
CISO mandate for an international industrial company
External security leadership on a mandate basis, for over two years.
An internationally active industrial company needed senior security leadership without creating a full-time position. For over two years ODCUS has held operational security responsibility as Fractional CISO.
Starting point
A viable security strategy, lived governance and reliable reporting to management were missing. Risks were neither systematically captured nor assessed, and security investments ran without clear prioritization.
Approach
- Developed a cybersecurity strategy based on NIST CSF 2.0
- Set up a program roadmap across identities, endpoints, applications, network and data on a Zero-Trust basis
- Established security policies, concepts and governance: security architecture, backup and recovery, access and role management, incident response
- Regular security reporting to management and the board of directors
- Coordinated cyber incidents and handled them with an external SOC and IRT
Result
- A documented, lived security strategy instead of loose individual measures
- A prioritized program with a clear roadmap
- Governance and incident processes that work in daily operations
- Demonstrable due diligence towards management and the board
Frameworks and tools used
NIST CSF 2.0Zero TrustISO 27001Incident Response