FAQ Answers
Questions and answers.
74 questions from all pages of this website. On the right, an assistant answers further questions, based only on what is published here.
SACOSI and working together
To the pageWho is Ivo Schönberner?
Ivo Schönberner is an IT entrepreneur and advisor based in Zürich and Frankfurt am Main and managing director of IT am Main GmbH. Under the SACOSI brand, he advises executive management, investors and family offices in Switzerland and Germany on IT, risks and regulation, with a focus on start-ups, scale-ups and ventures. His advisory product is called Situational Awareness: IT derived from the situation of the business.
What is SACOSI?
SACOSI stands for Situational Awareness Consulting by Ivo Schönberner. Under this name, Ivo Schönberner offers his advisory product Situational Awareness from Zürich: IT derived from a company’s goals, core processes, finances and stakeholder interests. He works as fractional CTO, IT architect, project lead or sparring partner.
Why is IT a topic for executive management from ten employees?
Because IT then no longer means handing out laptops. It is about customer data and data protection, about the security requirements of customers and investors, about regulations in every market in which the company operates, and about costs that have to fit the financial strategy. These questions decide growth and company value.
What does SACOSI do for investors and family offices?
SACOSI prepares IT situation pictures and IT due diligence reviews for holdings and, where needed, takes on technical leadership for a defined period. The principle: come in, resolve the situation, hand over with documentation.
What does Situational Awareness mean in IT?
Situational Awareness means awareness of the situation. The term comes from aviation and, following Mica Endsley, describes three levels: perceiving the situation, understanding it and projecting how it will develop. In IT this means: first the whole situation of the company is captured, that is goals, leadership vision, core processes, financial situation and the interests of investors and stakeholders. Then IT is built so that it meets exactly these goals.
Which companies does Ivo Schönberner work for?
For the executive management of start-ups, scale-ups and ventures that notice, from around ten employees, that IT is becoming a leadership question. For investors and family offices whose holdings have IT questions. And for companies in industries with high criticality: energy, manufacturing, MedTech and aviation. He supports corporate groups and joint ventures as programme lead.
Does Ivo Schönberner work in Switzerland and Germany?
Yes. He works from Zürich and Frankfurt am Main and takes on engagements in both countries, on site and remotely, in German and English.
How does a collaboration begin?
With a 30-minute conversation without a presentation. You describe the situation, Ivo Schönberner asks questions. Afterwards both sides know whether a situation picture makes sense and which engagement model fits.
How does Situational Awareness differ from conventional IT consulting?
Conventional IT consulting often starts with the technology and adapts the business to the system. Situational Awareness starts with the company: the goals of management, the expectations of investors, core processes and the financial position determine the architecture. The end result is not a slide recommendation but running IT that an internal team can take over.
About Ivo Schönberner
To the pageWhat does Situational Awareness mean for Ivo Schönberner?
Situational Awareness is his advisory product: IT is derived from the situation of the company, that is from goals, core processes, finances and the interests of investors and stakeholders, instead of adapting the business to a system. It is based on the three-level model of Mica Endsley (1995), supplemented by a fourth step: lead and hand over.
What is Ivo Schönberner’s background?
Before his career as an entrepreneur, Ivo Schönberner was an American football player and national team player, European champion 2014 and 2016. As managing director of IT am Main GmbH, he built, among other things, the IT of Discover Airlines from zero to around 2’200 employees and set up independent IT for the joint venture FraAlliance in under four months.
How does Ivo Schönberner approach IT problems?
Systemically: he does not solve the symptom, but builds the architecture from which the problem no longer arises. Decisions are prepared, documented and made verifiable before implementation.
Where does Ivo Schönberner work?
From Zürich and Frankfurt am Main, with engagements in Switzerland and Germany, on site and remotely, in German and English.
Situational Awareness
To the pageWhat is the advisory product Situational Awareness?
Situational Awareness is the advisory product of Ivo Schönberner. It aligns a company’s IT with the entire situation, that is with company goals, leadership vision, core processes, financial situation and the interests of investors and stakeholders: in four steps from capturing the situation through the fit analysis and the target picture to implementation and handover to an internal team.
What belongs in a situation picture according to Situational Awareness?
Six dimensions: the company’s goals, the leadership vision, the core processes, the financial position, the interests of investors and other stakeholders, and obligations and risks. IT is deliberately not part of the situation; it is measured against it.
Why does the financial position belong in IT consulting?
Because IT ties up money and can save money. Liquidity, budget, cost structure and financing stage decide which architecture is viable. A technically ideal solution that overstretches the company financially does not meet the goals of management.
How does Situational Awareness take investors and stakeholders into account?
Their expectations are explicitly captured in the situation picture, for example growth targets, exit readiness, due diligence readiness or requirements of shareholders. IT is designed to support these goals measurably, and conflicts of objectives between stakeholders are openly put forward for decision.
