Since 2021: vCISO mandate and ISMS platform from one company.
Two ways in: Consulting GmbH takes on the CISO function as vCISO or Interim CISO, Operations GmbH builds the OdySecure platform. Funded with €800,000 (BMFTR StartUpSecure), developed with the CISPA incubator.
25 years of experience in information security and cyber security. Partner at PwC, Director at Deloitte.
Certifications: ISO 27001 Lead Auditor since 2006, BS 25999 Lead Auditor, ITIL Service Manager (training), CISA (inactive), auditor of ISO 27001 audits based on IT-Grundschutz (inactive).
Industry experience: financial services, telecommunications, public sector, energy, German mid-market, and manufacturing. CISO roles in financial services and manufacturing.
Consulting GmbH takes on the CISO function as a mandate. Operations GmbH develops and licenses OdySecure. The platform is included in the vCISO mandate; organisations with their own CISO license it on its own.
Cybervize Consulting GmbH: the CISO function as a mandate
Founded in 2021. Consulting GmbH fills the CISO function as a vCISO, either for the duration of an implementation or permanently, or as an Interim CISO when a gap has to be closed at once.
Typical triggers: regulatory requirements such as NIS-2, DORA or ISO 27001 that must be met and evidenced; a vacant CISO post; an acquisition or carve-out after which security management has to be rebuilt.
Cybervize Operations GmbH: the OdySecure platform
Founded in 2023. Operations GmbH develops OdySecure, built during a 14-month partnership with the CISPA incubator, the Helmholtz Center for Information Security, under the BMFTR StartupSecure programme. The project was funded from October 2023 to March 2025.
In a vCISO mandate, OdySecure is the tool the work runs on. As a licence it is open to any organisation that fills the CISO function itself.
What sets Cybervize apart
01
Consulting built the platform
OdySecure codifies the methodology Cybervize Consulting has used to run mandates since 2021.
02
Funded development
The development of OdySecure was funded with €800,000 through StartUpSecure (BMFTR) and carried out with the CISPA incubator.
03
The goal is evidence
A mandate is complete when the requirement is demonstrably met. We keep the evidence in OdySecure.
Network and Recognition
The standards we work to
Our work is grounded in internationally recognized standards and frameworks.
ISO 27001
Building and operating ISMS according to the world's leading information security standard.
BSI IT-Grundschutz
The German reference framework for systematic IT security.
NIST CSF
Risk-based security management following the international gold standard. Identify, Protect, Detect, Respond, Recover.
NIS-2 & DORA
Compliance management for current EU regulations. From gap analysis to implementation and evidence management.
Data & AI Sovereignty, Made in Germany
Hosting and development in Germany, AI under your own control.
Data Residency Germany
Operated in data centers in Germany, by a European provider without a US parent company.
Development Germany
Product development and security engineering in Germany.
AI Under Control
Sovereign mode as the default: self-operated LLM, no data shared with external model providers.
Frequently Asked Questions about the Group Structure
Why does Cybervize consist of two separate companies?
Cybervize was founded in 2021 on one thesis: information security consulting delivers the greatest value when the right platform comes with it. Cybervize Consulting GmbH (founded 2021) is the consulting pillar and delivers vCISO, Interim CISO and implementation mandates. Cybervize Operations GmbH (founded 2023) develops OdySecure and licenses it to mid-market and enterprise clients. The separation enables clear roles: consulting owns mandates and methodology, operations owns product development, product operations and the licence business. For clients, the entry point stays unified; internally, both companies work closely together while remaining legally and financially independent.
What does the partnership with the CISPA incubator mean in practice?
The CISPA Helmholtz Center for Information Security is one of Europe's leading research institutions for cybersecurity. OdySecure was designed and built during a 14-month partnership with the CISPA incubator under the BMFTR StartupSecure programme. The project was funded from October 2023 to March 2025. Classic GRC tools turn compliance into a tick-box exercise running parallel to day-to-day operations. OdySecure was built to weave compliance requirements into the running security and IT processes, so that evidence is generated within day-to-day operations and processes are compliant by default. The architecture is therefore based on scientifically reviewed security and AI concepts, not a whiteboard sketch.
Where does the engagement start if we have no CISO of our own?
With a vCISO mandate from Cybervize Consulting GmbH. We take on the CISO function, either for the duration of an implementation or permanently, and carry your organisation's regulatory requirements through to evidence. OdySecure is included in the mandate. If the post falls vacant at short notice, an Interim CISO bridges the gap; ahead of an acquisition, cyber due diligence assesses the target. Organisations with their own CISO can license OdySecure without a mandate.
Is Cybervize large enough for enterprise mandates?
For more complex engagements, Cybervize Consulting works with a senior advisor pool and partner structures, so delivery capacity scales without mandates depending on a single person. OdySecure is module-licensed and designed for mid-market companies up to large groups, for IT and OT alike.
Where is OdySecure data processed?
Hosting of the platform and processing of your data within it exclusively in data centers in Germany, with a European provider without a US parent company, which under current law is not subject to the US CLOUD Act. In Sovereign mode, the default, AI models are self-operated in Germany with no data shared with external model providers; alternatively BYOK or Managed, where you decide on the data flow. OdySecure is GDPR-compliant with JSON data export that marks its own limits, anonymisation, and scheduled deletion. This data sovereignty is a direct consequence of the CISPA partnership and the platform architecture.
Which region does Cybervize cover?
The focus is on Germany, Austria and Switzerland. That is where most mandates sit and where the regulation is our daily business. We are not limited to it: OdySecure is available worldwide, and we take on mandates outside the German-speaking market as well. There is one limit, and that is language: we work in German and English. Headquarters in Düsseldorf; delivery happens on-site, hybrid or remote depending on the mandate.
Find out which way in fits your organisation.
In the intro call we establish which requirements apply to your organisation and whether a mandate, the platform or both is the right starting point. Free, 30 minutes, with a Senior CISO.