AGIDAT – Datenschutz | Informationssicherheit

External CISO / Information Security Officer

Strategic information security for SMEs — experienced, accessible, cost-effective.

What is an external CISO?

The Chief Information Security Officer (CISO) — in Germany often also called the Information Security Officer (ISO) — is responsible for the strategic direction and operational implementation of information security within an organization.

Many mid-sized companies cannot or do not want to fill this role internally. AGIDAT takes on the role of external CISO — with full expertise, but without the cost of a full-time position.

What we take on

Strategic tasks

  • Developing and maintaining an information security strategy
  • Creating and updating the security policy
  • Risk management: identifying, assessing, and treating risks
  • Reporting to executive management

Operational tasks

  • Building and maintaining an ISMS based on ISO 27001 or BSI IT-Grundschutz
  • Managing security incidents and emergency response
  • Coordinating penetration tests and vulnerability scans
  • Reviewing suppliers and service providers against security requirements

Communication

  • Point of contact for regulatory authorities (BSI, data protection authorities)
  • Providing evidence to customers and partners (security attestations, audits)
  • Training and raising employee security awareness

When do you need a CISO?

  • You want to build or certify an ISMS based on ISO 27001
  • Customers or clients require evidence of your information security
  • You are affected by NIS2 or other regulatory requirements
  • You lack internal capacity for strategic security topics
  • A security incident has revealed that structural measures are missing

NIS2 and regulatory requirements

The NIS2 Directive, transposed into German law in 2024, requires many companies to meet elevated security standards — including explicit management of information security risks by company leadership. An external CISO helps you meet these requirements.