OdySecure, the security platform by Cybervize, with a virtual CISO bookable as an add-on: your outsourced CISO on a retainer permanently fills the security function. For mid-market and corporates, without a full-time CISO hire.
Schedule vCISO Consultation NowCybervize's Virtual CISO, often called an outsourced or external CISO, staffs the security function permanently: a senior CISO on retainer, bookable as an add-on to OdySecure. Mid-market companies without an in-house CISO take the function from €3,600/month. Corporates use the same path with a project-based daily rate and the corporate modules of the platform. Both get the same solution at the level of expansion that fits them.
How the CISO role differs from the operational security officer is covered in our article on the difference between a CISO and an ISO.
The OdySecure Navigator works inside the platform: information around the clock, from your real data, with source and metric, read-only. The human vCISO sits above that layer: judgement, prioritization, decisions, accountability, audit and crisis leadership. The assistant makes your vCISO faster; it does not replace them.
The assistant answers "where do we stand". The vCISO answers "what do we do now and who is accountable".
Our vCISO service combines human expertise with intelligent automation. An experienced cybersecurity expert takes over the strategic management of your security measures, while OdySecure automates risk assessments, compliance checks, and the generation of appropriate measures. This means for you: Maximum security with minimal effort.
| Criterion | vCISO | Full-time CISO | IT Manager |
|---|---|---|---|
| Cost per year | From €43,200 (€3,600/month) | €135,000 to €200,000 cost of employment | €110,000 to €160,000 cost of employment |
| Flexibility | |||
| Expertise Level | Enterprise-Grade | Varies | Basic |
| Availability | As needed | Full-time | Full-time |
| Industry Experience | Cross-industry | Limited | Limited |
Ongoing employer cost of employment in the mid-market, as of 2026: base salary plus employer contributions, workplace and training. Within that, a CISO base salary sits at 110,000 to 160,000 EUR and an IT lead at 85,000 to 125,000 EUR (sources: Hays IT salary report 2025, StepStone, Robert Half 2026). In the first year, recruitment costs of 25 to 33 % of target annual salary are added (BDU 2024: 27.5 %). Large enterprises and highly regulated sectors sit above these figures.
Services (about 2 days, up to 16 hours per month):
Goal:
Basic assumption of the CISO function with continuous security management. Ideal for companies that want to take the first step towards a fully integrated Virtual CISO.
Services (about 3 days, up to 24 hours per month):
Goal:
More comprehensive, intensive support of the Virtual CISO function with a quantitative increase in supported hours. Designed for companies that need deeper strategic integration and operational control.
Services (5 to 6 days, up to 48 hours per month):
Goal:
Comprehensive and customized assumption of the CISO function for companies with the highest security requirements and complex challenges. Offers maximum flexibility and individual adaptation.
Cybervize offers vCISO packages from €3,600/month (basic retainer with about 2 days per month) up to roughly €8,500/month (senior retainer with 5-6 days per month). Hourly rates for spot engagements run €200-350/hour. For context: published retainers for external CISO and ISO mandates in the DACH region range from under €1,000/month for narrow ISO packages to around €8,000/month for full vCISO mandates; typical day rates for senior security advisory sit at €1,600 to €2,500 (own survey of public price lists, August 2026). Our pricing is transparent. The full cost comparison is in the post Virtual CISO costs.
For an example scenario at roughly 200 employees the standard package at €4,900/month is usually the fit. It covers the CISO time, access to the OdySecure security platform with ISMS, assessment, BCM and TPRM, a monthly steering call with management, a quarterly risk report and incident-response readiness. Compared to a full-time CISO at €135,000 to €200,000 annual cost of employment, the vCISO retainer at €58,800/year is well under half the cost, without losing C-level cybersecurity leadership. Detailed calculation is in the pricing pillar post.
