RISKORIA ADVISING & PROFESSIONAL SERVICES D.O.O. · ZAGREB+385 97 737 1345INFO@RISKORIA.EU

vCISO, security leadership under contract

Most organisations do not need a full-time security director, but someone who sets the direction, reports to the board and makes sure deadlines are met.

LEGAL FRAMEWORKZKS NN 14/2024REGULATION NN 135/2024, ANNEX IIISO/IEC 27001:2022

Why the role exists at all

The Act requires somebody to be accountable by name, and the Regulation that this person is not in a conflict of interest.

Article 29 of the Act places responsibility for the measures on the management body, and it cannot be passed to IT or to an outside contractor. But the management body cannot discharge that responsibility on its own either, because doing so requires somebody who tracks the state of things month by month, measures it and reports on it.

The Regulation spells this out. Sub-measure 1.4 requires established roles and responsibilities, sub-measure 1.6 the appointment of a person operationally responsible for cyber security, and sub-measure 1.5 the separation of roles that could create a conflict of interest. The last two are binding from the medium level upwards. Sub-measure 1.7 then requires annual reporting to the responsible persons on the state of cyber security, and sub-measure 1.8 security metrics.

Separation of roles is why the head of IT is often not a good fit for this role. The same person should not both implement a measure and judge whether it has been implemented. A vCISO is not in that reporting line but answers to the management body.

We contract a monthly volume of hours and clear deliverables, with no open-ended advice. Anything that does not appear in the report to the management body has not been done.

Which sub-measures the role covers

It does not cover them all, but it covers exactly those that need a standing person rather than a one-off project.

SUB-MEASUREWHAT IT REQUIRESWHAT WE DELIVER
1.4Established and maintained roles and responsibilitiesA role matrix with names and deputies, kept current through the year
1.5Separation of roles that could create a conflict of interestA role outside the IT line, reporting directly to the management body
1.6Appointment of a person operationally responsible for cyber securityA named person and a description of responsibilities, with a management decision
1.7Annual reporting to the responsible persons on the state of securityA report to the board in the language of decisions, with risks, cost and deadline
1.8Security metrics on the state of cyber securityA handful of indicators that are actually tracked, not a dozen nobody reads
3.1 and 3.4A risk management process and regular risk reportingMaintaining the risk register and reporting to the relevant parts of the business
8.4Monitoring and review of supply chain securitySupplier and contract clause reviews on an agreed cycle
11.4Detailed incident monitoring, analysis and response proceduresLeadership in the assessment, the notification and the communication

Sub-measures 1.5 and 1.6 are binding at the medium and advanced levels and voluntary at the basic level. The same applies to sub-measure 1.8. Which level binds you is set by the national risk assessment during categorisation.

What the contract carries

Six deliverables that repeat on an agreed rhythm, plus hours for whatever comes up unplanned.

01

A regular report to the management body, in the language of decisions

What has changed, which risks are open, what we are asking to have approved and what it costs. No technical vocabulary and no tool lists. The report goes to a meeting and leaves minutes, which are themselves the evidence for sub-measure 1.7.

BOARD REPORTMEETING MINUTESMETRICS
02

Oversight of the thirteen measures

We track the state of each sub-measure and flag whatever has slipped. The role is not to implement the measures instead of your people, but to know where each one stands and whose turn it is.

STATUS BY SUB-MEASUREPLAN WITH DEADLINESBACKLOG
03

Risk register and treatment plan

We keep the register alive rather than as a document opened before an audit. A new project, a new supplier and every incident go into the register, because those are the three most common sources of new risk.

RISK REGISTERTREATMENT PLANREVIEW RECORD
04

Taking part in the cyber security committee

Where a committee exists we take part in its work and prepare the materials. Where none exists we help set one up, because decisions with no body to take them usually are not taken.

AGENDAMATERIALSMINUTES
05

Supplier and contract clause reviews

We maintain the register of direct suppliers and track whether they meet the security clauses in their contracts. This is the measure most easily neglected and hardest to catch up on, because it requires negotiation.

SUPPLIER REGISTERCLAUSE REVIEWVERIFICATION RECORD
06

Support during an incident and its reporting

We guide you through assessing whether the incident is significant, through reporting within the 24 and 72 hour deadlines, and through communication to the board and to service recipients. Availability and response time are set in the contract, while technical recovery is done by your team or your contractor.

SIGNIFICANCE ASSESSMENTFORMS AND DEADLINESPOST-INCIDENT REPORT

Three roles that get confused

The difference is not formal, because it determines who may sign what.

01Head of ITImplements the measures and runs the systems. Answers for the technology working. Should not judge whether a measure they implemented themselves is sufficient, because that is the conflict of interest sub-measure 1.5 addresses.
02Head of cyber security, the CISOSets the direction, measures the state and reports to the management body. Does not implement measures or administer systems. Reports to the board rather than to IT, which is why the report goes to a meeting. A vCISO is not a separate role but this same role contracted externally.
03Data protection officerA role under the General Data Protection Regulation, with its own tasks and its own independence. It overlaps with cyber security around data breaches, but it is not the same role and is generally not held by the same person.

Frequently asked questions

The questions we are asked most often before we start.

How many hours a month?

It depends on size and maturity. For a mid-sized organisation a few days a month is usually enough, with more at the start while the risk register and the plan are set up. The volume is contracted and changes by agreement, not quietly.

Does a vCISO satisfy sub-measure 1.6?

The sub-measure requires the appointment of a person operationally responsible for cyber security. The appointment is made by the management body’s own decision, and the person may be external, under a contract that clearly sets out responsibilities and availability. What matters is that a decision, a description of responsibilities and a trail of that person’s work all exist.

Does this transfer responsibility to you?

No. Article 29 of the Act places responsibility on the management body and no contract transfers it. The same applies where an external provider runs the systems, under Article 26(4). Our responsibility is contractual, towards you, not towards the authority.

How quickly can you start?

From the first call to starting work usually takes two weeks, the time needed for a proposal and a signed confidentiality agreement. The first month is always denser, because it covers the picture of the current state.

Do you work alongside an existing security lead?

We do. In that case we do not take over the role but support the person already appointed, most often on reporting to the board, on the risk register and on audit preparation.

Can the same person be both vCISO and data protection officer?

As a rule no, because the data protection officer must be independent and must not end up supervising their own decisions. With us these are separate roles held by separate people.

What if the authority requests an audit?

We prepare you and help assemble the evidence, but we do not carry out the audit. Riskoria does not hold the national security certificate for auditing, so that role stays separate, and the separation protects you too.

Where to go next

The work a vCISO leads, set out in full on its own pages.

Need somebody to set the direction?

Half an hour, no obligation. Tell us what is missing in your security leadership and we will see whether a vCISO covers it.

Book a callINFO@RISKORIA.EU · +385 97 737 1345