CISOaaS
Chief Information Security Officer
A security executive on subscription. Policy, risk register, supplier reviews, board reporting and the evidence pack an auditor asks for — delivered by someone who has done the job, without a six-figure hire you cannot justify at your size.
Why the board now needs one
NIS2 moved accountability for cyber security out of the IT department and onto management personally. That changes what the role is: someone has to own the risk register, sign the policies, brief the board in language it understands, and be able to show a regulator what was decided and when. That is not a job an IT manager can absorb on top of running the network.
What you get
- A risk register that is maintained, not written once and filed
- Policies based on a recognised framework, adjusted to your sector and size
- Board reporting: what changed, what it costs, what happens if nothing is done
- A prioritised remediation list, scored by impact rather than by how loud the tool was
- Someone to sit in the audit and answer the questions
HOW IT WORKS
From first call to steady state
-
Assess
A structured questionnaire and a look at the estate, producing a picture of where you actually stand rather than where the last consultant said you did.
-
Plan
A tailored policy set and a programme, built against your regulatory profile and benchmarked against your industry.
-
Remediate
Tasks written so an engineer can act on them, ordered by what reduces risk fastest per euro spent.
-
Measure
A protection score per risk — ransomware, data leak, fraud, defacement — so progress is visible to people who do not read logs.
-
Sustain
Quarterly review as the rules, the threats and your own business change. Compliance is a state, not a project with an end date.
WHAT THIS ANSWERS
The obligations this covers
This is not a marketing claim. Each of these regimes names the requirement that this service is the answer to, and the page behind it says which clause.
- 96 days left NIS2 / ZInfV-1 Up to €10 M or 2% of turnover
- 444 days left AI Act Up to €35 M or 7% of turnover
- In force now DORA Up to 2% of global turnover
- In force now GDPR / ZVOP-2 Up to €20 M or 4% of turnover
- Contract requirement ISO/IEC 27001 Lost tenders
- Draft in parliament CER The same entities as ZInfV-1
Who this is for. Organisations in scope of ZInfV-1 or DORA, anyone chasing ISO 27001, and anyone whose largest customer has started sending security questionnaires.
THE REST OF IT
Delivered by the same team
Start with a conversation, not a quote
Tell us what you run and what you are being asked to prove. We will say what this would involve at your size, and whether you need it at all.