Cybervize fills the CISO role in your organisation. We implement whatever applies to you, whether NIS-2, DORA or ISO 27001, and keep the evidence for it, from €3,600/month. The work runs on our security platform OdySecure, which is included in the mandate.
Schedule vCISO Consultation NowVirtual CISO (vCISO) and external or outsourced CISO name the same service: the CISO function is filled from outside rather than by an in-house hire. Our vCISO delivers a result: a security function that is filled and requirements that are demonstrably met. We steer the implementation and are still there at the next audit. Mid-market companies without an in-house CISO get the function from €3,600/month. For corporates we bill on a project basis at a daily rate, with the corporate modules of OdySecure.
How the CISO role differs from the operational security officer is covered in our article on the difference between a CISO and an ISO.
Organisations need a CISO function for different reasons. The situation decides which route fits.
NIS-2, DORA, ISO 27001 or a customer audit call for measures, clear responsibilities and evidence that holds up. That is what the vCISO is for: ongoing, from €3,600/month.
See the vCISO packagesYour CISO is leaving, the successor is not yet in place, or an implementation project needs leadership for a limited period. That is the job of the Interim CISO, billed on a project basis.
Go to Interim CISOAfter closing, the acquired company often has no named security function. After a carve-out, the new entity needs its own ISMS before the Transitional Service Agreement expires. We fill the function and build up security.
Go to M&A supportAn experienced CISO takes over the steering of your information security and reports to management. Risks, measures and evidence are kept in OdySecure, so the current status can be checked at any time.
In German organisations the operational role is often called Informationssicherheitsbeauftragter (ISB), the information security officer. The ISB keeps processes running and the evidence complete. The CISO sets priorities, reports to management and prepares its decisions.
In the vCISO mandate we fill the CISO function. If your company has an ISB, we work with them: they stay in charge of day-to-day operations, we steer and report. If the role is vacant, we agree in the initial call who takes it on. CISO and ISB compared
The vCISO leads the implementation and keeps management informed throughout. Duties and accountability remain with the organisation and its management. For entities under NIS-2, management's duty is set out in § 38 BSIG: it must implement the risk management measures and oversee their implementation.
The OdySecure Navigator works inside the platform: information from your real data, with source and metric, read-only. The human vCISO sits above that layer: judgement, prioritization, decision papers for management, audit and crisis leadership. The assistant makes your vCISO faster; it does not replace them.
The assistant answers "where do we stand". The vCISO answers "what do we do now and who does it".
| Criterion | vCISO | Full-time CISO | IT Manager |
|---|---|---|---|
| Cost per year | From €43,200 (€3,600/month) | €135,000 to €200,000 cost of employment | €110,000 to €160,000 cost of employment |
| Flexibility | |||
| Expertise Level | Enterprise-Grade | Varies | Basic |
| Availability | As needed | Full-time | Full-time |
| Industry Experience | Cross-industry | Limited | Limited |
Ongoing employer cost of employment in the mid-market, as of 2026: base salary plus employer contributions, workplace and training. Within that, a CISO base salary sits at 110,000 to 160,000 EUR and an IT lead at 85,000 to 125,000 EUR (sources: Hays IT salary report 2025, StepStone, Robert Half 2026). In the first year, recruitment costs of 25 to 33 % of target annual salary are added (BDU 2024: 27.5 %). Large enterprises and highly regulated sectors sit above these figures.
Services (about 2 days, up to 16 hours per month):
Goal:
Basic assumption of the CISO function with continuous security management. Ideal for companies that want to take the first step towards a fully integrated Virtual CISO.
Services (about 3 days, up to 24 hours per month):
Goal:
Broader, more intensive support of the Virtual CISO function with a quantitative increase in supported hours. Designed for companies that need deeper strategic integration and operational control.
Services (5 to 6 days, up to 48 hours per month):
Goal:
Full and customized assumption of the CISO function for companies with the highest security requirements and complex challenges. Offers maximum flexibility and individual adaptation.
We fill the CISO function from our own audit and implementation practice.
Five questions any provider should be able to answer.
A vCISO (Virtual CISO) is an external Chief Information Security Officer who fills a company's CISO function on a mandate instead of as a full-time hire. At Cybervize the mandate is ongoing, covers two to six days a month and starts at €3,600/month, with the OdySecure platform included. The vCISO carries out the security work and keeps management informed on an ongoing basis. Duties and accountability stay with your company and its management.
Cybervize offers vCISO packages from €3,600/month (basic retainer with about 2 days per month) up to roughly €8,500/month (senior retainer with 5-6 days per month). Hourly rates for spot engagements run €200-350/hour. Published retainers for external CISO and ISO mandates in the DACH region range from under €1,000/month for narrow ISO packages to around €8,000/month for full vCISO mandates; typical day rates for senior security advisory sit at €1,600 to €2,500 (own survey of public price lists, August 2026). Our pricing is transparent. The full cost comparison is in the post Virtual CISO costs.
