Blog Security strategy

CISO as a Service: When does a security director as a service pay off?

The annual cost of an experienced CISO in the Czech Republic ranges from 2 to 4 million Kč. For most medium-sized companies, this is unaffordable. CISOaaS delivers the same expertise for a fraction of the cost, and NIS2 makes it increasingly relevant.

8 September 2025 · 9 minutes reading · Security strategy

Cybersecurity is no longer just a concern for large corporations. Ransomware targets manufacturing companies, hospitals, logistics firms and accounting offices. The NIS2 regulation extends obligations to thousands of medium-sized enterprises. Yet most of them do not have a single dedicated security specialist, let alone a Chief Information Security Officer.

The CISO as a Service (CISOaaS) model directly addresses this gap: organisations gain an experienced security leader on a part-time basis or as a shared service, with all the expertise and authority of the role, without the cost of full-time employment.

What a CISO does and why this role is critical

The Chief Information Security Officer is not a technical specialist sitting at a console monitoring logs. The CISO is a strategic role at the intersection of technology, business and law. Their responsibilities include:

The key is to understand that CISO is a bridge between the technical IT team and company management. Without it, safety issues either never reach senior management or arrive in a form that management does not understand and cannot make decisions on.

Why a medium-sized company cannot afford a full-time CISO

An experienced CISO with CISSP, CISM or CISA certifications and relevant experience demands a gross salary of 150 000 to 300 000 Kč per month in the Czech Republic. This is in addition to employer insurance contributions, benefits, training costs and recruitment expenses. Total annual costs easily exceed 3 million koruna.

For a company with a turnover of 200-500 million Kč, this represents a disproportionate burden, especially since a CISO in such a firm will not be fully occupied for eight hours a day. Strategic work, risk management and compliance typically require 10-20 hours a week in a smaller organisation. Paying full-time for 20 hours of meaningful work makes no economic sense.

The problem of delegating to the IT director

Many companies address the absence of a CISO by assigning security responsibility to the IT director or system administrator. This is problematic for several reasons:

What is included in the CISOaaS model

CISOaaS is not one-off advisory work or the sale of security software. It is a continuous service with a clearly defined scope. A typical CISOaaS offering from SecureOn.cz includes:

Strategic level

Operational level

Compliance and Certification

NIS2 and the requirement for a qualified security guarantor

Act No. 181/2014 Coll., as amended to implement the NIS2 Directive, explicitly requires that obligated entities ensure ICT security management is handled by a professionally competent person. The NÚKIB Decree specifies the requirements for education, experience and proof of professional competence of the cybersecurity guarantor.

For companies within the NIS2 scope (critical infrastructure, important and essential entities), this means: it is not sufficient for an IT administrator without formal security education to be responsible for security. Professional competence must be demonstrated—and it must be verifiable.

CISOaaS meets this requirement elegantly: the service provider supplies a certified expert with verifiable experience, whose expertise can be demonstrated during a NÚKIB audit. The company also avoids a lengthy and uncertain recruitment process.

How to choose a CISOaaS provider

When selecting a CISOaaS provider, consider:

CISOaaS is not a compromise. It is a pragmatic solution for companies that need serious security leadership without the serious personnel costs. If you are facing the decision of how to fill the security role in your company, contact us - We are happy to explain how the CISOaaS model works in practice and what it would include for your organisation.

Do you need advice on cybersecurity?

Our experts are ready to assess your situation. The first consultation is free of charge.

Get a free consultation