CISO as a Service · vCISO · ISB/ISO · NIS2-ready

External CISO · Enterprise-Grade Security Without the Full-Time Hire

A full-time CISO costs CHF 180,000–250,000/year. Our mandate starts at CHF 30,000, with ISO 27001 Lead Auditor expertise most internal teams don't have.

  • ISO 27001 Lead Auditor certified
  • Mandate active within 5 business days
  • Experience across finance, healthcare and industrial sectors
External CISO / ISO as a service for SMEs
Lead Auditor ISO 27001 (BSI)
Swiss provider, Zurich
Fixed fee
Free 30-min consultation
Quote within 24h
Active since 2017

Working for regulated industries and SMEs

CIPP/E · CIPM IAPP certified
ISO 27001 Lead Auditor (BSI)
Aligned with the FDPIC Revised FADP · Art. 10
HQ Baar, ZG Swiss brand
CH · EU · UK · US Mandates worldwide

Cost comparison

Full-time CISO: CHF 200,000+/year. Our mandate: from CHF 30,000.

You need us if any of these apply:

  • You process sensitive customer data and carry the liability
  • A customer, insurer or regulator requires ISO 27001 evidence
  • You have no internal security resource, and don't want to hire one
  • A cyber incident would materially disrupt your operations

Is your company prepared? Book a 30-min consultation now →

Philipp Staiger

Responsible for this mandate

Philipp Staiger

M.Sc., MIT Sloan Fellow · Lead Auditor ISO 27001 (BSI)

Manages fractional CISO mandates for Swiss SMEs and regulated mid-sized companies. Reports directly to executive management and the board of directors, while also supporting the ISMS in line with ISO 27001.

LinkedIn profile

Why information security is now a top-management matter

70 % of cyberattacks target SMEs. Executive management and the board of directors bear the responsibility, operationally, it is delegated to a CISO/ISB.

  • Mercedes-Benz, entire GitLab data (code) exposed online
  • 23andMe, DNA data of around 6 million customers published
  • Trello, data of over 15 million customers exfiltrated
  • Motel One, ransomware attack
  • Verivox, software vulnerability

Only 25 % of executives currently integrate data-security functions into products, services and vendor relationships. Security by design begins with a named, competent person.

Do you need a CISO/ISB/ISO?

The obligation or recommendation arises from your industry, data intensity and contractual landscape.

  • You process sensitive information (financial, health, R&D, trade secrets).
  • You are subject to sector-specific rules (FINMA outsourcing, EPDG, MDR, DORA, NIS2).
  • You are planning an ISO 27001 certification.
  • Your customers require a designated security officer in vendor reviews.
  • You operate critical infrastructure or process large volumes of personal data.

CISO, ISB, ISO, what is the difference?

The three roles are often used interchangeably, the differences lie primarily in budget responsibility and proximity to executive management.

RoleProximity to executive managementBudget responsibilityTypical mandate size
CISO (Chief Information Security Officer)C-level, seat on executive managementOwn budgetCorporate group / regulated mid-sized company
ISB (Information Security Officer)Reports to executive managementIndirect, advisorySME / regulated mid-sized company
ISO (Information Security Officer)Reports to IT/executive managementAdvisorySwiss SME

What's included?

Predictable availability with a fixed response time and ready-made reporting templates.

  • ISMS implementation and operation under ISO 27001
  • Internal audits and audit support
  • FINMA reporting and regulatory evidence
  • Incident response and emergency coordination
  • Board reporting templates and quarterly reviews with management
  • Response within 48 hours for security-relevant incidents

Complementary service: ISO 42001 AI Governance for the responsible use of AI in your company.

Which activities does SIDD take on as an external CISO/ISB/ISO?

  • Development, implementation and monitoring of an information security strategy, aligned with business objectives, risk profile and compliance.
  • Definition and maintenance of policies, standards and processes based on ISO 27001, BSI Grundschutz, NIST.
  • Advising and training executive management, business units and employees, awareness, best practices, security culture.
  • Management of internal and external audits, vulnerability and risk analyses, contingency plans, incident response.
  • Communication with the DPO, IT management, legal counsel, works council, clients, suppliers and authorities.

How much effort does a CISO/ISB/ISO require?

The effort depends on size, complexity and maturity level. A BSI study cites an average of 12 hours per week, with the following range:

  • Small companies (<50 employees): approx. 4 h/week
  • Medium-sized companies (51–250 employees): approx. 8 h/week
  • Large companies (>250 employees): approx. 16 h/week

With an external mandate you only pay for the time you use, without recruiting, continuing education, backup staff or social-insurance overhead.

