadership

Vertraulicher Sparringspartner für Führungskräfte und angehende Führungskräfte – wenn Entscheidungen tragfähig, nicht nur schnell sein müssen.Confidential sparring partner for leaders and emerging leaders – when decisions need to be sound, not just fast.

  • Führungskräfte & GeschäftsleitungenExecutives & management
  • Angehende FührungskräfteEmerging leaders
  • Sparring bei schwierigen EntscheidenSparring on difficult decisions
  • Haltung & StandortbestimmungStance & orientation

Anfrage für Vortrag oder Coaching →Enquire about a talk or coaching →

Ein Gründer.
Eine Architektur.
Mehrere Einheiten.
One founder.
One architecture.
Multiple units.

Was ich aufbaue, folgt einer Logik: spezialisierte Einheiten, die jeweils einen klar definierten Bereich abdecken – verbunden durch dieselbe Überzeugung und unter der strategischen Dachmarke Bralig Group.What I am building follows a logic: specialized units, each covering a clearly defined area – connected by the same conviction and under the strategic umbrella of Bralig Group.

Strategische DachmarkeStrategic Umbrella
Bralig Group
Strategische Dachmarke für Sicherheit, Systeme und unternehmerische Entwicklung. Bündelt alle Aktivitäten unter einer gemeinsamen Architektur.Strategic umbrella for security, systems and entrepreneurial development. Brings all activities together under a common architecture.
bralig-group.ch →
Security & ResilienceSecurity & Resilience
SecRec GmbH
Operative Sicherheitsmarke. Penetrationstests, Red Teaming, Incident Response, Forensik und KI-Sicherheit.Operative security brand. Penetration testing, Red Teaming, Incident Response, Forensics and AI Security.
secrec.ch →
Advisory & GovernanceAdvisory & Governance
Bralig
ICT-Strategie, Führung, Governance und Transformation. Unabhängig, herstellerneutral, ohne Verkaufsinteressen.ICT strategy, leadership, governance and transformation. Independent, vendor-neutral, without sales interests.
bralig.ch · demnächstbralig.ch · soon
Menschliche RisikenHuman Risks
Alethis
Social Engineering, interne Schwachstellen, menschliche Angriffsflächen – ausschliesslich auf Mandat.Social engineering, internal vulnerabilities, human attack surfaces – exclusively on mandate.
alethis.ch →
Digitale BildungDigital Education
Lumerus
Cybersecurity für Schulen, Senioren, Eltern und Vereine – verständlich und wirkungsvoll.Cybersecurity for schools, seniors, parents and associations – understandable and effective.
lumerus.ch →
Reputationsschutz · DemnächstReputation Protection · Coming Soon
Voris
Schutz der digitalen Reputation von Personen, Führungskräften und Organisationen. In Entwicklung.Protection of the digital reputation of individuals, executives and organisations. In development.

Gespräch
aufnehmen.
Start a
conversation.

Für Vorträge, Kooperationen, Medienanfragen oder Gespräche über Sicherheitskultur. Persönlich. Diskret. Direkt.For speaking engagements, cooperations, media inquiries or conversations about security culture. Personal. Discreet. Direct.

Emailjack@bralig.ch → TelefonPhone+41 77 412 75 56 →

Direkte Nachricht.Direct message.

Kein Formular. Kein Dropdown. Einfach schreiben. No form. No dropdown. Just write.

Direkt schreiben → Write directly →

Diese Website ist die persönliche und unternehmerische Website von Jack Bralig im Kontext der SecRec GmbH. Sie steht in keinem Zusammenhang mit der Gemeindeverwaltung Pratteln. Alle Inhalte, Thesen und Aussagen erfolgen ausschliesslich in persönlicher bzw. unternehmerischer Funktion und stellen keine Position oder Kommunikation der Gemeindeverwaltung Pratteln dar. This website is the personal and entrepreneurial website of Jack Bralig in the context of SecRec GmbH. It is not affiliated with the municipal administration of Pratteln. All content, theses and statements are made solely in a personal or entrepreneurial capacity and do not represent any position or communication of the municipal administration of Pratteln.