External information security officer — the role, not the headcount.

NIS2, ISO 27001, and TISAX® all ask for the same thing: a designated, reachable, properly resourced responsibility for information security. In companies between twenty and two hundred employees there is rarely a suitable position for it — so the task lands with the head of IT, who already holds a full-time role. We take on the engagement: as your designated information security officer, with a fixed reporting line to your executive management.

3 frameworks, one role
67% of MSPs offer vCISO (2025)
1–4 days per month, typical
§ 38 BSIG — management's duty
Current situation

The role is required. It is almost never filled.

Not out of negligence — but because for most companies it is too big to do on the side and too small to justify a position of its own.

“The head of IT can do it on the side”

Whoever is responsible for operations cannot assess them independently. That dual role surfaces in the audit at the latest — and it means security work always ends up behind day-to-day business.

Documents without operations

An externally produced policy package does not pass an audit if nobody maintains it. Assessors do not check whether an ISMS exists, but whether it is lived — certifications fail on that more often than on technology.

Management reports to itself

Section 38 BSIG requires approval and oversight by executive management. Without someone reporting to them regularly and in a structured way, that duty is practically impossible to fulfill — and, in case of doubt, impossible to prove.

No point of contact for customers

Security questionnaires, audit requests, and supply chain reviews need an addressee with subject expertise. Without one, these requests wander through the company and get answered too slowly or too vaguely.

Comparison

Three ways to meet the same obligation.

The question is rarely whether the role is needed — but in which form it fits the size of the company.

  Employed internally External retainer (vCISO) On the side, by IT
Available in three to nine months of searching two to four weeks immediately — nominally
Cost full-time position plus training a fraction of that, tied to actual demand hidden — in overtime and neglected operations
Independence given, provided it does not report into IT structurally given not given — operations assess themselves
Certification experience depends on the individual from many procedures, not from one usually none
Scales under audit pressure no — the position stays the same size yes — scope is adjusted no — operations suffer first
Makes sense from around 200 employees around 20 to 200 employees only as an interim solution

The market confirms this calculation: according to the State of the vCISO Report 2025, the share of managed service providers offering a vCISO service rose from 21 to 67 percent within a single year. Not because the model is new — but because regulation is now reaching company sizes that could never have afforded a security department of their own.

Services

What the retainer includes.

Not advice on request, but a role with fixed dates, fixed deliverables, and a fixed reporting line.

Governance

An ISMS that someone actually runs.

Maintenance of the risk register, action plan, and policies in day-to-day operation — on fixed dates rather than in bursts shortly before the audit.

Management report

The basis on which your leadership decides.

A quarterly report to executive management: risk position, status of measures, open decisions — documented, and therefore usable as evidence of the oversight duty under Section 38 BSIG.

Audit

The person sitting next to you in the audit.

Preparation for and support through ISO 27001 certifications and TISAX® assessments, handling of nonconformities, and communication with auditors — from a lead auditor's perspective.

Incident

The calm voice when it counts.

A rehearsed response to security incidents including the NIS2 reporting chain with its 24-hour initial notification — prepared before it is needed, not improvised while things are burning.

Supply chain

Answers that do not hold up contracts.

Handling of security questionnaires and supply chain requests from your customers, plus review of the security clauses in contracts before they are signed.

Training

Awareness that outlasts an annual obligation.

Awareness across the workforce and the training for executive management that NIS2 requires — documented, because the documentation is part of the duty too.

Difference

An officer who can also implement the measure.

Most vCISO retainers stop at the edge of the technology: a policy gets written, and someone else owes its implementation. On Apple fleets we shorten that path — what the ISMS demands is enforced through Mosyle MDM and is retrievable as evidence in the next audit.

  • Disk encryption and patch level as enforced configuration, not as a request
  • Device compliance as a precondition for access, checked continuously
  • Audit evidence straight from the MDM instead of from screenshots
  • One counterpart for the security requirement and its technical implementation
FAQ

Frequently asked questions about the retainer.

What is the difference between a vCISO and an external information security officer?

In practice, both terms describe the same thing from two angles. “External information security officer” is the term the German frameworks use — it describes the designated role that ISO 27001, the VDA ISA catalog, and a NIS2 implementation presuppose organizationally. “vCISO” is the market term for the same retainer, usually with somewhat more weight on strategy, budget advice, and management communication. We deliver both in one engagement and set the emphasis according to whether you are heading into an audit or running a security program over several years.

Does the external information security officer take on management's liability?

No — and any provider promising that should make you suspicious. Section 38 BSIG expressly assigns the approval of risk management measures and the oversight of their implementation to executive management; a waiver of claims for damages is excluded by law. What an external information security officer delivers is something different and practically decisive: they put executive management in a position to meet its oversight duty in the first place — through regular, documented reports, clear decision papers, and traceable risk assessments. It is exactly this evidence that counts when it matters.

How much time does this take per month?

The typical scope runs between one and four days per month. A company with around fifty employees and an existing ISMS usually manages on one to two days in normal operation. During certification, a TISAX® assessment, or an acute security incident, the demand rises sharply — and falls again afterwards. This elasticity is the core of the model: you cannot let a permanent position breathe, but you can let a retainer.

Can an external person fill the role for TISAX® at all?

Yes. The VDA ISA catalog requires that responsibility for information security is clearly designated, resourced, and anchored in the organization — it does not require that the person be employed by the company. What matters to assessors is that the role is reachable, actually prepares decisions, and is connected to the management level through a documented reporting line. An external retainer satisfies that, provided it is contractually clean and reflected in the ISMS.

What happens if we want to fill the role internally later?

Then it is an orderly handover, not a fresh start. Everything created during the retainer — policies, risk register, action plans, reporting lines, audit records — belongs to you and sits in your systems, not ours. Many companies use the retainer exactly this way: as a build-up phase until the organization is large enough for its own position. We hand over to the internal successor and support the onboarding if that is wanted.

Read next

Related