Skip to content
Peter-Christoph Haider
Menu

Board work

An operator on the board, not an observer.

I have spent two decades running technology companies rather than advising them — building enterprise software, operating IT infrastructure for critical environments, and buying and integrating businesses. I take on a small number of board and advisory mandates where that experience changes the decision.

Where I add value.

Four areas where I have made the decision myself rather than read about it.

Scaling technology organisations

Founding and running a software company through every stage from first line of code to enterprise deployment — product, engineering culture, pricing, and the point at which a founder-led team needs structure.

M&A and capital allocation

Acquiring, integrating and holding profitable technology businesses. Diligence that finds the real risks, valuation discipline, and the post-close reality of merging teams and systems.

Critical infrastructure and resilience

Operating secure network and cloud infrastructure for companies, public authorities and critical infrastructure operators — where availability and security obligations are not abstractions.

Technology risk from the outside

More than thirty startup investments across deep tech, biotech, semiconductors and robotics. Useful for judging which emerging technology threatens an incumbent and which is noise.

Named specialism

Cybersecurity competence at board level.

Under the NIS2 Directive and Germany's implementing legislation, the management bodies of essential and important entities must approve and oversee cybersecurity risk-management measures, keep their own knowledge current through regular training, and can be held personally liable for failures. Comparable expectations reach financial entities through DORA.

Most boards are now looking for at least one member who can carry that competence credibly rather than nominally. I operate the kind of infrastructure the legislation was written about — secure networks, cybersecurity and cloud systems for companies, public authorities and critical infrastructure operators across Germany — and I can sit on the other side of the table and ask the questions a supervisory authority would.

This is board-level technology and governance experience, not legal or compliance advice. Boards should take their own counsel on the specific obligations that apply to them.

  • Reviewing and challenging cyber risk-management measures
  • Testing incident response and reporting readiness
  • Assessing supply chain and third-party exposure
  • Judging whether security spend is buying real resilience
  • Preparing boards for audit and supervisory scrutiny

What fits.

Company type
Technology-led businesses: software and SaaS, IT and managed services, industrial technology, and companies whose operations depend on infrastructure they cannot afford to lose.
Stage
From post-Series A through established mid-market. Also private-equity portfolio companies and family businesses professionalising their governance.
Role
Non-executive director, supervisory board member (Aufsichtsrat), advisory board (Beirat), or a defined advisory mandate.
Geography
Germany, Austria and Switzerland. Remote-friendly mandates elsewhere in Europe considered.
Languages
German and English, both to full working standard.
Capacity
I hold a deliberately small number of mandates so that each one gets real attention. Please ask about current availability.

Discuss a mandate

For nomination committees, chairs, founders, investors and search consultants. Tell me about the company and the gap on the board, and I will tell you honestly whether I am the right person.

Prefer to talk first? Book thirty minutes.