External CISO, Implementation Consultancy & Project Management
External CISO
As an external CISO or Information Security Officer - depending on the size of your organization, either full-time or part-time - we take care of your information security. Whether to bridge a temporary bottleneck, secure additional capacity ahead of audits and certifications, or simply because it is the most cost-effective solution.
In doing so, we act as a true business partner for all corporate divisions: making risks manageable and leveraging cybersecurity as a competitive advantage in customer trust.
Security responsibility without creating a full-time post
Not every organisation needs a full-time CISO – and not every organisation can justify the cost of one. At the same time, ISO 27001, NIS-2 and customer audits require a designated person to be responsible for information security.
An external part-time appointment bridges this gap without creating a permanent post. Depending on the size of the organisation, this could be as a CISO or an information security officer, on a full-time or part-time basis, for a fixed term or on a permanent basis.
Our role typically encompasses:
Steering and Reporting
Monthly reporting as well as quarterly steering committees – preparation, facilitation, and follow-up
Progress reporting to executive management and leadership teams
Identifying and escalating roadblocks, such as resource constraints or stalled implementation in business units
Alignment of priorities and developing proposed solutions
Building and Maintaining an Audit-Ready ISMS
Development and maintenance of the Information Security Policy
Drafting and aligning ISMS mandatory documentation, including key performance metrics
Ongoing gap analyses and internal audits against ISO 27001, BSIG (German BSI Act), and NIS2
Facilitating the complete risk assessment and treatment process, including workshops
NIS2 and BSIG applicability and impact analyses
Audit-compliant documentation with established standards and schedules
Implementing Measures and Transferring Knowledge
Selection, planning, and implementation of defined security measures
Operational areas such as Identity and Access Management (IAM), vulnerability management, asset management, endpoint and network protection, backup and recovery, and penetration testing
Awareness training for employees and management, including phishing simulations and tabletop exercises according to BSI guidelines
Preparing incident response processes and managing cross-functional coordination in the event of an emergency
Mentoring and knowledge transfer to your team to build sustainable internal capabilities
What we bring to the table
We listen and collaborate with IT, development, and sales to design pragmatic solutions – instead of establishing a “Department of No.” Whether you call it an interim CISO, a virtual CISO or a fractional CISO – the principle is the same: senior security leadership without a permanent hire.
What else you can count on:
Proven, Reliable Experience
Colleagues with deep technical understanding paired with real-world professional and leadership experience.
Established Concepts
Derived from over 1,000 security and compliance projects with more than 500 client organizations across almost every industry.
Resilient Under Pressure
Delivering results even under tight schedules and limited budgets – including security incident and crisis management when it matters most.
Communication at Eye Level
Just as comfortable in the server room and on the factory floor as we are in the executive boardroom.
100% Independence
No hidden kickbacks, finder’s fees, commissions, or other sales incentives.
Operational Redundancy
We appoint a dedicated deputy at the start of every project.
What an engagement looks like in practice
A real-world client engagement where we provide one of our senior consultants as a part-time Information Security Officer (ISO):
Aligning on timeline, priorities, working modes, interfaces, reporting lines, and the assigned team in a Project Charter
Review of the current security roadmap and recent audits, focusing on gaps and deviations
Gap assessment based on ISO 27001 and NIS2 (as required)
Joint prioritization and deriving immediate action items
On-site execution
Communication & Steering Committees – monthly reporting, quarterly steering committees, progress reports, and managing obstacles/escalations.
Security Policy & ISMS Documentation – guideline documents, key metrics, policies, emergency plans, and documentation standards.
Gap Analyses & Risk Assessment – internal audits against ISO 27001, BSIG, and NIS2, risk analysis process, workshops, milestones, and coordinating external audits.
Action Execution & Effectiveness Review – from IAM and vulnerability management to penetration testing, including metrics to measure effectiveness.
Incident Response – preparing processes and managing cross-functional internal and external coordination in the event of an emergency.
Mentoring & Knowledge Transfer – building sustainable internal capabilities within the client’s team.
From practice
Interim CISO in the automotive sector
Full responsibility for SOC, ISMS and IAM. Handover to the client’s permanent security structure within five months.
Our team of hands-on security experts
Experienced operators with deep technical expertise, ready to lead your security initiatives to success
Dr. Ingo Pansa
Interim CISO at Keenfinity • Lead Architect for Access Management at Mercedes-Benz AG • CPO at Planck Security • Head of Europe’s largest procurement project for cybersecurity services
Stev Gödecke
Former CIO at a medium-sized group of companies (>4,000 IT users) • Over 20 years’ experience in network technology • Over 100 successful security projects (including >30 SOC projects, OT, microsegmentation, SASE/SSE)
Lutz Kirsten
Former Head of the In-house SOC at Bausparkasse Schwäbisch Hall (DORA-regulated) • SecOps SIEM/SOAR for the City of Munich • CISSP, IPMA Level D • Co-leader of Europe’s largest SOC procurement project
Tino Brunzel
Interim ISB role in the manufacturing sector (500 employees) • Security Architect at Mercedes-Benz • PwC Risk Assurance (including ISO 27001 audits) • Deloitte Cybersecurity
Niclas Ilg
PhD in Computer Science (thesis on intrusion detection) • NIS2 impact assessments for KRITIS energy suppliers • NDR/SIEM at a major German bank • EDR/SIEM/SOAR at a leading car manufacturer
Dr. Jannis Stemmann
VP Robert Bosch (including Head of Manufacturing) • Senior Engagement Manager at McKinsey • Over 100 security projects • CISSP, GICSP, ISO 27001 Lead Auditor
Our promise to you:
Our promise to you is absolute independence in our consultancy services. We act solely on your behalf.
All information you share with us, as well as our reports, remains confidential and will not be shared with third parties. In our experience, there is no such thing as perfect security – but we protect your data with the same resources as we use to protect our own.
If you are not satisfied with our service, we will not charge you for it. Furthermore, we are open to performance-based fee structures, for example for meeting project milestones on time.
Your initial point of contact
Dr. Ingo Pansa
Senior Solution Manager, CyberCompare