A meeting in a bright meeting room

CISO mandate for an international industrial company

External security leadership on a mandate basis, for over two years.

An internationally active industrial company needed senior security leadership without creating a full-time position. For over two years ODCUS has held operational security responsibility as Fractional CISO.

Starting point

A viable security strategy, lived governance and reliable reporting to management were missing. Risks were neither systematically captured nor assessed, and security investments ran without clear prioritization.

Approach

  • Developed a cybersecurity strategy based on NIST CSF 2.0
  • Set up a program roadmap across identities, endpoints, applications, network and data on a Zero-Trust basis
  • Established security policies, concepts and governance: security architecture, backup and recovery, access and role management, incident response
  • Regular security reporting to management and the board of directors
  • Coordinated cyber incidents and handled them with an external SOC and IRT

Result

  • A documented, lived security strategy instead of loose individual measures
  • A prioritized program with a clear roadmap
  • Governance and incident processes that work in daily operations
  • Demonstrable due diligence towards management and the board

Frameworks and tools used

NIST CSF 2.0Zero TrustISO 27001Incident Response