Four people are seated at a table in a meeting room, while a presenter speaks in front of a screen.

IT security, right-sized

Five services around information security for Swiss SMEs. More protection, fewer tools, less cost.

Five services, one principle

Security leadership, consulting, ISMS and assessment. One thread runs through all: more protection, fewer tools, less cost.

Interim & Fractional CISO

Security leadership without a full-time hire. Operational responsibility on a mandate basis, 1 to 4 days per week, we stay until it is done.

Learn more

Security Management & Operations

Full security expertise as consulting. Senior support on specific topics while your IT leadership stays in charge.

Learn more

ISMS & ISO 27001

Information security that works in daily operations. From assessment to certification readiness, no paper tiger.

Learn more

Security Assessment with Implementation

No shelf reports. A prioritized assessment with measures that actually get implemented, measured by business risk. At a fixed price of CHF 9,800.

Learn more

AI Governance & Secure AI Adoption

Use AI without losing control over your data and knowledge. Usage policies, AI risk analysis, nDSG-compliant adoption and, on request, an AI management system based on ISO/IEC 42001.

Learn more
Who it is for

Who we work with, and where it actually hurts

The reasons a company hands security to someone outside rarely have much to do with the law. Usually it comes down to capacity, customers and budget. Here is what that looks like in your industry, and which of our services actually moves the needle there. Every industry also has its own page with the full picture.

Manufacturing & Industry

Swiss engineering and metalworking firms are still waiting for a recovery. In Swissmechanic's May 2026 business barometer, about three quarters rate their business situation as unfavourable, the business climate index sits at around minus 30 points, and four in ten firms saw falling EBIT margins in the first quarter of 2026. In a year like that, no board signs off a new full-time security position. The demands arrive anyway: large customers send supplier questionnaires, insurers attach conditions, and on the shop floor control systems and office IT are growing together.

Typical trigger: A major customer sends a security questionnaire with a deadline, and nobody inside can answer it.

What we find in these companies

  • Security sits with the IT lead who already carries everything elseOperations, ERP, projects and support run through the same person. Security is not in bad hands there. It is simply the task that always comes last.
  • Customer questionnaires decide who gets the orderIf you cannot evidence supply chain, emergency planning and access control, you drop off the bidder list before anyone talks about price.
  • Machines run for 15 years and moreControllers on old software versions cannot simply be updated, because the vendor has not approved it or the line would have to stop.
  • The toolset grew, it was never designedFirewall, endpoint protection, backup and monitoring come from different years and overlap. With margins shrinking, that is real money buying no additional protection.
  • One day of downtime costs more than the annual security budgetThat is the real argument on a shop floor, and it is a commercial one, not a regulatory one.

Why these services fit

Interim & Fractional CISO

Assigned responsibility without creating a position

A mandate of one to four days a week costs a fraction of a permanent CISO and can be scaled back once the programme stands. That is the cost structure a board will approve even with headcount frozen.

Your IT lead keeps operations. We take on security leadership, prioritisation and reporting to management and the board.

Security Assessment with Implementation

Count what you already have before you invest

For a fixed CHF 9,800 we measure maturity, surface duplicate licences and prioritise by business risk rather than product catalogue.

In most companies what gets cut pays for a good part of what is missing. That is why this service comes first, not last.

ISMS & ISO 27001

The questionnaire becomes an answer that is already on file

An ISMS answers customer and audit questions once, in a structured way, instead of assembling them from scratch each time. Supply chain and NIS2 requirements from EU customers are covered with it.

The certificate is the visible part. The practical benefit is that sales no longer waits for IT.

More on manufacturing

Energy & critical infrastructure

Around 600 utilities supply Switzerland with electricity. The median distribution grid operator serves just under 1,500 end customers. So the typical Swiss utility carries the duties of a critical infrastructure operator with an IT team of a handful of people. On top of that, grid costs are regulated. Security cannot simply be financed through the tariff, it has to be justified and correctly sized.

Typical trigger: The board or the owning municipality asks about the state of cyber security, and there is no defensible answer.

What we find at utilities

  • Critical infrastructure duties, SME resourcesThe requirements were written for operators with dedicated staff functions. They have to be met by a team that also runs the control room, office IT and the customer portal.
  • Control technology and office IT are convergingTelecontrol, smart meters and vendor remote-maintenance access now sit on the same network as mail and ERP.
  • Remote access nobody fully knows aboutSuppliers have been given access over the years. Who can reach what today is rarely documented properly.
  • Regulated costs, unregulated expectationsEvery franc spent on security has to stand up to the regulator and the owners. Buying a tool is easier than explaining why it was needed.
  • Mandatory reporting assumes a rehearsed processSince April 2025 critical infrastructure operators must report cyber attacks. In many places the process behind that exists only on paper.

