Swiss security consulting, right-sized
IT security that protects without breaking your budget.
Many Swiss SMEs have a strategy and a concept. What is often missing is execution in daily operations. We bring your security into operation, right-sized and with clear responsibility.
Free initial assessment, 30 min →Most companies do not have a security problem. They have a sizing problem.
Too many tools, too little overview, too much spend for too little real protection. We turn that around.
More protection, fewer tools, less cost.
Five ways to bring your security into operation
From operational security leadership to an assessment with implementation. All hands-on, vendor-independent and right-sized.





Every industry, its own levers
Security risks look different in manufacturing than at an energy provider. We show you where we concretely start.
Manufacturing & Industry
- Security sits with the IT lead on the side, without clear responsibility
- Tools accumulated over years, nobody checks what they really protect
- Supply-chain and NIS2 requirements from larger customers
- OT and IT are converging, and the attack surface grows with them
We take over the responsibility instead of letting it run on the side
Senior security leadership on a mandate basis, with board-ready reporting. Experience when you need it, without the fixed costs of your own CISO position.
Size first, invest second
We assess maturity, clean up the accumulated tools and derive a prioritised roadmap. More protection with fewer tools and lower costs, instead of yet another piece of software.
An ISMS that is lived in daily operations
We build an ISMS that covers supplier and NIS2 requirements and works in operation. Verifiable for customers and audits, without paper tigers.
Energy & critical infrastructure
- Subject to the ISG as critical infrastructure, but without a structured ISMS
- OT and IT are merging, creating new attack surfaces
- Legacy systems run with minimal security oversight
- Protection needs and supplier risks are not captured in a structured way
An ISMS that passes the audit and stays practical
We build it on ISO 27001 and the ICT minimum standard, with asset inventory and protection needs. Audit-ready and lived, not just documented.
Supplier and legacy risks under structured control
We establish third-party risk and measure management in ongoing operations. Regulation fulfilled, without additionally burdening your team.
Security leadership in a regulated environment, without a full-time position
We lead security in the ISG context, vendor-independent and pragmatic. Senior responsibility, right-sized for your organisation.
Financial services
- FINMA, nDSG and DORA requirements across the entire supply chain
- High-value target, compliance is a business prerequisite
- Security evidence demanded by customers and regulators
- Compliance costs grow without a clear overview
Compliance that carries you in daily business instead of slowing you down
We build an ISMS that covers FINMA, nDSG and DORA requirements and is lived. Audit-proof, without paralysing the business units.
Budget where the risk really is
We measure maturity against recognised frameworks and prioritise what has impact. Clear priorities instead of actionism.
Due diligence that is documented and provable
We deliver board-ready security reporting for regulators and the board of directors, in business language. Provable diligence under Art. 717 CO.
Healthcare & Life Sciences
- Sensitive patient data, strict regulatory requirements
- Subject to the ISG, often under-resourced relative to the risk
- Security lands with the IT team without dedicated responsibility
- Data protection under the nDSG with a duty to provide evidence
Understand first, then secure
We capture infrastructure, processes and data protection on site and derive a prioritised plan. A clear baseline instead of gut feeling.
Data protection considered from the start
We build an ISMS with protection needs, risk analysis and data protection impact assessment. ISG and nDSG requirements fulfilled, workable in daily operations.
Security that relieves your busy team
We take over security responsibility instead of leaving it with an already stretched IT team. More security, without additional internal load.
Retail & Logistics
- Supply-chain security requirements from partners
- Many locations and systems, inconsistently secured
- M365 and cloud environments without consistent hardening
- Security requirements to implement across many teams
Bring all locations to a consistent standard
We harden M365 and cloud, sort out identities and Conditional Access. One consistently secured environment instead of isolated solutions per location.
Make progress visible and steerable
We assess maturity and coordinate implementation across the teams. Steered, measurable progress instead of a report in a drawer.
One target picture instead of many single measures
We run a security programme with a clear target picture across all locations, prioritised and right-sized.
Technology & SaaS
- ISO 27001 or SOC 2 as a prerequisite for enterprise deals
- Fast growth, accumulated security debt
- Security as a competitive advantage, but without structure
- Customer questionnaires and audits tie up the team
Become certifiable without slowing the team down
We build a lean ISMS and prepare the ISO 27001 certification, workable in daily operations. The evidence your enterprise customers demand.
Visibly reduce accumulated security debt
We make the security debt visible and reduce it in priority order. From chaos to a roadmap that matches your pace of growth.
