What is an external CISO?
The Chief Information Security Officer (CISO) — in Germany often also called the Information Security Officer (ISO) — is responsible for the strategic direction and operational implementation of information security within an organization.
Many mid-sized companies cannot or do not want to fill this role internally. AGIDAT takes on the role of external CISO — with full expertise, but without the cost of a full-time position.
What we take on
Strategic tasks
- Developing and maintaining an information security strategy
- Creating and updating the security policy
- Risk management: identifying, assessing, and treating risks
- Reporting to executive management
Operational tasks
- Building and maintaining an ISMS based on ISO 27001 or BSI IT-Grundschutz
- Managing security incidents and emergency response
- Coordinating penetration tests and vulnerability scans
- Reviewing suppliers and service providers against security requirements
Communication
- Point of contact for regulatory authorities (BSI, data protection authorities)
- Providing evidence to customers and partners (security attestations, audits)
- Training and raising employee security awareness
When do you need a CISO?
- You want to build or certify an ISMS based on ISO 27001
- Customers or clients require evidence of your information security
- You are affected by NIS2 or other regulatory requirements
- You lack internal capacity for strategic security topics
- A security incident has revealed that structural measures are missing
NIS2 and regulatory requirements
The NIS2 Directive, transposed into German law in 2024, requires many companies to meet elevated security standards — including explicit management of information security risks by company leadership. An external CISO helps you meet these requirements.