Cybersecurity is no longer just a concern for large corporations. Ransomware targets manufacturing companies, hospitals, logistics firms and accounting offices. The NIS2 regulation extends obligations to thousands of medium-sized enterprises. Yet most of them do not have a single dedicated security specialist, let alone a Chief Information Security Officer.
The CISO as a Service (CISOaaS) model directly addresses this gap: organisations gain an experienced security leader on a part-time basis or as a shared service, with all the expertise and authority of the role, without the cost of full-time employment.
What a CISO does and why this role is critical
The Chief Information Security Officer is not a technical specialist sitting at a console monitoring logs. The CISO is a strategic role at the intersection of technology, business and law. Their responsibilities include:
- Security strategy - defining the vision, target state and security roadmap in line with company objectives
- Risk management - systematic identification, assessment and treatment of security risks
- Compliance - ensuring compliance with regulations (NIS2, GDPR, ISO 27001, sector standards)
- Security programme management - coordination of technical measures, training, audits and suppliers
- Communication with management - translating technical risks into business language for the board and management
- Response to incidents - leadership and coordination in the event of a cyber attack
- Safety culture - building an organisation where safety is not a hindrance but part of the work
The key is to understand that CISO is a bridge between the technical IT team and company management. Without it, safety issues either never reach senior management or arrive in a form that management does not understand and cannot make decisions on.
Why a medium-sized company cannot afford a full-time CISO
An experienced CISO with CISSP, CISM or CISA certifications and relevant experience demands a gross salary of 150 000 to 300 000 Kč per month in the Czech Republic. This is in addition to employer insurance contributions, benefits, training costs and recruitment expenses. Total annual costs easily exceed 3 million koruna.
For a company with a turnover of 200-500 million Kč, this represents a disproportionate burden, especially since a CISO in such a firm will not be fully occupied for eight hours a day. Strategic work, risk management and compliance typically require 10-20 hours a week in a smaller organisation. Paying full-time for 20 hours of meaningful work makes no economic sense.
The problem of delegating to the IT director
Many companies address the absence of a CISO by assigning security responsibility to the IT director or system administrator. This is problematic for several reasons:
- Security and IT naturally have different, and sometimes conflicting, priorities (availability versus security).
- The IT director lacks specialised security training and certifications.
- Security matters get lost in IT day-to-day operations.
- Lack of an independent perspective: the IT director cannot effectively audit themselves.
- In the event of an incident or audit, the company cannot demonstrate the professional competence of the safety guarantor.
What is included in the CISOaaS model
CISOaaS is not one-off advisory work or the sale of security software. It is a continuous service with a clearly defined scope. A typical CISOaaS offering from SecureOn.cz includes:
Strategic level
- Processing of security strategy and ISMS policy
- Regular risk management (risk assessment, risk treatment plan)
- Regular reports for management (dashboard, KPIs, trends)
- Company representation in communications with regulators (NÚKIB, supervisory authorities)
- Coordination with the Data Protection Officer and the legal department
Operational level
- Security incident management (incident response plan, coordination during an attack)
- Supervision of patch management and vulnerability assessment
- Coordination of penetration tests and audits
- Management of safety training and phishing simulations
- Documentation management and record-keeping (ISMS documents, processing records)
Compliance and Certification
- Ongoing compliance with NIS2, GDPR and relevant standards
- Preparation for ISO 27001 certification or NÚKIB audit
- Supply chain management (security requirements for subcontractors)
NIS2 and the requirement for a qualified security guarantor
Act No. 181/2014 Coll., as amended to implement the NIS2 Directive, explicitly requires that obligated entities ensure ICT security management is handled by a professionally competent person. The NÚKIB Decree specifies the requirements for education, experience and proof of professional competence of the cybersecurity guarantor.
For companies within the NIS2 scope (critical infrastructure, important and essential entities), this means: it is not sufficient for an IT administrator without formal security education to be responsible for security. Professional competence must be demonstrated—and it must be verifiable.
CISOaaS meets this requirement elegantly: the service provider supplies a certified expert with verifiable experience, whose expertise can be demonstrated during a NÚKIB audit. The company also avoids a lengthy and uncertain recruitment process.
How to choose a CISOaaS provider
When selecting a CISOaaS provider, consider:
- Certification of a specific CISO - CISSP, CISM, CISA or equivalent
- Relevant sector experience - ideally from your sector or a similarly regulated environment
- Clear scope of service - the contract must define the number of hours, availability and escalation procedures
- Continuity - what happens if a specific CISO falls ill or leaves?
- References - verifiable references from existing clients
- Compliance with NIS2 - ability to demonstrate professional competence during a regulatory audit
CISOaaS is not a compromise. It is a pragmatic solution for companies that need serious security leadership without the serious personnel costs. If you are facing the decision of how to fill the security role in your company, contact us - We are happy to explain how the CISOaaS model works in practice and what it would include for your organisation.