Internal vs. external CISO, the key differences

CriterionInternal (FTE)External (SIDD)
Cost/year (full FTE equivalent)CHF 180k – 280kCHF 30k – 120k
Availability/backup1 person, vacation riskTeam backup, escalation
IndependencePolitically tied inNeutral, audit-ready
CertificationsInvestment and training obligationBSI Lead Auditor included
Time-to-productivity3–6 months of onboarding14 days

Packages

Flexible annual hours allowance. You draw on hours throughout the year, we remain your dedicated point of contact.

Advisory CISO

from CHF 30k / year

Strategic and advisory, with quarterly reviews with executive management. Ideal for SMEs with an IT lead.

Interim CISO

On request

Full mandate for a fixed term, transition, restructuring, crisis situations, audit preparation.

Process after engagement

Contract

Digital service agreement defining the scope of services as information security officer.

Kick-off

Workshop to get acquainted, align expectations, and define next steps.

InfoSec Analysis

Inventory of processes, systems, and documents. Identifying the need for action.

InfoSec Concept

Action plan with policies, training, and awareness measures.

Implementation

Support through advisory services, training, and review.

Ongoing support

Dedicated point of contact, with ongoing monitoring and updating.

Why SIDD?

What concretely sets SIDD's fractional CISO/ISO/ISMS mandate apart from an in-house position or a pure consulting firm.

An auditor's perspective from the outset

Your mandate is led by an ISO/IEC 27001 Lead Auditor (BSI-trained). You gain the perspective that will matter later in the certification audit, before the external audit takes place.

Mandate instead of permanent hire

You fill the steering role on a fractional basis at a fraction of a full-time position, without recruiting, training, or cover arrangements. The mandate scales with the actual steering needs, from a standby level up to full governance.

Law and technology under one roof

NIS2, ISO 27001, and regulated mandates call for legal assessment and technical depth at the same time. Lawyers holding doctorates and our own InfoSec engineering team work under one roof, instead of you having to coordinate two service providers.

Steering and review kept separate

We keep ongoing CISO/ISO governance and independent auditing strictly separate. This makes your security statements credible to supervisory authorities, customers and certifiers.

Demonstrable, not just slides

Asset inventory, risk treatment and reporting run as maintained, auditable tooling on the Priverion platform. During an audit or a NIS2 request, you pull the current status, not an outdated presentation.

A dedicated person since 2017

You have a named contact person rather than a rotating pool, with an initial response within 24 hours. Active since 2017 with a high renewal rate, because the role is designed for continuity and not for a one-off project.

Cybersecurity and CISO, law and technology from a single source

Cybersecurity is a board-level topic in Switzerland: NIS2 in the EU, the Swiss ICT minimum standard and FINMA requirements all call for a named, qualified function. As your external CISO, we combine the technical management of your information security with the legal assessment under the revised FADP, the GDPR and regulatory requirements, all from a single source.

FINMA- and bank-proven

SIDD already works with regulated Swiss companies in finance, insurance and healthcare. You gain lead-auditor experience from real FINMA, DORA and ISO 27001 mandates.

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For your CISO/ISB mandate, concretely: LexCommand crosswalks the overlapping duties from ISO 27001, NIS2, DORA and FINMA, and drafts ISMS policies and board reports into your Word templates, every statement carrying its citation to the primary source.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions before engaging us

What does an external CISO/ISO cost?

Advisory from CHF 30k/year, vCISO from CHF 60k/year, interim on request. The final price depends on company size, industry and the number of hours required.

Can you take over an existing ISMS?

Yes. We take over ISMS mandates from in-house functions or other service providers and continue ongoing operations, including audit support.

How quickly are you available?

Contract signing and kick-off within 14 days. In emergencies (security incident, audit preparation) this can be expedited.

Do you cover NIS2, DORA, FINMA?

Yes. We regularly work on mandates subject to NIS2, subject to DORA and regulated by FINMA. Requirements are integrated into the action plan.

What sets you apart from an IT shop or a law firm?

We are both, and more. Technical expertise (penetration testing, ISMS), legal expertise (GDPR, revised FADP) and auditor qualification in one person. This makes mandates robust before supervisory authorities.

Are inquiries subject to confidentiality?

Yes, Art. 321 SCC.

Free 30-minute consultation, no commitment

We assess your starting point and tell you exactly what makes sense.

30-minute consultation with Philipp Staiger, free and no obligation Book an appointment