External CISO/ISO and security governance for financial institutions
ICT and cyber security have become a supervisory duty of the management body. DORA places ultimate responsibility for the ICT risk framework on the management body, FINMA holds the board and senior management accountable for operational risk and operational resilience. You need defined roles, robust governance, a policy set and regular board reporting. SIDD delivers exactly that as an external CISO/ISO, audit-ready and independent.
vCISO / external ISOFINMA · DORA governanceDE · FR · EN
For banks, insurers, securities firms, FinTechs, asset managers and their critical IT providers
vCISO / external ISO
defined role
FINMA & DORA
management-body duties
Policies & reporting
audit-ready
KPI / KRI
Board-ready
CH · EU
multilingual DE/FR/EN
Responsible for this mandate
Philipp Staiger
M.Sc., MIT Sloan Fellow · Lead Auditor ISO 27001 (BSI)
Leads ISO 27001 and ISMS projects in healthcare from the scope workshop to stage-2 audit support, the interface to management, IT, data protection and the external certification body.
Security governance has become a board responsibility
On ICT and cyber risk the supervisor no longer addresses IT alone, but the management body itself. DORA and FINMA anchor responsibility where strategic decisions are made.
DORA expressly places ultimate responsibility for the ICT risk framework on the management body. The management body approves the ICT risk strategy, controls its implementation and must keep its knowledge continuously up to date. Responsibility cannot be fully delegated, it stays with the body at the top. For Swiss institutions DORA usually does not apply directly, but often indirectly, for example via EU branches and subsidiaries or via contracts with EU-regulated financial entities. Whether DORA applies directly or indirectly we verify per institution case by case.
FINMA anchors the same principle from a supervisory angle. FINMA Circular 2023/01 on operational risks and resilience for banks is in force and applies to FINMA-supervised institutions. It expects the board and senior management to steer operational risks and operational resilience, which includes ICT risks, cyber risks and the management of critical business processes. The supervisor wants to see that the top body has oversight and decides on the basis of robust information.
In practice this means: you need a clearly assigned security role, a governance model with defined responsibilities, a maintained policy set and reporting that gives the board an understandable and audit-ready picture of the security posture. These are exactly the building blocks many institutions lack, or they are scattered and hard to evidence in a supervisory dialogue.
A clearly assigned security role (CISO or ISO) with a mandate and an escalation path to the management body
A governance model with defined responsibilities across the three lines of defence
A maintained policy set for information security, ICT risk and cyber
KPIs and KRIs that make the security posture measurable and reflect the risk-appetite level
Regular, board-ready reporting to the board and senior management
Regulator-facing documentation that holds up in the FINMA dialogue and in internal audit
How we deliver your security governance
You get a staffed security role and a governance scaffold that makes the management body's responsibility visible and audit-ready. Our advice stays independent because we do not sell an in-house SOC.
We take on the mandate as an external CISO or information-security officer (ISO). You get a named, reachable person with a clear remit, defined response times and a fixed reporting line to the management body. The vCISO works closely with your IT, your risk and compliance functions and internal audit, and fills the security role without you having to build a full-time position straight away.
We build a security-governance framework that fits FINMA and DORA. This includes the role-and-responsibility model across the three lines of defence, a policy set for information security, ICT risk and cyber, and the linkage with your ICT risk management and your third-party management. We align the framework with recognised standards such as ISO 27001 so that governance and a later ISMS share the same foundation.
We define KPIs and KRIs that make the security posture measurable and set up a reporting cadence. The board receives an understandable dashboard with risk posture, open measures, incidents and trends, complemented by the regulatory-relevant points. This lets the management body exercise its supervisory duty and base its decisions on robust information rather than on hearsay.
We maintain all evidence in the Priverion Platform: policies, roles, risks, measures, KPI/KRI and board reports sit versioned in one place and are exportable. When internal audit or FINMA asks, the governance is evidenced, current and audit-ready. For purely operational services such as 24/7 monitoring or managed incident response we coordinate specialised partners when needed, which keeps our recommendations independent.
Why SIDD for your security governance
Board reporting on ICT and cyber risk combines law, supervision and technology. We cover exactly that combination from one partner, multilingual and independent.
Law, supervision and security from one partner
FINMA and DORA duties are classified by doctorate-level lawyers, the security role and the technical measures are led by an in-house technical team under an ISO 27001 Lead Auditor. So governance, policies and reporting hold up legally and technically at once.
A staffed security role
You get a named external CISO or ISO with a clear mandate, fixed response times and a reporting line to the management body. The supervisor expects an assigned, reachable role, and that is exactly what we provide, without you having to build a full-time position straight away.