Why these services fit

ISMS & ISO 27001

Structure sized to the organisation you actually are

We build the ISMS along ISO 27001 and the Swiss ICT minimum standard, with asset inventory, protection requirements and a supplier overview.

The scope matches 1,500 end customers, not 150,000. A system your team can actually run is worth more than one that impresses an auditor and then nobody.

Security Management & Operations

Remote access and suppliers back under control

We bring order to access, permissions and vendor maintenance, and establish measure tracking that works during normal operations.

Your people stay on the grid. We work off the backlog without the supply suffering for it.

Interim & Fractional CISO

A named responsibility that can also report

For the board, the municipality and the regulator what counts most is that someone can explain the security position in business language and justify the spend.

We take that on as a mandate, with experience from regulated environments and without you having to create a position.

More on energy & critical infrastructure

Financial services

Since the Financial Institutions Act, independent asset managers and trustees are supervised by FINMA as well. Most of them are micro-businesses with fewer than five full-time positions. They have to meet expectations on operational risk and outsourcing that were written for institutions with their own staff functions. On top of that, custodian banks run their own due diligence on the asset managers they work with, with their own questionnaires and their own deadlines.

Typical trigger: The custodian bank or the auditor asks for evidence on IT security and outsourcing, and there is nobody inside who can produce it.

What we find at financial firms

  • Requirements built for large institutions, a team of fiveWhat is a staff function at a bank is an extra job for someone whose actual work is looking after clients.
  • The IT is outsourced, the responsibility is notAn external provider runs the systems. Towards the regulator, the custodian bank and your clients, you are still the one answering.
  • Payment approvals run over mail and phoneThat is exactly where payment fraud starts. Business email compromise was the second costliest fraud category in the FBI IC3 2025 annual report, with around USD 3 billion in reported losses across 24,768 complaints.
  • Compliance costs grow with nobody saying when it is enoughWithout a reference frame, every new requirement is answered with another tool or another mandate.
  • Discretion is the actual productAn incident that becomes public rarely costs systems. It costs mandates.

Why these services fit

ISMS & ISO 27001

Built once, it serves all three audiences

Regulator, custodian bank and clients ask essentially the same things in different formats. An ISMS delivers the evidence in a structured, reusable form.

Every further request becomes routine instead of a special project that blocks half the firm.

Interim & Fractional CISO

Due care that is documented and provable

We take on the named security responsibility and deliver reporting in business language for the board, auditors and the regulator.

That includes the things small institutions most often fall down on: payment approval processes, vetting of IT providers, and an incident plan that actually exists.

Security Assessment with Implementation

Know where you stand before the next budget is signed

A fixed-price assessment shows where you sit against recognised frameworks and which measures actually have an effect.

That is the basis for capping compliance spend instead of rolling it forward every year.

More on financial services

Healthcare & Life Sciences

Swiss acute care hospitals reached an EBITDAR margin of 6.8 percent in 2025. That is better than in previous years, but still clearly below the roughly ten percent needed to self-finance investment. The net margin was back in positive territory for the first time in years, at 1.0 percent (PwC hospital study, July 2026, fiscal year 2025). In plain terms: it is enough to operate, not enough to invest. A security budget in that situation competes directly with medical equipment and staffing. To move anything here you have to argue in downtime and operational risk, not in threat scenarios.

Typical trigger: An incident at another institution, an audit finding, or a tender that demands security evidence.

What we find in healthcare

  • Every franc has to be justified against equipment and staffSecurity only wins that comparison when the benefit is expressed in downtime and operational risk.
  • Medical devices cannot simply be updatedSoftware versions are vendor-approved. An update on your own initiative can affect the device's certification.
  • Operations run around the clockMaintenance windows barely exist. Every change has to fit the clinical routine, not the other way round.
  • Many professions, shift work, high turnoverShared logins are not carelessness. They appear because the process at the bedside has to be faster than the login.
  • Patient data with evidence duties, but no dedicated roleResponsibility ends up with the IT team that is already at its limit.

Why these services fit

Security Assessment with Implementation

A known amount instead of an open consulting bill

CHF 9,800 fixed price, and the result is a prioritised roadmap with measures that actually get implemented.

In an institution where every expense must be justified, predictability is an argument in itself.

