
IT security, right-sized
Five services around information security for Swiss SMEs. More protection, fewer tools, less cost.
Five services, one principle
Security leadership, consulting, ISMS and assessment. One thread runs through all: more protection, fewer tools, less cost.
Interim & Fractional CISO
Security leadership without a full-time hire. Operational responsibility on a mandate basis, 1 to 4 days per week, we stay until it is done.
Learn more →Security Management & Operations
Full security expertise as consulting. Senior support on specific topics while your IT leadership stays in charge.
Learn more →ISMS & ISO 27001
Information security that works in daily operations. From assessment to certification readiness, no paper tiger.
Learn more →Security Assessment with Implementation
No shelf reports. A prioritized assessment with measures that actually get implemented, measured by business risk.
Learn more →AI Governance & Secure AI Adoption
Use AI without losing control over your data and knowledge. Usage policies, AI risk analysis, nDSG-compliant adoption and, on request, an AI management system based on ISO/IEC 42001.
Learn more →The principle
Right-sizing security spend
Not a separate service, a principle that runs through every mandate. Many companies have accumulated security tools and licenses over the years that overlap, go unused, or solve problems they do not have. At the same time, basic low-cost measures are often missing.
Book a call →The first step in every mandate
- What do you already have?
- What of it works?
- What can we cut or consolidate?
- Where is basic protection missing?
- The result: better protected and spending less
Was Kunden und Partner sagen
FAQ
Here you will find answers to frequently asked questions about our services and expertise.

Who do we work for?
We work with Swiss SMEs between 50 and 500 employees that need senior security expertise without creating a full-time position. Typically management, IT leads and boards of directors, often triggered by an incident, a customer requirement or a regulatory deadline.
What services does ODCUS offer?
Five services around information security: Interim & Fractional CISO, Security Management & Operations as consulting, ISMS and ISO 27001 certification, Security Assessment with implementation, and AI Governance & Secure AI Adoption. One principle runs through every mandate: more protection, fewer tools, less cost.
How does ODCUS support companies with security?
We take responsibility and stay until it is done. Instead of a report that disappears in a drawer, you get operational security leadership, an ISMS that works in daily operations, or an assessment whose measures actually get implemented. The first step is always: what do you already have, what of it works, and what can we cut?
What type of businesses can benefit from our services?
Companies with 50 to 500 employees without a full-time CISO, firms in ISG-regulated sectors with an ISMS deadline by the end of 2026, SMEs that need ISO 27001 for customer requirements, and anyone who feels they spend too much on security without keeping an overview.
What benefits does consulting from ODCUS offer?
We are practitioners, not pure consultants, with an implementation background. We advise vendor-independently, recommendations follow fit, not commission. We right-size security spend, the first step is always what can be cut. And you work directly with the principal, no handoff to junior staff.
How does ODCUS differ from other security consultancies?
Large firms are expensive and impersonal, classic boutiques swap people during a project. At ODCUS the person you meet is the person who does the work. And instead of selling tools, we right-size security: most companies do not have a security problem, they have a sizing problem.
What is important to ODCUS in collaboration?
What matters most is trust on equal terms. We tell you even when the right recommendation is to spend less, and we expect the same openness in return. Honest, direct, and without conflict of interest.