Strategy & Security Leadership
As your vCISO we develop the security strategy, run risk governance and keep management informed. We keep measures, owners and due dates in one place in OdySecure.
Cybervize fills the CISO role in mid-market companies. We implement NIS-2, DORA or ISO 27001 and keep the evidence for it, from €3,600/month. The OdySecure platform is included in the mandate. If you have your own CISO, you license OdySecure on its own, per module at a fixed annual price.
Book an intro callIn the mandate we fill your CISO function and carry out the implementation, at a fixed monthly price instead of open hour budgets. If you fill the function yourself, you license the OdySecure platform on its own. The areas below apply to both routes.
As your vCISO we develop the security strategy, run risk governance and keep management informed. We keep measures, owners and due dates in one place in OdySecure.
NIS-2 implementation, DORA preparation, ISO 27001 certification readiness, BSI IT-Grundschutz and KRITIS requirements.
Structured cybersecurity assessments with multi-site capability and automated corporate, site and working reports.
Executive trainings on NIS-2 and DORA, awareness programs for staff, phishing simulations as fixed-price packages.
IEC 62443 assessments, OT/IT convergence, third-party risk (TPRM) for manufacturing mid-caps and KRITIS operators.
Cybersecurity due diligence ahead of transactions, post-merger integration and crisis situations such as CISO departure or incident response.
External CISO services come from large consultancies as well as specialist firms, and many offerings are built for enterprise clients. You can put these five questions to any provider, including us.
Ask about mandates in your industry and at companies of your size. A provider who only knows security from large groups brings structures that don't hold up in the mid-market.
NIS-2, DORA or ISO 27001, plus TISAX or IEC 62443 depending on your industry. An external CISO has to know which requirements apply to your organisation and turn them into evidence an assessor accepts.
Mid-market companies need budget certainty. A retainer states the monthly price and scope upfront. Our vCISO packages start at €3,600/month, and the tiers are published on the vCISO page.
Ask what happens in the first weeks. A structured onboarding with a baseline review and prioritised measures shows whether the provider has a way of working or is still inventing one.
Recommendations without a tool deliver little measurable security gain. Measures, owners and evidence belong in a system with an audit trail, across several sites where needed. With us that is OdySecure, included in the mandate.
The vCISO mandate is the direct route. You can commission the other services individually when a specific need arises.
We fill the CISO role, platform included: from €3,600/month, against €135,000 to €200,000 a year in ongoing cost of employment for a full-time hire.
Learn moreThe second route for organisations with their own CISO: ISMS, compliance and evidence on a single data layer. Module-licensed, run by your own IT team.
Learn morePlatform-based assessment per ISO 27001, IEC 62443, NIS-2 and DORA, with multi-site capability.
Learn moreStructured NIS-2 compliance: gap assessment, roadmap and implementation in 12 weeks.
Learn moreSafe AI adoption with governance frameworks and risk assessment for mid-market companies.
Learn moreCybersecurity due diligence before the deal, then post-merger integration or building a standalone ISMS after a carve-out.
Learn moreSelf-check available
Free, no signup, around 5 minutes. Detailed evaluation by email if desired.
Our methodology is the same in the vCISO mandate as on the platform. Add fixed prices, fast availability and an interface that an IT lead with a mixed remit can run on their own.
Pricing depends on the engagement model. Point-in-time assessments and NIS-2 gap analyses typically land in the mid to high four-figure range. Operational engagements like a vCISO from €3,600/month (basic retainer) up to €8,500/month (senior retainer) are the mid-market alternative to a full-time CISO (€135,000 to €200,000 a year fully loaded). Training is offered as fixed-price packages. Important: mid-market consulting should work with clear deliverables and fixed prices, not open T&M hour buckets.
For mid-market companies, a vCISO (Virtual CISO) is usually the more economical choice. A full-time CISO costs €135,000 to €200,000 a year fully loaded and is oversized for 1-2 days/week of actual demand. A vCISO brings several years of information security experience into a 2-6-day-per-month retainer, starts within a few days, and scales with demand. A full-time hire only becomes economical at much larger companies or under high regulatory load (financial services, critical infrastructure).