Which tools does Situational Awareness work with?
With proven management tools instead of IT jargon: SWOT analysis of the company, process map, process flows of the core processes (for example in BPMN), stakeholder, RACI and prioritisation matrices, and a decision log. The target picture and roadmap of IT are derived from these.
How does the documentation become audit-proof?
All results are kept in a conformant manner, for example according to the requirements of ISO 27001 and ISO 9001: versioned, with approvals, owners and evidence, in an auditable system instead of scattered files. This way an auditor can trace every decision, even after the handover.
Where does the term Situational Awareness come from?
From aviation and human factors research. In 1995 Mica R. Endsley defined Situational Awareness as the perception of the elements of a situation, the comprehension of their meaning and the projection of their future status. Pilots and air traffic controllers train exactly these three levels.
How can you tell that the business is being forced into the IT?
Typical signs: employees keep shadow lists alongside the system, processes are rebuilt because a tool requires it, decisions depend on individual people, and nobody can explain on one page which IT supports which business goal.
What do you receive at the end of an engagement?
A situation picture on one page, a fit analysis with a decision log, a target picture with a roadmap and, if desired, the implemented IT with a documented handover to the internal team, including playbooks (documented procedures, SOPs) for operations and emergencies.
How long does a situation picture take?
That depends on size, locations and regulation. Scope and timeframe are set in the initial conversation and are then fixed in writing.
Is Situational Awareness a framework or a certification?
No. It is a way of working with fixed results. Existing standards such as ISO 27001 or ITIL are used where they serve the business, but are not introduced for their own sake.
Which company sizes is Situational Awareness suitable for?
From the start-up with ten people to the company with around 1’000 employees, plus programmes in corporate groups and joint ventures. What matters is not size, but that IT and business are drifting apart.
Who carries responsibility during the engagement?
Responsibility for decisions stays with the company. Ivo Schönberner prepares decisions, documents them in the decision log and implements what has been decided.
Does Ivo Schönberner work vendor-independently?
Yes. Technology follows the business. Microsoft 365, Mac and Windows, cloud or locally operated AI are chosen by fit, not by partner status.
What does Situational Awareness cost?
There is no off-the-shelf package. Billing is by day rate or as a monthly engagement, depending on engagement model and scope. You clarify the framework in the first conversation.
Executive management
To the pageWhy should a CEO care about IT?
Because beyond a certain size, IT helps decide how fast the company can grow and what it is worth. Whether new locations, markets or products launch on time, whether customer data is secure and whether a due diligence goes through without discounts depends on decisions that are otherwise taken without executive management.
Why should a CFO care about IT?
Because IT ties up money, generates running costs and carries risks that appear on no balance sheet until they materialise. The question of whether a solution is financed as an investment (CAPEX) or as running expense (OPEX) belongs to the financial strategy, not only to the purchasing department.
What does a situation picture give executive management?
One page on which goals, core processes, finances, stakeholders, obligations and today’s IT stand together. Executive management sees which IT supports which goal, where risks lie and which decision is due next.
Do we need a full-time CIO or CTO for this?
Not necessarily. Many growing companies need the leadership for a defined period: clarify the situation, set the direction, put the team and partners in place and then hand over. That is the core of an engagement as fractional CTO.
How does Ivo Schönberner report to executive management and the board of directors?
With decision papers instead of technical reports: occasion, options, costs, risks and recommendation, recorded in the decision log. The decision stays with executive management.
Should we plan IT as CAPEX or OPEX before an exit?
That depends on the exit horizon, the valuation logic and the type of investor, not on a fixed rule. With a short exit horizon, you avoid investments that a buyer often does not pay for and deliberately manage the effect on EBITDA, because a valuation based on multiples treats running expense differently from capitalised investments. With a long-term investor, CAPEX for a platform that carries over years is negotiable. The framework for this is set by the financial strategy, not by IT alone.
What is the difference between conformant and certified?
Conformant means that processes and evidence meet the requirements of a standard such as ISO 27001 or ISO 9001 in substance. Certified means that an external auditor has formally confirmed this. For internal steering, conformity can be enough, but in customers’ supplier assessments and security questionnaires a certificate often makes the difference as to whether a tender proceeds at all.
Investors and family offices
To the pageWhat is an IT due diligence?
IT due diligence examines, before or after an investment, whether a company’s IT can carry the business model and the growth plan. It assesses architecture, security, costs, dependencies on people and vendors and regulatory obligations, and quantifies what is needed to remedy the findings.
When is an IT situation picture worthwhile for a holding?
Before the investment, when IT can be a value driver or a risk. In the first weeks after the investment, when management needs a plan. And whenever a holding grows, enters new markets or becomes regulated.