Interim & Fractional CISO

Relief for IT, not another load on it

We take on security responsibility instead of leaving it with a stretched IT team, and align measures with clinical operations.

Senior experience on the days it is needed, without another full-time line in the staffing plan.

ISMS & ISO 27001

Protection requirements and evidence, without slowing care

We assess protection requirements and risks along the care processes and document them so the evidence holds up with regulators and partners.

Data protection under the revised Swiss FADP is built in rather than bolted on.

AI Governance & Secure AI Adoption

Clear rules before patient data flows into AI tools

Speech recognition and documentation assistants are in use in many institutions faster than the rules covering them.

We clarify which tools are permitted, which data may go into them, and how that is documented.

More on healthcare

Retail & Logistics

Swiss retail is only growing in part of the assortment. In the first half of 2026, total nominal turnover rose 1.2 percent according to the Swiss Retail Federation, and bricks-and-mortar retail 1.0 percent. Food grew 3.8 percent while bricks-and-mortar non-food shrank by 3.3 percent. Price competition and margin pressure sit at the top of the industry's worry list. At the same time revenue depends directly on IT: tills, warehouse, web shop and dispatch. An outage here does not stop a project, it stops the business.

Typical trigger: An outage in your own operation or at a logistics partner, or a major customer writing security requirements into the framework contract.

What we find in retail and logistics

  • Many sites, each one slightly differentStores, warehouses and branch offices grew over the years. What applies in one building does not apply in the next.
  • High turnover and seasonal staffAccounts are opened quickly and rarely closed cleanly. After two seasons nobody knows who still has access.
  • The cloud environment grew, it was never set upThe baseline settings in M365 date from the migration. Nobody has deliberately reviewed them since.
  • An outage costs revenue from the first minuteTills, warehouse and web shop hang together. There is no grace period in which you calmly restore.
  • The margin leaves no room for security that returns nothingWhere non-food turnover is shrinking, every expense has to either reduce risk or replace another cost.

Why these services fit

Security Management & Operations

Bring every site to the same standard

We harden M365 and cloud, tidy up identities and set conditional access so that store operations and security work together.

One standard across all sites is also the cheaper operation: fewer special cases, less support effort, fewer licences that only one location needs.

Security Assessment with Implementation

Make visible what actually stops the business

We assess along the processes that carry revenue and prioritise by impact on operations rather than technical severity.

The result is an order of work a CFO can sign off on.

Interim & Fractional CISO

One target picture instead of many single measures

We run a security programme with a clear target picture and coordinate delivery across regions and teams.

Progress becomes measurable instead of disappearing into individual projects.

More on retail & logistics

Technology & Software

In software and IT companies the customer's security questionnaire often decides the deal earlier than the product does. If you cannot show an ISO 27001 certificate in a tender, you are filtered out in pre-qualification without ever presenting. At the same time security is nobody's full-time job internally. The CTO answers the questionnaires personally, and those hours are missing from development.

Typical trigger: An enterprise deal is stuck in vendor review and the customer wants evidence rather than assurances.

What we find at technology companies

  • The questionnaire is the real obstacle to the saleIt is not the feature that decides, it is whether you can evidence access control, backup, incident response and supplier management.
  • Without a certificate you are not even invitedIn many tenders ISO 27001 is an admission criterion, not a scoring question.
  • Security work eats development timeEvery questionnaire ties up senior engineers for days. That time is missing from the product and it is the most expensive time in the company.
  • Fast growth, accumulated security debtAccess, environments and the separation of development and production grew with the team, without anyone reorganising them.
  • AI in the product and in daily development, without rulesWhat may go into models and assistants and what may not is rarely defined. Customers now ask about it directly.

Why these services fit

ISMS & ISO 27001

The questionnaire becomes a certificate

We build a lean ISMS and take you to certification without loading a process apparatus onto the engineering team.

The sales cycle shortens because vendor review no longer starts from zero on every deal.

Interim & Fractional CISO

Someone who holds up in the customer's security review

Where it helps, we sit in the vendor review and answer the technical follow-up questions with the necessary experience.

Your engineers stay in engineering, and the customer gets a counterpart who speaks their language.

AI Governance & Secure AI Adoption

Rules for AI that do not slow your team down

We define which data may go into which models, how customer data stays protected, and how that is documented towards customers.

On request as a management system to ISO/IEC 42001, when customers want the formal proof.

More on technology & software

Family Offices

Swiss single family offices run very small core teams. In the 2026 survey by SFOA, UBS and the University of St. Gallen, 61 percent run a team of one to five people, and specialist work is deliberately given to outside partners. On security for the family and the premises, 56 percent offer nothing at all. It is the least covered service in the whole catalogue. At the same time this small team looks after very large assets.