For a typical mid-market company with one to three sites, realistic timing is 8 to 12 weeks for audit-ready readiness: gap assessment (2 to 3 weeks), prioritised measure roadmap (1 to 2 weeks), quick-wins implementation and documentation (5 to 7 weeks). Prerequisite: management commitment and named contacts from IT, legal and business units. Holding structures with multiple subsidiaries need 16 to 20 weeks. The legally binding compliance statement remains a matter for counsel.
Where no one in-house is named to lead security, the vCISO mandate is the direct route: we fill the CISO function (2 to 6 days/month), carry out the implementation of NIS-2 and ISO 27001 and keep the evidence. The OdySecure platform is included in the mandate. If you have your own CISO, you license OdySecure on its own: an assessment for the baseline, compliance work and evidence on one data layer. Pure advisory mandates without an operational arm tend to leave mid-market clients with stacks of recommendations and no implementation partner, and therefore little measurable security improvement.
Recommended approach: (1) group-wide ISMS umbrella with a unified question catalogue, (2) site-specific assessments via a multi-site platform with a consolidated corporate report, (3) maturity-level differentiation instead of a one-size mandate; IT-heavy subsidiaries and production sites have requirements that differ in kind, (4) central governance with decentralised owner roles through a 4-role model (Admin / Owner / Reviewer / User), (5) board-level corporate report at the push of a button. This keeps compliance auditable without suffocating local sites.
Mid-market doesn't need a scaled-down enterprise template. Key differences: (1) fixed prices and clear deliverables instead of open T&M mandates, (2) operational involvement instead of pure PowerPoint advisory, (3) one person with C-level experience instead of a junior team with senior reviewer, (4) lean tools instead of enterprise GRC suites with six-figure license fees, (5) direct senior consultant access instead of escalation chains. Mid-market companies buy consulting for a concrete outcome, not for a methodology.
The mandatory baseline depends on industry and size: NIS-2 for essential and important entities from 50 employees, or with turnover and balance sheet each above €10m, across 18 sectors, DORA for financial services, TISAX/VDA ISA for automotive suppliers, IEC 62443 for OT-heavy industrial operations, BSI IT-Grundschutz as a pragmatic baseline, ISO 27001 as the internationally recognised ISMS standard. In practice, Cybervize recommends a multi-standard approach with a shared data layer: one answered control catalogue covers several standards in parallel.
Cybervize focuses particularly on manufacturing, financial services, critical infrastructure (KRITIS), telecommunications and mid-market holdings with multiple subsidiaries. The common pattern: high regulatory load (NIS-2, DORA, KRITIS regulation), specialised risk profile (OT/IT convergence, supply chain, M&A) and at the same time security teams too small for full coverage. An external mandate closes the gap between obligation and internal capacity, without expensive in-house headcount expansion.
In an intro call we clarify which requirements apply to your organisation and which route fits: the vCISO mandate from €3,600/month with the platform included, or the platform licence for your own team.
Book an intro callNIS2 is mandatory. Learn how a Virtual CISO systematically guides mid-market companies to NIS2 compliance: in 12 months, with realistic costs, without full-time hiring.
What a vCISO delivers, what it costs, and why mid-market companies need strategic cybersecurity leadership now. Practical guide with 90-day plan, NIS2 context, and selection criteria.
Structured NIS-2 compliance: gap assessment, roadmap, and implementation in 12 weeks.
Learn moreExperienced C-level security leadership, 2 to 6 days a month, with the platform as the working tool.
Learn moreAnalysis of your IT security posture with an actionable roadmap.
Learn moreFive modules, one data layer: ISMS, BCM, assessment, TPRM and awareness. Answers with source and metric.
Learn moreFree self-check: where do you stand on the ten §30 BSIG measures? 30 questions, instant traffic light.
Learn moreThe ten regulated sectors in which we take on the CISO function.
Learn more