What does “come in, resolve, leave” mean?
I take on a clearly defined engagement in the holding, clarify the situation, implement the most important decisions and hand over with documentation to management or an internal team. No lasting dependency on the advisor arises.
Does Ivo Schönberner also work for family offices?
Yes. Family offices often hold stakes in different industries and sizes. A situation picture per holding makes IT risks and costs comparable, without a large consulting team being needed for every question.
Which documents does an IT due diligence need?
Typically a system overview, contracts with IT vendors, costs of recent years, roles and access rights, security concepts, incidents, certificates and audit reports. What is missing is itself a finding.
How do CAPEX or OPEX in IT affect the value of a holding?
That depends on the exit horizon and the valuation logic, not on a fixed rule. In a valuation based on EBITDA multiples, running expense (OPEX) lowers EBITDA and thus tends to lower the multiple value, while capitalised investments (CAPEX) do not burden EBITDA directly, but tie up liquidity and free cash flow. Before a near exit, investments that a buyer does not pay for are usually avoided; with a long-term investment horizon, CAPEX for a supporting platform can make sense. The assessment belongs in the IT situation picture of the holding.
Does a holding have to be certified to ISO 27001, or is working in a conformant manner enough?
Legally, in most cases working in a conformant manner is enough, meeting the requirements of a standard in substance without being externally audited. In due diligence reviews, supplier assessments and customers’ security questionnaires, a certificate nevertheless makes a big difference, because it creates trust without a review of your own and can shorten sales cycles.
Start-ups and scale-ups
To the pageWhen does a company need an IT strategy?
At the latest when IT no longer fits in one head. That is often the case at around ten employees: roles, access rights, customer data, contracts and the first customer requirements for security can then no longer be managed on the side.
What is different about IT for scale-ups?
The pace. What is built for twenty people today has to carry a hundred in a year, in several countries and under new regulations. Modern technology without legacy baggage makes this possible if it is documented and built to scale from the start.
CAPEX or OPEX: how should IT be financed?
That depends on the exit horizon, the valuation logic and the type of investor, not on a fixed rule. Subscriptions and cloud services are running expense (OPEX) and preserve liquidity; with a near exit, this also avoids investments that a buyer often does not pay for. Own hardware or locally operated systems are investments (CAPEX) that can be cheaper over time and are negotiable with a long-term investor. The decision belongs to financial planning and is justified in the decision log.
Why separate development and production systems from the start?
Because otherwise errors, test data and experiments have a direct effect on live operations, and because customers, investors and auditors increasingly ask about it. Anyone who introduces development, test and production systems and the separation of customer tenants only afterwards rebuilds existing processes and pays considerably more for it than if the separation had been planned from the beginning.
Which regulations come with growth?
That depends on industry and markets. Customers in the EU bring the GDPR, corporate customers bring security evidence such as ISO 27001 or TISAX, AI products bring the EU AI Act, and critical sectors bring reporting obligations. An overview is on the Regulation page.
Succession and handover
To the pageWhich IT risks does a buyer take on in a business succession?
Without their own review, a buyer takes on the condition of the IT as it is: an open investment backlog, outdated or poorly maintained systems, ongoing licence and contract commitments, security gaps and the dependency on individual people or service providers. These risks often only show months after the handover.
What does financial due diligence miss in IT?
Financial due diligence examines figures, contracts and balance sheet items. It does not show whether an application is technically outdated, whether an investment backlog is pending, whether knowledge exists in only one head or whether there are security gaps. These questions are answered by a technical due diligence, which complements the financial one and does not replace it.
How do you identify dependencies on key people (key-person dependencies)?
Key-person dependencies show when access credentials, passwords, configurations or procedures are known to only one person and are documented nowhere. A key-person dependency map systematically records which knowledge is tied to which person and shows what documenting it or arranging cover costs.
When should an owner prepare the IT situation picture before the handover?
Well before the first approach to buyers or the succession arrangement, so that the investment backlog and key-person dependencies can still be remedied rather than merely disclosed. Even without a concrete sale plan, the situation picture is worthwhile as soon as a succession becomes foreseeable.
What belongs in a technical due diligence in a succession?
Architecture and condition of the systems, security and access, running costs and contract terms, dependencies on people and service providers, the licence inventory and its transferability, and the question of whether the existing documentation is sufficient for a new team at all.
What does investment backlog mean, and how is it estimated?
Investment backlog is technology that should long since have been renewed or replaced, but keeps running because nobody approved the investment. It cannot be quantified to the exact franc, but it can be stated as a range with a rationale per item, so that buyer and seller have a common basis for the negotiation.
Regulation and standards
To the pageDoes NIS2 apply to Swiss companies?