Typical trigger: An attempted fraud on a payment, or a family asking how things stand after an incident in their circle.

What we find in family offices

  • No IT team, distributed infrastructureSystems, service providers, private devices and second residences belong to the same risk picture but to no shared responsibility.
  • Payment approvals under time pressureMail and phone without a binding call-back rule are the most common point of attack. In the FBI IC3 2025 annual report, business email compromise was the second costliest fraud category overall, with around USD 3 billion in reported losses.
  • External providers hold the most confidential documentsFiduciary, legal, IT and administration work with everything. A structured review of those partners rarely happens.
  • There is no plan for the serious caseWho decides, who is informed and who calls the bank tends to be settled during the incident. By then there is no time.
  • Discretion is the actual valueThe damage is rarely technical. It comes from publicity and lost trust.

Why these services fit

Interim & Fractional CISO

Security responsibility without creating a position

Family offices give specialist work to outside partners anyway. Security is exactly that kind of work: too important to do on the side, too small for a dedicated role.

We take it on as a mandate, with one fixed point of contact and no rotating faces.

Security Assessment with Implementation

Know where the family office really stands

We review systems, processes and payment approvals and derive a prioritised plan, sized for a lean structure.

Carried out discreetly, with a result the family understands, not only the IT provider.

Security Management & Operations

Payment processes and providers under control

We establish approvals with a binding call-back rule, vet the external partners and keep the incident plan current.

This is the part that prevents the most frequent and most expensive damage, and it costs less than any technology.

For the personal protection of private individuals and their families we run a separate, discreet offering under Digital Shield.

More on family offices

Sources for the industry figures, always the most recent edition available: Swissmechanic business barometer (May 2026), VSE on the structure of Swiss electricity supply, PwC hospital study (July 2026, fiscal year 2025), Swiss Retail Federation on the first half of 2026, SFOA, UBS and the University of St. Gallen, Swiss Single Family Office Landscape 2026, and the FBI IC3 2025 annual report. As of August 2026.

The principle

Right-sizing security spend

Not a separate service, a principle that runs through every mandate. Many companies have accumulated security tools and licenses over the years that overlap, go unused, or solve problems they do not have. At the same time, basic low-cost measures are often missing.

Book a call

The first step in every mandate

  • What do you already have?
  • What of it works?
  • What can we cut or consolidate?
  • Where is basic protection missing?
  • The result: better protected and spending less
Stimmen

Was Kunden und Partner sagen

FAQ

Here you will find answers to frequently asked questions about our services and expertise.

Two professionals in dark clothing walk through a modern office space with plants, engaging in conversation. Schedule a call without obligations
Who do we work for?

We work with Swiss SMEs between 50 and 500 employees that need senior security expertise without creating a full-time position. Typically management, IT leads and boards of directors, often triggered by an incident, a customer requirement or a regulatory deadline.

What services does ODCUS offer?

Five services around information security: Interim & Fractional CISO, Security Management & Operations as consulting, ISMS and ISO 27001 certification, Security Assessment with implementation, and AI Governance & Secure AI Adoption. One principle runs through every mandate: more protection, fewer tools, less cost.

How does ODCUS support companies with security?

We take responsibility and stay until it is done. Instead of a report that disappears in a drawer, you get operational security leadership, an ISMS that works in daily operations, or an assessment whose measures actually get implemented. The first step is always: what do you already have, what of it works, and what can we cut?

What type of businesses can benefit from our services?

Companies with 50 to 500 employees without a full-time CISO, firms in ISG-regulated sectors with an ISMS deadline by the end of 2026, SMEs that need ISO 27001 for customer requirements, and anyone who feels they spend too much on security without keeping an overview.

What benefits does consulting from ODCUS offer?

We are practitioners, not pure consultants, with an implementation background. We advise vendor-independently, recommendations follow fit, not commission. We right-size security spend, the first step is always what can be cut. And you work directly with the principal, no handoff to junior staff.

How does ODCUS differ from other security consultancies?

Large firms are expensive and impersonal, classic boutiques swap people during a project. At ODCUS the person you meet is the person who does the work. And instead of selling tools, we right-size security: most companies do not have a security problem, they have a sizing problem.

What is important to ODCUS in collaboration?

What matters most is trust on equal terms. We tell you even when the right recommendation is to spend less, and we expect the same openness in return. Honest, direct, and without conflict of interest.