Information Security Officer (ISB) as a Service

6 min readLast updated By Oliver Stutz

Introduction

The Information Security Officer (ISB) is the central operational role in any organisation's cyber governance. While the executive board defines the risk appetite and IT runs the systems, the ISB is the bridge: they translate regulatory requirements (ISO 27001, FINMA Circular 2023/1, ISG, NIS2, DORA) into documented processes, coordinate controls and deliver the evidence that auditors and supervisors expect to see. In Switzerland, demand for ISB as a Service (ISB-aaS) has visibly grown since the Information Security Act (ISG) came into force on 1 January 2024 and the BACS reporting duty went live on 1 January 2025.

This article clarifies the role and explains when an external ISB makes more sense than an internal one. What you will take away:

  • the typical duties of an ISB and how they differ from a CISO and a DPO;
  • the legal anchors (ISG, FINMA, ISO 27001 Clause 5.3) for the ISB function;
  • pros and cons of internal vs external;
  • typical mandate models and effort ranges;
  • selection criteria for an ISB service provider.

The article is aimed at managing directors, IT leaders and board members of Swiss SMEs, hospitals, municipalities and utilities facing the question: do I hire a full-time ISB, or do I engage an external provider?

What an ISB actually does

An ISB's duties can be organised along the Plan-Do-Check-Act cycle that underpins the ISMS in ISO/IEC 27001:2022:

  • Plan: maintain the risk register under ISO/IEC 27005, run protection-needs analyses, update the information security policy, maintain the Statement of Applicability;
  • Do: coordinate the implementation of Annex A controls (e.g. access management A.5.15, cryptography A.8.24, supplier management A.5.19–A.5.22), run the awareness programme A.6.3, accompany IT projects as the security stakeholder;
  • Check: conduct internal audits (Clause 9.2 ISO 27001), management reviews (Clause 9.3), KPI reporting to the executive board, prepare external audits;
  • Act: handle non-conformities (Clause 10.2), capture lessons learned from incidents, drive continuous improvement of the ISMS.

On top of that comes the operational crisis role: in a cyber incident, the ISB is the single point of contact for internal escalation, IT forensics, external notifications to BACS (24 hours under Art. 74a ff. ISG) and, if personal data are affected, the interface to the DPO for the FDPIC/EDÖB notification under Art. 24 DSG. For banks, FINMA Supervisory Notice 05/2020 adds a 24-hour notification duty.

ISB vs CISO, where the line runs

International literature often uses the terms interchangeably; in Swiss practice they are functionally distinct. The CISO (Chief Information Security Officer) is strategic and usually C-level adjacent: they own the security budget, the strategy and reporting to the board and audit committee. The ISB is the operational hand that translates this strategy into daily processes.

In SMEs up to around 200 employees the distinction is artificial, there, the ISB is effectively also the CISO. Above roughly 500 employees, or in a regulated environment (bank, insurer, hospital, energy utility), the split is worth making, because the strategic reporting duty to the board (FINMA Circular 2023/1 mn. 8) demands a seniority different from operational ISMS management.

Organisational placement is critical: the ISB must not report into IT leadership, because that creates a conflict of interest (the controller controls themselves). Recommendation: the ISB reports directly to the executive board or to the CISO, who in turn reports to the board. Clause 5.3 ISO/IEC 27001:2022 explicitly requires «assigned responsibility and authority», which includes a corresponding hierarchical placement.

In SIDD mandates we take on either both roles or only the external ISB/CISO, depending on size, see Sections 5 and 6 for the models.

Legal basis of the ISB role

Unlike the DSB under Art. 10 DSG, the ISB is not explicitly named in Swiss law, with one exception: in the federal administration, the function is anchored in Art. 83 ff. of the Information Security Ordinance (ISV). For the private sector, the ISB duty arises indirectly from several sources:

  • ISO/IEC 27001:2022 Clause 5.3 requires assigned security responsibility, anyone seeking certification needs an ISB function;
  • FINMA Circular 2023/1 mn. 27 ff. requires banks to have a dedicated ICT security function reporting independently of IT leadership;
  • Art. 8 DSG / Art. 32 GDPR require «adequate technical and organisational measures», the executive board cannot evidence these without a dedicated function;
  • Art. 21(2) NIS2 does not name the ISB function explicitly but requires governance structures, training of management bodies (Art. 20 NIS2) and personal liability of the executive board;
  • DORA Art. 5 requires financial entities to have a documented ICT risk-management framework under the responsibility of the management body.