Board-ready reporting
We translate the security posture into an understandable picture for the board and senior management: KPIs, KRIs, open measures, incidents and trends. So the body can exercise its supervisory duty under FINMA and DORA and evidence its decisions.
Audit-ready evidence in tooling
We maintain policies, roles, risks, measures, KPI/KRI and board reports versioned in the Priverion Platform. If internal audit or FINMA asks, the governance is available as maintained, exportable tooling.
Independent, no in-house SOC
We do not sell an in-house SOC or managed incident response. That keeps our recommendations on measures, tools and partners independent. Operational services such as 24/7 monitoring or live incident response we coordinate with specialised providers when needed.
Multilingual for CH and EU
We run governance, policies and board reporting in German, French and English, fitting institutions with sites or supervision in Switzerland and the EU. So the reporting speaks the same language as your board and your supervisor.
Two routes to audit-ready security governance
Governance setup & board reporting
Fixed fee
The one-off build of your security governance, ready to present to the board and in the FINMA dialogue.
Role-and-responsibility model across the three lines of defence, aligned to FINMA and DORA
Policy set for information security, ICT risk and cyber, aligned to ISO 27001
Definition of KPIs and KRIs with thresholds and a link to risk appetite
Board-reporting template and reporting cadence for the board and senior management
Regulator-facing documentation, versioned in the Priverion Platform
The ongoing operation: a named security role that maintains the governance, briefs the board regularly and is reachable in the supervisory dialogue.
External CISO or information-security officer with a clear mandate and a reporting line to the management body
Ongoing maintenance of policies, risks, measures and KPI/KRI in the Priverion Platform
Regular board reporting in DE, FR or EN, aligned to your meeting cadence
Linkage with ICT risk management, third-party management and internal audit
Point of contact in the FINMA dialogue and for internal-audit questions
LexCMD
Our tool: LexCommand
Why we work with LexCommand, our own Swiss legal AI
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
01
Sovereign in Switzerland
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
02
No citation, no claim
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
03
From effort to judgement
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
04
Three disciplines, one picture
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For your governance and board reporting, concretely: LexCommand mirrors the responsibilities from DORA, FINMA Circular 2023/01, ISO 27001 and NIS2 against each other in one crosswalk and drafts policies and board templates as Word documents, every statement with a source from the primary text.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
Frequently asked questions
What is the difference between a CISO and an ISO?
The terms overlap. A CISO (Chief Information Security Officer) is responsible for information security at leadership level, an ISO (information-security officer) is the equivalent role. What matters is not the title but the mandate: an assigned, reachable person with a clear remit and a reporting line to the management body. We fill the role so that it fits your size and supervision.
Can an external CISO replace the management body's responsibility?
No. DORA places ultimate responsibility for the ICT risk framework on the management body, and FINMA holds the board and senior management accountable for operational risk and resilience. This responsibility cannot be outsourced. An external CISO relieves the body operationally, prepares decisions and delivers the reporting with which the management body can exercise its supervisory duty. Ultimate responsibility stays with the board.
Does DORA apply to our Swiss institution?
For Swiss institutions DORA usually does not apply directly. It often takes effect indirectly, for example via EU branches and subsidiaries or via contracts with EU-regulated financial entities that pass DORA requirements down contractually. Whether and how DORA affects you we verify case by case. Independently of that, FINMA Circular 2023/01 on operational risks and resilience addresses the same governance expectations, and it applies to FINMA-supervised institutions.
How often should the board receive a security report?
There is no fixed rule, a regular cadence is common, for example quarterly, complemented by event-driven reports for material incidents or risks. We align the cadence with your meeting rhythms and your risk profile and fix it in the governance. What matters is that the reporting is consistent, board-ready and audit-ready, so the management body always has an evidenced overview.
Do you run a SOC or 24/7 incident response?
No. SIDD is a legally led governance, compliance and security advisory partner. We do not run an in-house SOC, no managed or live incident response and no internal red team. Pentests and vulnerability scans are part of our scope. Purely operational services such as 24/7 monitoring or live incident response we coordinate with specialised partners when needed, which keeps our advice independent.
Do you work in French and English?
Yes. We run governance, policies and board reporting throughout in German, French and English, relevant for institutions with sites or supervision in Switzerland and the EU. So the reporting speaks the same language as your board and your supervisor.
Matching next steps
Your security governance ties closely to the security role, the ISMS and ICT risk management:
We staff the security role as an external CISO/ISO, build the governance framework and deliver board-ready reporting that meets your management body's responsibility under FINMA and DORA.