Group-wide ISMS framework
Single platform framework for ISO 27001, NIS-2, DORA and IEC 62443 across all subsidiaries and plants. Consolidated reports at group, site and working level from a single data layer.
Cybervize also fills the CISO role in corporates. We implement NIS-2, DORA, ISO 27001 and IEC 62443 across subsidiaries and plants and keep the evidence. We bill on a project-based daily rate, with the corporate modules of OdySecure. Corporates with their own CISO license the platform on its own, with an onboarding project handed over to their team if they wish.
Book an intro callIn the mandate we fill the CISO function and steer ISMS and compliance across subsidiaries and plants. The OdySecure platform keeps governance, execution and audit trails on one data layer; corporates with their own CISO license it on its own. The areas below apply to both routes.
Single platform framework for ISO 27001, NIS-2, DORA and IEC 62443 across all subsidiaries and plants. Consolidated reports at group, site and working level from a single data layer.
Platform rollout across multiple companies and countries with central governance and decentralised owner roles. DE/EN user interface from module launch, more languages on demand.
Reproducible audit trails for internal audit, external auditors, certification bodies and regulatory reviews. Evidence exportable on demand.
KPI dashboards and on-demand reports in the language of corporate leadership. Maturity heatmaps, risk trends, measure status.
IEC 62443 for plants, OT/IT convergence, third-party risk (TPRM) and supply-chain cybersecurity audits for manufacturing corporates and critical-infrastructure operators.
Cybersecurity due diligence for transactions, post-merger integration, carve-out support and risk mitigation across holding structures.
The vCISO mandate fills the function, OdySecure holds governance and evidence across every company in the group. You can commission the other services individually.
A permanently filled CISO function, platform included. For corporates without an in-house CISO function or with a CISO vacancy. Corporate modules of the platform, project-based daily rate.
Learn moreThe second route for corporates with their own CISO: ISMS, compliance and evidence from a single platform. Multi-entity, multi-country, multilingual, auditor-accepted.
Learn moreMulti-site assessment against ISO 27001, IEC 62443, NIS-2 and DORA with the OdySecure assessment module. Maturity heatmap, plant- and group-level report from a single data layer.
Learn moreStructured NIS-2 implementation: gap assessment, roadmap and implementation across multiple subsidiaries, with consolidated maturity reporting.
Learn moreAdvisory service for corporates with their own AI deployment or AI strategy. ISO/IEC 42001 is available as an activatable standard in OdySecure, and the evidence can be used in supervisory-board reporting.
Learn moreCybersecurity due diligence before the transaction, then building security after an acquisition or from scratch after a carve-out.
Learn moreSelf-check available
Free, no signup, around 5 minutes. Detailed evaluation by email if desired.
Five questions you can put to any provider of external CISO services, including us. They show whether a mandate holds up inside a group or only in the presentation.
Ask where the methodology comes from and who owns it. A control catalogue generated from a standards table does not know the follow-up questions an assessor asks. At Cybervize every mandate is run with the same methodology and evidenced in OdySecure.
Ask about mandates in holding and multi-entity structures and in your industry. An external CISO in a group has to bring central governance and the responsibility within each company together without paralysing the sites.
NIS-2, DORA, ISO 27001, IEC 62443 or TISAX apply differently to the companies in a group. The provider has to know that picture company by company and turn it into one body of evidence.
Check what you are buying: a mandate with a named function and a clear daily rate, or consulting hours with no defined end. We bill corporate mandates per project on a daily rate, with the corporate modules of OdySecure.
Ask to see a piece of evidence the way an assessor receives it: with timestamp, owner and version, for several companies and plants from a single data layer. With us that is OdySecure.
Our corporate mandates follow one methodology, and the same methodology is built into OdySecure, which serves multi-entity corporates and their plants from a single data layer. Corporates without an in-house CISO function fill it with our vCISO; corporates with their own CISO start with the platform and an onboarding project.
In corporates we fill the CISO function as a vCISO mandate at a project-based daily rate. Every mandate follows the same methodology. It is built into OdySecure, the platform our vCISO works with, with multi-entity support and consolidated group reporting.
The platform operates on a 4-role model (admin / owner / reviewer / user) and separates central group governance from decentralised site execution. A single control catalogue serves multiple standards in parallel (ISO 27001, NIS-2, IEC 62443, DORA, TISAX). Reports are generated at three levels: group report for board and supervisory board, site report for local management, working report for operational security leadership. Multilingual user interface (DE/EN) from module launch.
Evidence is built on reproducible audit trails: every control answer, every measure and every piece of evidence is documented with timestamp, owner and versioning. The methodology aligns with ISO 27001, IEC 62443 and BSI IT-Grundschutz. Evidence can be exported from the platform for internal audit, external auditors, certification bodies and regulatory reviews.
Three scenarios are typical: Co-existence: Cybervize as the specialised module for cybersecurity standards, while the existing GRC suite continues to cover enterprise risk management. Gradual replacement: migration over 12 to 18 months with parallel operation and data takeover. Full replacement: for groups looking to modernise their GRC investment and unhappy with licence and implementation costs of the legacy suite. Cybervize supports API integration with existing ITSM and SIEM systems.
The group report delivers on demand: (1) maturity heatmap by site and standard, (2) top-10 risks with mitigation status, (3) measure tracking by owner and due date, (4) compliance status for NIS-2, DORA, ISO 27001 and sector-specific requirements, (5) 12-month trend charts. Format: PDF templates for supervisory-board sessions, interactive dashboard for ongoing oversight. Language: DE/EN. KPI-driven, free of consulting jargon.
Currently supported: ISO 27001:2022, NIS-2 (with sector-specific minimum measures), DORA (financial sector), IEC 62443 (OT and industrial security), TISAX (automotive), BSI IT-Grundschutz, KRITIS regulation, NIST CSF. The underlying architecture works with a shared control mapping: answering a control once applies it to every parallel standard. Extensions follow market demand (Cyber Resilience Act, EU AI Act, NIS-2 sector expansions).
Corporates without their own CISO fill the function through the vCISO mandate: a senior CISO runs the ISMS and the evidence across every company in the group, the OdySecure platform with its corporate modules is included, and billing is on a project-based daily rate. Corporates with their own CISO license the platform on its own, with an onboarding project of 6 to 12 months handed over to your internal team if you wish. If you only need to bridge a vacancy, the Interim CISO is the better fit, with no platform dependency.
Three models. vCISO mandate: we fill the CISO function, the platform is included, billed on a project-based daily rate. Platform licence on its own for organisations with their own CISO: annual licence, scaled by digitally connected people and modules, not by headcount. Interim CISO for vacancies: typically €8,000 to €15,000 a month, project-based, no platform dependency. Entry prices are on the pricing page; the corporate quote is calculated per project and under NDA.
In an intro call we clarify which requirements apply across your companies and which route fits: the vCISO mandate, or the platform licence with an onboarding project. If you wish, we show OdySecure against your group setup.
Book an intro callNIS2 is mandatory. Learn how a Virtual CISO systematically guides mid-market companies to NIS2 compliance: in 12 months, with realistic costs, without full-time hiring.
What a vCISO delivers, what it costs, and why mid-market companies need strategic cybersecurity leadership now. Practical guide with 90-day plan, NIS2 context, and selection criteria.
Experienced C-level security leadership, 2 to 6 days a month, with the platform as the working tool.
Learn moreImmediate security expertise for transition phases and critical projects.
Learn moreAnalysis of your IT security posture with an actionable roadmap.
Learn more