Advisory CISO
from CHF 30k / year
Strategic and advisory, with quarterly reviews with executive management. Ideal for SMEs with an IT lead.
A full-time CISO costs CHF 180,000–250,000/year. Our mandate starts at CHF 30,000, with ISO 27001 Lead Auditor expertise most internal teams don't have.
Working for regulated industries and SMEs
Cost comparison
Full-time CISO: CHF 200,000+/year. Our mandate: from CHF 30,000.
70 % of cyberattacks target SMEs. Executive management and the board of directors bear the responsibility, operationally, it is delegated to a CISO/ISB.
Only 25 % of executives currently integrate data-security functions into products, services and vendor relationships. Security by design begins with a named, competent person.
The obligation or recommendation arises from your industry, data intensity and contractual landscape.
The three roles are often used interchangeably, the differences lie primarily in budget responsibility and proximity to executive management.
| Role | Proximity to executive management | Budget responsibility | Typical mandate size |
|---|---|---|---|
| CISO (Chief Information Security Officer) | C-level, seat on executive management | Own budget | Corporate group / regulated mid-sized company |
| ISB (Information Security Officer) | Reports to executive management | Indirect, advisory | SME / regulated mid-sized company |
| ISO (Information Security Officer) | Reports to IT/executive management | Advisory | Swiss SME |
Predictable availability with a fixed response time and ready-made reporting templates.
Complementary service: ISO 42001 AI Governance for the responsible use of AI in your company.
The effort depends on size, complexity and maturity level. A BSI study cites an average of 12 hours per week, with the following range:
With an external mandate you only pay for the time you use, without recruiting, continuing education, backup staff or social-insurance overhead.
| Criterion | Internal (FTE) | External (SIDD) |
|---|---|---|
| Cost/year (full FTE equivalent) | CHF 180k – 280k | CHF 30k – 120k |
| Availability/backup | 1 person, vacation risk | Team backup, escalation |
| Independence | Politically tied in | Neutral, audit-ready |
| Certifications | Investment and training obligation | BSI Lead Auditor included |
| Time-to-productivity | 3–6 months of onboarding | 14 days |
Flexible annual hours allowance. You draw on hours throughout the year, we remain your dedicated point of contact.
Advisory CISO
from CHF 30k / year
Strategic and advisory, with quarterly reviews with executive management. Ideal for SMEs with an IT lead.
vCISO (fractional)
from CHF 60k / year
Fractional, operational and strategic. Monthly steering, ISMS operation, audit support.
Interim CISO
On request
Full mandate for a fixed term, transition, restructuring, crisis situations, audit preparation.
Digital service agreement defining the scope of services as information security officer.
Workshop to get acquainted, align expectations, and define next steps.
Inventory of processes, systems, and documents. Identifying the need for action.
Action plan with policies, training, and awareness measures.
Support through advisory services, training, and review.
Dedicated point of contact, with ongoing monitoring and updating.
What concretely sets SIDD's fractional CISO/ISO/ISMS mandate apart from an in-house position or a pure consulting firm.
Your mandate is led by an ISO/IEC 27001 Lead Auditor (BSI-trained). You gain the perspective that will matter later in the certification audit, before the external audit takes place.
You fill the steering role on a fractional basis at a fraction of a full-time position, without recruiting, training, or cover arrangements. The mandate scales with the actual steering needs, from a standby level up to full governance.
NIS2, ISO 27001, and regulated mandates call for legal assessment and technical depth at the same time. Lawyers holding doctorates and our own InfoSec engineering team work under one roof, instead of you having to coordinate two service providers.
We keep ongoing CISO/ISO governance and independent auditing strictly separate. This makes your security statements credible to supervisory authorities, customers and certifiers.
Asset inventory, risk treatment and reporting run as maintained, auditable tooling on the Priverion platform. During an audit or a NIS2 request, you pull the current status, not an outdated presentation.
You have a named contact person rather than a rotating pool, with an initial response within 24 hours. Active since 2017 with a high renewal rate, because the role is designed for continuity and not for a one-off project.
Cybersecurity is a board-level topic in Switzerland: NIS2 in the EU, the Swiss ICT minimum standard and FINMA requirements all call for a named, qualified function. As your external CISO, we combine the technical management of your information security with the legal assessment under the revised FADP, the GDPR and regulatory requirements, all from a single source.
SIDD already works with regulated Swiss companies in finance, insurance and healthcare. You gain lead-auditor experience from real FINMA, DORA and ISO 27001 mandates.
Our tool: LexCommand
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For your CISO/ISB mandate, concretely: LexCommand crosswalks the overlapping duties from ISO 27001, NIS2, DORA and FINMA, and drafts ISMS policies and board reports into your Word templates, every statement carrying its citation to the primary source.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
Advisory from CHF 30k/year, vCISO from CHF 60k/year, interim on request. The final price depends on company size, industry and the number of hours required.
Yes. We take over ISMS mandates from in-house functions or other service providers and continue ongoing operations, including audit support.
Contract signing and kick-off within 14 days. In emergencies (security incident, audit preparation) this can be expedited.
Yes. We regularly work on mandates subject to NIS2, subject to DORA and regulated by FINMA. Requirements are integrated into the action plan.
We are both, and more. Technical expertise (penetration testing, ISMS), legal expertise (GDPR, revised FADP) and auditor qualification in one person. This makes mandates robust before supervisory authorities.
Yes, Art. 321 SCC.
We assess your starting point and tell you exactly what makes sense.