Atdhe Buja | Chief Information Officer | January 2022–July 2024 | Kosovo
I led technology and cybersecurity initiatives at ICT Academy, a four-person organization working across education, research and development, consulting, and professional activities. This case study describes how I formalized business processes, strengthened security governance, and connected technical delivery with organizational priorities.
I reported monthly to the owner and general manager. My responsibilities included technology priorities, security policies and risk reviews, cloud and cybersecurity engineering oversight, client requirements, service contracts, vendor deliverables, and reporting on IT and security expenditure. The four-person company included me; the six-person research project team described below was a separate project scope.
Read the full CIO case study on my website
- Defined business processes across Education, R&D, Consulting, and Activities, including a research-to-consulting process.
- Established a BPMN process repository using Red Hat Process Automation Manager and standardized the R&D register.
- Used ISO 9001 principles and Plan–Do–Check–Act feedback to structure process documentation and review.
- Maintained security policies and risk assessments aligned with ISO 27001/27002, with project and remediation follow-up in Asana.
- Oversaw least-privilege access practices, MISP threat-intelligence sharing, and a cloud-to-local backup approach incorporating offline external storage.
- Led the EC-Council Authorized Training Center application process and municipal IT and cybersecurity workshop delivery.
- Led a six-person research project with Global Cyber Alliance, using GCA AIDE data for Python-based IoT attack-detection research.
| Date | Milestone | Context |
|---|---|---|
| December 2018 | ICT Academy CERT established | Earlier ICT Academy work; precedes my CIO appointment |
| September 2019 | ICT Academy CERT first TI-listed | Earlier institutional milestone |
| January 2022 | CIO appointment began | Start of the CIO period covered here |
| March 2024 | EC-Council ATC announcement | Training capability development |
| May 2024 | Municipal IT and cybersecurity workshop announcement | Public-sector capacity building |
| May 2024 | ICT Academy CERT completed TI re-listing | Institutional milestone during the CIO period |
| July 2024 | CIO appointment ended | End of the CIO period covered here |
ICT Academy CERT is TI-listed. This case study does not claim TI accreditation or FIRST membership for this team. My separate UBT-CERT case study concerns a different organization and team.
- Operating model and business processes
- Security governance and resilience
- Leadership, partnerships, and delivery
- Timeline and public references
- Research-to-consulting process and modeling notes
- Research register structure
- Illustrative risk and remediation example
- CIO leadership reflection
The risk example is illustrative and does not document a completed historical remediation. Confidential operational records are not included.
This is a retrospective professional account. Public sources confirm the institutional milestones linked below; descriptions of my responsibilities and internal practices are based on my own account. No independently measured cost savings, risk-reduction percentages, uptime improvements, or recovery-time results are claimed. ISO alignment describes the principles used, not organizational certification. Public records can change after the historical period described.
This is a personal portfolio, not an official organizational publication or endorsement.