Not directly. NIS2 is an EU directive. It affects Swiss companies via an establishment in the EU, because EU customers have to demonstrate the security of their supply chain and pass this requirement on by contract, or when they offer certain digital services such as cloud or managed services in the EU. A representative in the EU must then be designated.
Since when has the new Swiss data protection act applied?
Since 1 September 2023. It applies to all companies that process personal data in Switzerland. Anyone serving customers in the EU must also observe the GDPR.
Does the EU AI Act apply to Swiss companies?
Yes, if they place AI systems on the market in the EU or the output of their AI systems is used in the EU. The obligations have applied in stages since February 2025. The obligations for high-risk systems apply from December 2027, for AI in regulated products from August 2028.
What is the difference between ISO 27001 and TISAX?
ISO 27001 is an international standard for information security management systems, with a certificate. TISAX is an assessment procedure of the automotive industry based on the VDA ISA catalogue, with a label instead of a certificate, and is required by vehicle manufacturers by contract.
Does the EU MDR apply in Switzerland?
In Switzerland, the Medical Devices Ordinance (MedDO) applies, with Swissmedic as supervisory authority. For access to the EU market, the EU MDR applies. Since 26 May 2021, the EU has treated Switzerland as a third country for medical devices, so Swiss manufacturers need an authorised representative in the EU.
Does a start-up have to be certified to ISO 27001?
Not by law. But corporate customers, tenders and investors often ask for it. It makes sense to set up processes early so that a certification later is a small step and not a rebuild.
Fractional CTO
To the pageWhat does a fractional CTO do?
A fractional CTO takes on the technical leadership of a company part-time or for a defined period. They are responsible for architecture, technology decisions, security and building the team, without the company having to hire a full-time executive immediately.
When is a fractional CTO worthwhile?
There are four typical situations: there is no CTO yet, the current CTO is leaving, a financing round or due diligence is coming up, or the platform no longer carries the growth. In all four cases, technical leadership is needed quickly, but not necessarily permanently.
How much time does Ivo Schönberner invest as fractional CTO?
That depends on the situation. One to three days per week or a monthly engagement with a fixed scope is usual. The framework is set in the initial conversation.
What is the difference between a fractional CTO and an interim CTO?
An interim CTO replaces a missing executive, usually full-time for a transition period. A fractional CTO works part-time, often over a longer period. Ivo Schönberner takes on both forms, depending on what the situation requires.
Does a fractional CTO help with an IT due diligence?
Yes. They prepare architecture, security, documentation and team so that investors can examine what they want to examine, and accompany the conversations with the reviewers.
IT architecture
To the pageFor which company sizes does Ivo Schönberner work as IT architect?
Mainly for companies with around 50 to 1’000 employees, often SMEs and companies in regulated industries. At this size, IT is too complex for improvisation, but usually has no architecture department of its own.
What is a target architecture?
A target architecture describes what a company’s IT should look like in twelve to 36 months: identities, workplaces, applications, data, operations and security, derived from the processes and goals of the business, with a roadmap to get there.
Does Ivo Schönberner work with Mac and Windows?
Yes. He plans workplaces with Mac and Windows on an equal footing, including device management, identity and security, so that both worlds meet the same rules.
When should AI run locally rather than in the cloud?
When data is confidential, personal or regulated and should not or may not go to third parties. A locally operated model can then be the more sensible choice. The decision depends on data, costs and requirements and is justified in the decision log.
What is compliance by design?
Compliance by design means that requirements such as ISO 27001, the Swiss Federal Act on Data Protection (FADP), the GDPR or sector requirements are built into the architecture from the start, instead of being added later. This saves rework and makes audits plannable.
Project leadership
To the pageWhich enterprise projects has Ivo Schönberner led?
With IT am Main, among others, the IT build-up of Discover Airlines from 2021 to 2026 with a prepared handover to the group IT of the Lufthansa Group, and the IT build-up for FraAlliance, the joint venture of Fraport and Lufthansa, in under four months.
What is special about IT projects in joint ventures?
Two or more shareholders bring their own IT standards, security rules and approval routes. Project leadership has to connect these worlds without violating any of them, and be able to evidence every decision to both sides.
Does Ivo Schönberner also take on carve-outs and carve-ins?
Yes. Separating a unit from a corporate group (carve-out) or integrating into a corporate group (carve-in) are situations in which Situational Awareness is particularly effective, because business and IT are in motion at the same time.
How does Ivo Schönberner report as project lead?
With evidence instead of status slides: decisions in the decision log, progress measured by verifiable results, risks with owners and dates.
Does Ivo Schönberner have experience in aviation?
Yes. Two of his largest engagements took place in the environment of the Lufthansa Group, including Discover Airlines with the network connection of the Operations Control Center and FraAlliance in Frankfurt.
No question matches this filter.