CRA full compliance required 453 days left What it means for you
THZ Networks Under attack? SOS — incident response, any hour of any day

CISOaaS

Chief Information Security Officer

A security executive on subscription. Policy, risk register, supplier reviews, board reporting and the evidence pack an auditor asks for — delivered by someone who has done the job, without a six-figure hire you cannot justify at your size.

Why the board now needs one

NIS2 moved accountability for cyber security out of the IT department and onto management personally. That changes what the role is: someone has to own the risk register, sign the policies, brief the board in language it understands, and be able to show a regulator what was decided and when. That is not a job an IT manager can absorb on top of running the network.

What you get

  • A risk register that is maintained, not written once and filed
  • Policies based on a recognised framework, adjusted to your sector and size
  • Board reporting: what changed, what it costs, what happens if nothing is done
  • A prioritised remediation list, scored by impact rather than by how loud the tool was
  • Someone to sit in the audit and answer the questions

HOW IT WORKS

From first call to steady state

  1. Assess

    A structured questionnaire and a look at the estate, producing a picture of where you actually stand rather than where the last consultant said you did.

  2. Plan

    A tailored policy set and a programme, built against your regulatory profile and benchmarked against your industry.

  3. Remediate

    Tasks written so an engineer can act on them, ordered by what reduces risk fastest per euro spent.

  4. Measure

    A protection score per risk — ransomware, data leak, fraud, defacement — so progress is visible to people who do not read logs.

  5. Sustain

    Quarterly review as the rules, the threats and your own business change. Compliance is a state, not a project with an end date.

WHAT THIS ANSWERS

The obligations this covers

This is not a marketing claim. Each of these regimes names the requirement that this service is the answer to, and the page behind it says which clause.

Who this is for. Organisations in scope of ZInfV-1 or DORA, anyone chasing ISO 27001, and anyone whose largest customer has started sending security questionnaires.

Start with a conversation, not a quote

Tell us what you run and what you are being asked to prove. We will say what this would involve at your size, and whether you need it at all.

Get in touch +386 51 249 533