CISO as a Service

The Security Director your SME needs, without the annual salary

A senior fractional CISO to design strategy, govern risks, coordinate vendors and report to the board. Expert decisions on a realistic budget.

Strategic security meeting with the management committee
0
Savings vs. in-house CISO
0
Average experience
0
To get started
0
NDA confidentiality
Why a fractional CISO

Expert leadership without full-time commitment

An SME cannot afford €90,000/year for a senior CISO. It also cannot afford not to have one. This is the in-between solution that makes sense.

Clear strategy

Annual security plan with objectives, KPIs and a roadmap prioritised by risk and return. Not a list of random tasks.

Board reporting

Quarterly executive reports in business language. No empty jargon: risk, impact and decision.

Risk management

Asset inventory, risk map, treatment plans and periodic review with real criteria.

Compliance that matters

GDPR, NIS2, ISO 27001, ENS, DORA. Whatever applies to your sector, managed with intelligence and no useless paperwork.

Vendor coordination

Your CISO talks to your MSP, MSSP, lawyers, insurer and external auditor. You just read the summary.

Crisis response

If there is an incident, your CISO is on the front line. Communication, regulators, customers, crisis management. You are not alone.

Executive dashboard

The reporting you will take to the board

Overall maturity, compliance by standard, open risks and pending decisions. Ready to present without translating from IT jargon.

ciso.izuuk.com / executive-board / Q2-2026
Executive board · Q2 2026
For board
78/100
Security maturity
↑ 6 points vs Q1
Regulatory compliance
ISO 27001
85%
ENS High
72%
GDPR
100%
NIS2
64%
DORA
42%
CRIT Missing MFA on privileged access · 4 accounts affected → CTO
HIGH Backup without restore test · >90 days → IT Mgr
HIGH Critical vendor without DPA signed → Legal
MED Continuity plan not updated · Q2 review → COO
MED Awareness training pending · 18% of staff → HR
Service scope

What your fractional CISO takes on

Strategic security plan

12-24 month vision with budget, milestones and KPIs aligned with the business plan.

Risk analysis and management

MAGERIT/ISO 27005 methodology, semi-annual review and treatment plans.

Governance and policies

Definition and maintenance of policies, standards and procedures. Approved with management.

Regulatory compliance

Mapping of applicable obligations, compliance plan and audit-ready evidence.

Vendor risk management

Critical vendor assessment, security clauses in contracts, due diligence.

Awareness and training

Awareness plan for employees with simulated phishing campaigns and training sessions.

Board reporting

Executive scorecard with key metrics, quarterly board presentation.

Crisis leadership

Incident response plan, exercises and executive leadership during real incidents.

How we get started

Your CISO in 30 days

DAY 1 CISO assignment

We introduce the senior CISO assigned to your sector and maturity level. If they do not fit, we change them — no questions asked.

WEEK 1 Immersion and diagnosis

Meetings with management, IT and key areas. Asset inventory, critical systems and regulatory obligations.

WEEK 2-3 Risk analysis

Identification of major risks, valuation and prioritisation. First validation meeting with management.

WEEK 4 Strategic plan

12-month roadmap with quick wins, prioritised investments and KPIs. Approved at the board.

ONGOING Operation and reporting

Recurring agreed dedication (8-60h/month per plan), quarterly reporting, annual plan review.

Who decides today which risks your business takes?

Let's spend 30 minutes on your current situation and see if a fractional CISO makes sense for you.

Book a chat
FAQ

Frequently asked questions about CISO as a Service

The CISO acts as an advisory role with delegated authority. Ultimate legal responsibility always lies with the company's management, but the CISO signs their recommendations, leaves a decision audit trail, and carries professional liability insurance.

Depending on the plan: 8h/month on Advisor, 20h/month on Strategic, up to 60h/month on Embedded. Hours are real senior CISO time — not juniors in disguise.

They work with your team. The CISO sets the what and why; the how is executed by your IT (in-house or managed). Complementary, not a replacement.

Scorecard with KPIs: maturity level (1-5 scale), open vs. closed risks, incidents avoided, regulatory compliance, board satisfaction.