SECURITYSQUAD

An information security officer, without having to hire one

A named contact, predictable effort, cancellable monthly – in three tiers that match the size of your organisation.

The role

What a security officer is responsible for

The information security officer is the central point of contact for every question of information security. They develop policies and see them implemented, assess risks, advise on projects and procurement, and coordinate the protective measures. Above all they are the link between management, IT and the business units – the place where security turns from a technical task into an organisational one.

Then there is the obligation side: NIS2, the German IT Security Act and ISO 27001 all require somebody to carry the responsibility. The security officer prepares audits, supports incident handling and makes sure staff know what to watch out for.

When an external security officer beats an internal post is set out separately.

Tiers

Three tiers, one principle

Each tier is half a fixed base and half hours as used. That gives you a predictable floor while you know where the ceiling lies.

TierHours / monthFixedAs used
S – Basic8 h4 hup to 4 h
M – Standard16 h8 hup to 8 h
L – Extended32 h16 hup to 16 h

Variable hours that go unused are not billed. We state the commercial terms in the quote.

What is included

What each tier contains

S – Basic

  • Regular baseline advice and review meetings
  • Maintenance of policies and security documentation
  • A point of contact for security-related questions
  • Support for awareness measures

M – Standard

Everything in S, plus:

  • Small risk and vulnerability assessments
  • Support with audit preparation (ISO 27001, IT-Grundschutz, NIS2)
  • Advice on procurement and projects with a security dimension
  • Regular reporting to management and IT

L – Extended

Everything in M, plus:

  • Close support on measures and projects
  • Internal audits and compliance checks
  • Support during security incidents and crisis exercises
  • Management dashboards and reporting
Terms

The terms, without small print

Minimum term
One month. Cancellable monthly thereafter.
Changing tier
Possible after three months, in either direction.
Additional hours
Beyond the tier, by arrangement and with notice.
Response times
We agree fixed response times on request.
Transparency
A monthly report shows what the hours were spent on.
How we work
Remote or on site, as agreed with you.
The model

Why half fixed and half as used

A pure time-and-materials contract makes costs unpredictable; a pure retainer pays for idle time. Splitting it solves both:

Predictability

The fixed base sits in the budget and the effort is capped. You know in advance what the worst case looks like.

Fairness

Quiet months cost less. Variable hours that are not needed are not billed.

Flexibility

When demand grows – ahead of an audit, say – you change tier instead of negotiating a new contract.

Fields of work

What a security officer actually works on

The role is often reduced to documentation. In practice the work spreads across seven fields, and which of them carry weight is decided by your situation:

Risk assessment

Identify critical processes and assets, make risks transparent and keep assessing them – including along the supply chain.

Frameworks

Establish which standards have to be met: ISO 27001, IT-Grundschutz, NIS2, critical infrastructure rules.

Threat picture

Recognise threats early rather than waiting for the incident.

Governance

Improve the effectiveness and efficiency of measures – and present the picture to management in a form they can decide on.

Enablement

Build knowledge in the organisation and choose the awareness measures that fit.

Architecture

Bring security requirements into digitalisation projects early instead of retrofitting them.

Operations

Make it measurable how quickly things are detected and how quickly they are answered.

Questions

Frequently asked questions about the external security officer

Does an external officer replace an in-house post?

For most small and mid-sized organisations, yes. An in-house post only pays off at a size where the task genuinely fills someone's time – and it has to be filled, kept trained and covered during holidays. If you build the role internally later, we hand over in an orderly way.

How quickly can we reach you?

You get a named contact, not a hotline. Regular meetings are part of every tier. If you need fixed response times, we agree them – and then they sit in the contract rather than in a promise.

What happens in a quiet month?

Only the fixed share applies. Unused variable hours lapse; they are neither billed nor carried over.

Can we start with S and move up later?

Yes, a change is possible after three months in either direction. Many start with S, move to M or L for the duration of an audit preparation, and move back afterwards.

Do you take the role in public authorities as well?

Yes. We work for companies, municipalities and public authorities. The combination of ISO 27001 and IT-Grundschutz is particularly sought after there, and both are core to what we do.

Which tier fits you?

One conversation usually settles it – half an hour is typically enough.

Arrange a first conversation