For an example scenario at roughly 200 employees the standard package at €4,900/month is usually the fit. It covers two C-level meetings per month, two brief alignment meetings per week, weekly reports via dashboard or email, building and maintaining a compliance catalogue, and access to the OdySecure security platform. Compared to a full-time CISO at €135,000 to €200,000 annual cost of employment, the vCISO retainer at €58,800/year is well under half the cost, without losing C-level cybersecurity leadership. Detailed calculation is in the pricing pillar post.
Smaller and mid-market companies have four lower-cost alternatives to a full-time CISO: (1) vCISO (Virtual CISO), external CISO on retainer, from €3,600/month; (2) Fractional CISO, partial CISO function, often 1-2 days per month; (3) Interim CISO, temporary full-time coverage during vacancies; (4) vCISO with its own ISMS platform, which is how Cybervize works: the OdySecure platform is part of the mandate and the evidence is built there. For most SMEs the vCISO model is the most cost-effective alternative: you get C-level cybersecurity leadership without the €135,000 to €200,000 annual cost of employment of a permanent CISO.
CISO (Chief Information Security Officer) is the strategic cybersecurity leadership role at C-level, traditionally as a permanent hire. vCISO (Virtual CISO) is the same role delivered as an external, flexible service on a retainer, typically remote, often cross-industry. ISO (Information Security Officer / Informationssicherheitsbeauftragter in German) is the operational role under BSI-IT-Grundschutz and ISO 27001, usually one level below the CISO and more focused on implementation than on strategy. Cybervize delivers both vCISO and ISO/ISB mandates depending on the scope you need.
The vCISO service is particularly suitable for medium-sized companies that need cybersecurity expertise at C-level but don't want to finance a full-time position. The service is also ideal for companies in growth phases or with temporary increased security needs.
Access to the OdySecure platform is part of the mandate, with no separate licence to pay. The platform supports your vCISO's work: it assists with risk assessments, keeps track of compliance requirements and proposes measures. Your vCISO uses it to steer the ISMS and the reporting to management.
Our vCISO service typically starts within the first week after contract signature. After a structured onboarding with baseline assessment, measures are prioritised and the platform is configured to your requirements.
We have experience in numerous industries, including financial services, healthcare, manufacturing, public sector, and technology companies. Our expertise covers industry-specific security requirements and compliance regulations.
A full-time CISO is a permanent position with an ongoing cost of employment of €135,000 to €200,000 per year. A vCISO (Virtual CISO) provides the same strategic cybersecurity leadership at C-level, but as a flexible, external service. You get an experienced CISO on demand who manages your security strategy without the fixed costs of a permanent hire. This makes it the cost-effective alternative, especially for mid-market companies.
An external CISO brings cross-industry experience from numerous companies and is immediately available without lengthy recruitment. As an external leader, they act independently and objectively in security assessments and audits. Especially during vacancies, while searching for a permanent CISO, or when facing urgent compliance requirements like NIS-2 or ISO 27001, an external CISO is the fastest solution.
Yes. The vCISO is not limited to mid-market. Corporates use the same mandate: we fill the CISO function on a permanent basis, with the OdySecure platform included. What changes is the scope: corporate modules of the platform (multi-entity rollout, auditor-accepted group reporting, multi-country) and a project-based daily rate instead of the €/month retainer. If you only need to bridge a short-term vacancy, Interim CISO is the right choice, not vCISO.
The vCISO is a permanent mandate: we fill your CISO function on an ongoing monthly basis, with the OdySecure platform included in the mandate. The Interim CISO is a short-term bridge across a specific vacancy or crisis (CISO departure, audit preparation, post-incident stabilisation), project-based, usually without the platform, no lock-in. Both lines are standalone: you can start with Interim CISO and switch to vCISO later, or book vCISO directly.
We fill your CISO function from €3,600/month. OdySecure is included in the mandate.
Schedule a consultation nowWhat a vCISO delivers, what it costs, and why mid-market companies need strategic cybersecurity leadership now. Practical guide with 90-day plan, NIS2 context, and selection criteria.
NIS2 is mandatory. Learn how a Virtual CISO systematically guides mid-market companies to NIS2 compliance: in 12 months, with realistic costs, without full-time hiring.
Virtual CISO, Interim CISO, or Full-Time CISO? Detailed comparison with costs, availability, capabilities, and a clear decision matrix for every company.
Five modules, one data layer: ISMS, BCM, assessment, TPRM and awareness. Answers with source and metric.
Learn moreImmediate security expertise for transition phases and critical projects.
Learn moreStrategy, compliance and operational security for mid-market companies.
Learn more