Smaller and mid-market companies have four lower-cost alternatives to a full-time CISO: (1) vCISO (Virtual CISO), external CISO on retainer, from €3,600/month; (2) Fractional CISO, partial CISO function, often 1-2 days per month; (3) Interim CISO, temporary full-time coverage during vacancies; (4) CISO-as-a-service platform like Cybervize, which combines human advisory with ISMS tooling. For most SMEs the vCISO model is the most cost-effective alternative: you get C-level cybersecurity leadership without the €150,000+/year fixed cost of a permanent CISO.
CISO (Chief Information Security Officer) is the strategic cybersecurity leadership role at C-level, traditionally as a permanent hire. vCISO (Virtual CISO) is the same role delivered as an external, flexible service on a retainer, typically remote, often cross-industry. ISO (Information Security Officer / Informationssicherheitsbeauftragter in German) is the operational role under BSI-IT-Grundschutz and ISO 27001, usually one level below the CISO and more focused on implementation than on strategy. Cybervize delivers both vCISO and ISO/ISB mandates depending on the depth of responsibility you need.
The vCISO service is particularly suitable for medium-sized companies that need cybersecurity expertise at C-level but don't want to finance a full-time position. The service is also ideal for companies in growth phases or with temporary increased security needs.
The AI platform complements human expertise by performing automated risk assessments, monitoring compliance requirements, and generating action proposals. It serves as a central dashboard for all security aspects of your company.
Our vCISO service typically starts within the first week after contract signature. After a structured onboarding with baseline assessment, measures are prioritised and the platform is configured to your requirements.
We have experience in numerous industries, including financial services, healthcare, manufacturing, public sector, and technology companies. Our expertise covers industry-specific security requirements and compliance regulations.
A full-time CISO is a permanent position with annual salaries starting at 150,000 EUR plus overhead. A vCISO (Virtual CISO) provides the same strategic cybersecurity leadership at C-level, but as a flexible, external service. You get an experienced CISO on demand who manages your security strategy without the fixed costs of a permanent hire. This makes it the cost-effective alternative, especially for mid-market companies.
An external CISO brings cross-industry experience from numerous companies and is immediately available without lengthy recruitment. As an external leader, they act independently and objectively in security assessments and audits. Especially during vacancies, while searching for a permanent CISO, or when facing urgent compliance requirements like NIS-2 or ISO 27001, an external CISO is the fastest solution.
Yes. The vCISO is not limited to mid-market. Corporates use the same path: permanent CISO function on OdySecure, senior CISO retainer bookable as an add-on. What changes is the level of expansion: corporate modules of the platform (multi-entity rollout, auditor-accepted group reporting, multi-country) and a project-based daily rate instead of the €/month retainer. If you only need to bridge a short-term vacancy, Interim CISO is the right line, not vCISO.
The vCISO is a permanent staffing of the security function on the platform, senior CISO retainer bookable as an add-on: ongoing, on a monthly cadence, integrated for the long term. The Interim CISO is a short-term bridge across a specific vacancy or crisis (CISO departure, audit preparation, post-incident stabilisation), project-based, usually without the platform, no lock-in. Both lines are standalone: you can start with Interim CISO and switch to vCISO later, or book vCISO directly.
Secure enterprise-level cybersecurity expertise now at a fraction of the cost of a full-time CISO.
Schedule a consultation nowWhat a vCISO delivers, what it costs, and why mid-market companies need strategic cybersecurity leadership now. Practical guide with 90-day plan, NIS2 context, and selection criteria.
NIS2 is mandatory. Learn how a Virtual CISO systematically guides mid-market companies to NIS2 compliance: in 12 months, with realistic costs, without full-time hiring.
Virtual CISO, Interim CISO, or Full-Time CISO? Detailed comparison with costs, availability, capabilities, and a clear decision matrix for every company.
Five modules, one data layer: ISMS, BCM, assessment, TPRM and awareness. Answers with source and metric.
Learn moreImmediate security expertise for transition phases and critical projects.
Learn moreStrategy, compliance and operational security for mid-market companies.
Learn more