In practice, any mid-sized Swiss organisation that processes personal data at scale or operates under regulatory requirements should have a named ISB function, internal or external.

When ISB-aaS pays off

An external ISB is not the right choice for every organisation. Rule of thumb: up to around 500 employees, or as long as the role does not reach full-time utilisation, ISB-aaS is regularly more economical and qualitatively better. Four typical scenarios:

  1. SME with 50–500 employees without full-time need: an internal ISB would only be 30–50% utilised and would have to fill the rest with IT operations or compliance, leading to the conflict of interest mentioned above.
  2. Acute certification phase (e.g. ISO 27001 build over 9–12 months): peak demand is high, and afterwards the load drops to 20–30% of original effort. An external ISB scales flexibly with that curve.
  3. Specialist know-how for FINMA, DORA, NIS2 or ISG, which is rarely available internally, an external ISB team brings experience from 30–50 comparable mandates.
  4. Transition phase after the departure of the previous ISB: 3–6 months of interim ISB bridge the gap and support the recruitment of a successor.

When ISB-aaS is not the right choice: large groups above roughly 1,000 employees, organisations with deeply integrated security engineering teams (in-house SOC, in-house red team), and government bodies with classification tiers that exclude external mandates.

Typical mandate models and effort

Three models have established themselves in Swiss ISB-aaS mandates:

  • Retainer model (standard): 8–32 hours per month at a fixed rate, with an annual activities plan (ISMS reviews, internal audit, risk refresh, awareness campaign, penetration tests, supplier audits). Suited to SMEs with an established ISMS.
  • Project plus retainer: initial build phase (e.g. ISO 27001 implementation) in project mode with 40–80 days over 9–12 months, then transition into a retainer at 1–2 days per month. Common for organisations without an existing ISMS.
  • Interim model: 2–5 days per week for 3–9 months, until an internal successor has been found and onboarded. Higher day rates, but a defined end date.

Effort rule of thumb: for an SME with 100 employees without special regulation, 8–12 hours of ISB per month are realistic once the ISMS is in place. In regulated industries (bank, hospital, energy utility), the need doubles because additional audits, reporting duties and supervisory dialogue come on top.

Important: the mandate contract should regulate organisational integration (reporting line, escalation, deputy arrangements for incidents), response times (e.g. within 4 hours for critical incidents) and rights of access to systems and documentation. A confidentiality agreement is standard.

Selection criteria for an ISB provider

Not every IT consultant is an ISB. The following criteria are sound in Swiss market practice:

  • Consultant certifications: ISO 27001 Lead Implementer or Lead Auditor, CISM, CISSP, as a minimum standard. For FINMA mandates, additional experience with banking or insurance regulation.
  • Reference mandates in a comparable industry and size (named with consent or described anonymously).
  • Industry fit: a hospital ISB needs different experience from a bank ISB. Ask for specific projects in your sector.
  • Independence: a provider who simultaneously runs your IT and supplies your ISB has a structural conflict of interest, which any ISO audit will flag.
  • Insurance cover: professional liability insurance with an adequate sum insured (at least CHF 5 million).
  • Provider's own security maturity: an ISB provider without a documented ISMS of its own is disqualified.
  • Availability: defined response times and deputisation for holidays, illness, departure.

Avoid providers who offer a flat-rate quote without prior assessment. A serious ISB-aaS provider first runs a short situational assessment (1–2 days) before committing to an effort estimate.

How SIDD supports you

SIDD provides certified Information Security Officers as a service, individually or as a team, to Swiss SMEs, hospitals, municipalities, utilities and financial services. Our consultants bring 10 to 20 years of experience in ISO 27001, FINMA, DORA, NIS2 and ISG and hold Lead Implementer and Lead Auditor certifications. They take on the function from day one and ensure the required organisational independence from IT.

Our mandates combine the ISB function with hands-on services from one source: external CISO/ISB, ISMS build through to ISO 27001 certification, regular penetration tests and vulnerability scans, and awareness workshops.

If you are evaluating whether an external ISB fits your organisation, request a non-binding quote or contact us via the contact form. In a 30-minute initial call we will clarify your situation, the realistic effort and the mandate model that fits.

Need help putting this into practice? SIDD operates the matching service.
See service →

Information Security Officer (ISB) as a Service

INSIGHT

InfoSec
24 May 2026
Oliver Stutz
Information security officer as a service: what the role involves, how it differs from a CISO, legal bases, engagement models and selection criteria.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.