An information security officer, without having to hire one
A named contact, predictable effort, cancellable monthly – in three tiers that match the size of your organisation.
What a security officer is responsible for
The information security officer is the central point of contact for every question of information security. They develop policies and see them implemented, assess risks, advise on projects and procurement, and coordinate the protective measures. Above all they are the link between management, IT and the business units – the place where security turns from a technical task into an organisational one.
Then there is the obligation side: NIS2, the German IT Security Act and ISO 27001 all require somebody to carry the responsibility. The security officer prepares audits, supports incident handling and makes sure staff know what to watch out for.
When an external security officer beats an internal post is set out separately.
Three tiers, one principle
Each tier is half a fixed base and half hours as used. That gives you a predictable floor while you know where the ceiling lies.
| Tier | Hours / month | Fixed | As used |
|---|---|---|---|
| S – Basic | 8 h | 4 h | up to 4 h |
| M – Standard | 16 h | 8 h | up to 8 h |
| L – Extended | 32 h | 16 h | up to 16 h |
Variable hours that go unused are not billed. We state the commercial terms in the quote.
What each tier contains
S – Basic
- Regular baseline advice and review meetings
- Maintenance of policies and security documentation
- A point of contact for security-related questions
- Support for awareness measures
M – Standard
Everything in S, plus:
- Small risk and vulnerability assessments
- Support with audit preparation (ISO 27001, IT-Grundschutz, NIS2)
- Advice on procurement and projects with a security dimension
- Regular reporting to management and IT
L – Extended
Everything in M, plus:
- Close support on measures and projects
- Internal audits and compliance checks
- Support during security incidents and crisis exercises
- Management dashboards and reporting
The terms, without small print
- Minimum term
- One month. Cancellable monthly thereafter.
- Changing tier
- Possible after three months, in either direction.
- Additional hours
- Beyond the tier, by arrangement and with notice.
- Response times
- We agree fixed response times on request.
- Transparency
- A monthly report shows what the hours were spent on.
- How we work
- Remote or on site, as agreed with you.
Why half fixed and half as used
A pure time-and-materials contract makes costs unpredictable; a pure retainer pays for idle time. Splitting it solves both:
Predictability
The fixed base sits in the budget and the effort is capped. You know in advance what the worst case looks like.
Fairness
Quiet months cost less. Variable hours that are not needed are not billed.
Flexibility
When demand grows – ahead of an audit, say – you change tier instead of negotiating a new contract.
What a security officer actually works on
The role is often reduced to documentation. In practice the work spreads across seven fields, and which of them carry weight is decided by your situation:
Risk assessment
Identify critical processes and assets, make risks transparent and keep assessing them – including along the supply chain.
Frameworks
Establish which standards have to be met: ISO 27001, IT-Grundschutz, NIS2, critical infrastructure rules.
Threat picture
Recognise threats early rather than waiting for the incident.
Governance
Improve the effectiveness and efficiency of measures – and present the picture to management in a form they can decide on.
Enablement
Build knowledge in the organisation and choose the awareness measures that fit.
Architecture
Bring security requirements into digitalisation projects early instead of retrofitting them.
Operations
Make it measurable how quickly things are detected and how quickly they are answered.
Frequently asked questions about the external security officer
Does an external officer replace an in-house post?
For most small and mid-sized organisations, yes. An in-house post only pays off at a size where the task genuinely fills someone's time – and it has to be filled, kept trained and covered during holidays. If you build the role internally later, we hand over in an orderly way.
How quickly can we reach you?
You get a named contact, not a hotline. Regular meetings are part of every tier. If you need fixed response times, we agree them – and then they sit in the contract rather than in a promise.
What happens in a quiet month?
Only the fixed share applies. Unused variable hours lapse; they are neither billed nor carried over.
Can we start with S and move up later?
Yes, a change is possible after three months in either direction. Many start with S, move to M or L for the duration of an audit preparation, and move back afterwards.
Do you take the role in public authorities as well?
Yes. We work for companies, municipalities and public authorities. The combination of ISO 27001 and IT-Grundschutz is particularly sought after there, and both are core to what we do.
Which tier fits you?
One conversation usually settles it – half an hour is typically enough.
Arrange a first conversation