Security that grows with you
We bring senior security leadership that scales with your growth. Security as an enabler for deals, not a brake.
Selected mandates from practice
Anonymised insights into real projects, from security leadership through ISMS to recovery.
The principle in practice
Vendor-independent
We do not sell tools. Recommendations follow fit, not commission.
Right-sized
The first step is always: what do you already have, what works, and what can be cut?
Directly with the principal
The person you meet is the person who does the work. No junior handoff.
Implementation over reports
We deliver results, not slide decks that disappear into a drawer.

A partner who stays
We also tell you when the right recommendation is to spend less. That honesty is why an assessment often turns into a long-term collaboration.
- One dedicated senior-level contact
- Decisions that management and the board understand
- Measures that get implemented instead of ending up in a drawer
How a collaboration starts
No long lead time, no sales pressure. Three steps from the first question to implementation.
Free initial assessment
30 minutes, online, no pitch. We listen and put things in perspective.
Baseline review
What do you have, what works, what can be cut. Followed by a clear offer.
Implementation
We take responsibility and stay until it works in daily operations.
Latest posts
Hands-on analyses on security, cost and leadership, fresh from the blog.
Compliance
How much does ISO 27001 cost? The certificate is the cheapest part
How much does ISO 27001 cost for an SME? Why the certificate is the smallest item, where the money goes and how to…
Cybersecurity
CISO vs. information security officer: the difference
CISO or information security officer? We explain the difference between the two roles, the thinking error behind it…
Compliance
ISG ISMS Obligation by 2026: Are You Really Affected?
Information security management system (ISMS) obligation by the end of 2026: Very few Swiss SMEs are directly…
Cybersecurity
When 'isolated' is only an assumption
An AI model escaped an isolated test environment and breached Hugging Face. The real lesson has nothing to do with…
Strategy
Where the name ODCUS comes from (and how to pronounce it)
ODCUS is inspired by Odysseus. What the Greek hero has to do with modern IT security, and why the journey to the…
Cybersecurity
How much does a security assessment cost? Honest numbers for SMEs
How much does a security assessment cost in Switzerland? Honest price ranges, real cost drivers, and how to recognize…
Compliance
nDSG Liability for Managing Directors: Who Really Pays
For data privacy violations, the company doesn't pay, you do, personally, up to 250,000 CHF. What the new FADP means…
Cybersecurity
How much does a CISO cost in Switzerland? Honest figures
How much does a CISO cost in Switzerland? We compare full-time employment against CISO as a Service to show you which…
Insights
Analyses and perspectives on security, cost and compliance.
Frequently asked questions
Answers to what management, IT and boards ask most often.
Who do we work for?
We work with Swiss SMEs between 50 and 500 employees that need senior security expertise without creating a full-time position. Typically management, IT leads and boards of directors, often triggered by an incident, a customer requirement or a regulatory deadline.
What services does ODCUS offer?
Five services around information security: Interim & Fractional CISO, Security Management & Operations as consulting, ISMS setup and ISO 27001 certification, Security Assessment with implementation, and AI Governance & Secure AI Adoption. One principle runs through every mandate: more protection, fewer tools, less cost.
How does ODCUS support companies with security?
We take responsibility and stay until it is done. Instead of a report that disappears in a drawer, you get operational security leadership, an ISMS that works in daily operations, or an assessment whose measures actually get implemented. The first step is always: what do you already have, what of it works, and what can we cut?
What type of businesses can benefit from our services?
Companies with 50 to 500 employees without a full-time CISO, firms in ISG-regulated sectors with an ISMS deadline by the end of 2026, SMEs that need ISO 27001 for customer requirements, and anyone who feels they spend too much on security without keeping an overview.
What benefits does consulting from ODCUS offer?
We are practitioners, not pure consultants, with an implementation background. We advise vendor-independently, recommendations follow fit, not commission. We right-size security spend, the first step is always what can be cut. And you work directly with the principal, no handoff to junior staff.
How does ODCUS differ from other security consultancies?
Large firms are expensive and impersonal, classic boutiques swap people during a project. At ODCUS the person you meet is the person who does the work. And instead of selling tools, we right-size security: most companies do not have a security problem, they have a sizing problem.
What is important to ODCUS in collaboration?
What matters most is trust on equal terms. We tell you even when the right recommendation is to spend less, and we expect the same openness in return. Honest, direct, and without conflict of interest.
Next step
Talk to us before you release more budget.
A free initial assessment shows you in 30 minutes where you stand and what can be saved. No pitch, no obligation.







