Your situation

CISO as a service: external information security officer

You want ongoing support for your information security but lack sufficient internal resources. With CISO as a service, an external information security officer from secuvera supports your ISMS (information security management system). They connect IT, business units and senior management with clearly agreed tasks.

Free of charge and without obligation.

  • BSI-certified for IS consulting and IS audit
  • ISO 27001 Lead Auditors on the team
  • Supporting member of the CISO Alliance
secuvera employee analysing on a laptop, next to an illuminated lighthouse model
CISO as a service: a fixed point of reference for your information security.

Your situation

Your head of IT is also your IT security officer – and there is too little time left for information security?

In many companies, the head of IT also takes on the role of IT security officer. This dual role often leads to a comparatively low level of information security. This is rarely due to a lack of competence or will, but to the resources and core objectives of IT: IT is responsible for operations and implementation, while the information security officer is its partner with a focus on risks, rules and effectiveness.

However, an ISMS to ISO 27001 or IT-Grundschutz needs someone who maintains the reference documents, chairs the security committee, briefs new employees and reports to management every year.

This is where secuvera's external IT security officer comes in – also known as "CISO as a service". They bring experience, mediate neutrally between departments and roles and can draw on the full expertise of secuvera when needed. We tailor the scope to your needs.

Services & results

Core services at a fixed rhythm, additional services as agreed

Your ISMS receives ongoing support: an external information security officer maintains the ISMS documents, supports IT and the security committee, reports to management and raises your employees' awareness. You define the scope and frequency with us in advance; audits or migrations are added as needed. IT operations and decisions remain with you.

We define the core services with you on a case-by-case basis. The rhythms below serve as a planning basis – for example, security committee and IT meeting every two months, awareness training once a year. We plan larger projects separately as additional services.

Maintaining ISMS documents

Your external information security officer regularly maintains the reference documents of your ISMS. This includes minor adjustments resulting from regular changes in the information domain. We also keep the existing data in the ISMS tool up to date.

Supporting IT and the security committee

We agree the frequency and format of meetings as part of the core services.

  • IT meetings, for example every two months: we support significant changes and strategic developments.
  • Participation in and chairing of the security committee as agreed. Here too, a rhythm of about two months serves as a planning basis.
  • During on-site visits, your external information security officer is available for questions on information security.

Reporting and awareness

  • Annual management report: we compile the relevant information for your management.
  • We introduce new employees to your security rules. We create and update the documents needed for this.
  • Annual awareness training for all employees: we schedule the sessions to suit your organisational structure. Experience shows that this is spread over three to five sessions of about one hour each.

Supporting additional projects

Larger projects are not automatically part of the ongoing support. You can additionally agree the following services as needed:

  • Updating or creating security concepts, including application-specific concepts, policies and implementation concepts.
  • Supporting extensive projects, procurements and changeovers. We assess their impact on information security and the security concept.
  • Supporting migrations, IT changes and decommissioning. We incorporate the changes into the security concept.
  • Advising on replacing your existing ISMS software.
  • Training your employees in using the ISMS software.
  • Preparing for reviews and audits by third parties.
  • Supporting internal audits separately or having them carried out by independent auditors. We clarify independence from the audited activities in advance.
  • On request, helping to evaluate security advisories from CERTs or manufacturers.

Our expertise

Your external information security officer does not work alone: they can draw on colleagues and thus on secuvera's entire portfolio – from ISMS consulting to ISO 27001 and IT-Grundschutz and internal audits to penetration tests.

secuvera has offered IT security consulting since 1988 and has been a BSI-certified IT security service provider since December 2011.

Getting started

Defining the tasks and interfaces of your external information security officer

Defining the assignment

We clarify contact persons, decision-making channels, authority and available resources. Your IT remains responsible for operations. External support does not replace a full-time position needed internally or the complete implementation of measures.

Agree on CISO as a service
An open brass compass in the hands of a secuvera employee
The information security officer role reliably filled, closely coordinated with your head of IT.

Operations and implementation of measures

The external information security officer does not take on operational tasks or the complete implementation of measures. Your management retains decisions and management responsibility. We record tasks and interfaces before the support begins.

Questions about engaging CISO as a service

Does an external information security officer replace our head of IT?

No. The information security officer looks at information security across the areas involved and mediates between IT, business units and management. Running IT remains the task of your organisation. The roles are meant to work together and are defined before the engagement.

Which tasks are part of the ongoing CISO as a service support?

Possible core services are maintaining the ISMS reference documents, regular IT and security meetings, management reports and awareness training. Which of these secuvera takes on, and at what rhythm, is agreed for your security organisation.

Do we still have to implement our own security measures?

Yes. The external information security officer does not take on operational tasks or the complete implementation of security measures. Internal responsibilities and management decisions remain necessary. The support also does not replace a full-time position needed internally.

Is an external information security officer the same as CISO as a service?

At secuvera, both terms refer to the same offering: an external IT security officer who supports your ISMS. We define the tasks, authority and interfaces involved with you before the support begins.

What should we regulate in the contract with an external information security officer?

Initial guidance is provided by requirement ISMS.1.A5 "Contract design when appointing an external information security officer" in the BSI IT-Grundschutz Compendium – regardless of whether you fill the role internally or externally. We define tasks, rhythms and boundaries together before the start.

Articles on this topic (in German)

All 2 articles on the topic (in German)

How can we support you with CISO as a service?