
Senior security leadership, when you need it
In our experience, a full-time CISO costs well over CHF 200,000 per year. Most SMEs do not need that capacity permanently, but they still need the expertise. We take on operational security leadership on a mandate basis, 1 to 4 days per week, 3 to 12 months. Not advice from the outside, but leadership from within. And we stay until it stands.
Why it matters:
The board is liable. Its duty of care under Art. 717 of the Swiss Code of Obligations today includes cybersecurity, and the revised Data Protection Act (nDSG) provides for personal fines of up to CHF 250,000. Security leadership is therefore no longer optional, it is documented proof of due diligence. An interim CISO brings the experience without the fixed costs and without a long-term commitment.
What you receive:
- Build or take over risk management
- Align the security strategy with business goals
- Security reporting for management and the board
- Assess and right-size existing measures
- Coordinate incident response
- Manage suppliers and partners
What a mandate covers in practice
The three areas where a Fractional CISO makes the biggest difference.

Risk management
Risk management that enables decisions instead of producing lists.
- Risk analysis with a business focus
- Evaluation models for decisions
- Clear protection priorities
- A management-ready risk overview

Security reporting for management and board
Documented proof of due diligence, understandable for non-technical readers.
- Board-ready security reports
- KPIs instead of jargon
- Proof of the duty of care
- Decision templates

Incident response
Preparation and coordination, before and while it burns.
- Incident response plan
- Roles and escalation paths
- Exercises and real-case coordination
- Lessons learned
Mandate or consulting?
With the Fractional CISO we take the role and the responsibility, embedded in your organization. If you want to stay in charge and only bring in senior expertise on specific topics, Security Management & Operations is the right path, the same breadth, but as consulting.
The ODCUS difference
No selling of additional tools. The first step is always: what do you already have, what of it works, and what can we cut? Most mandates begin by lowering costs and improving protection at the same time.
Who this is for
- Companies with 50 to 500 employees without a full-time CISO
- After an incident or audit
- Before a certification or regulatory requirement
- When the board makes security a top priority
References from practice
- Active CISO mandate for over 2 years at an international industrial company (1,600 employees)
- Cybersecurity strategy developed and implemented following the NIST Framework 2.0
- Zero Trust program set up and steered (identity, endpoints, apps, network, data)
- Led ransomware recovery, threat management during a complete rebuild
- CISM certified (ISACA), trainer at heise Academy, Haufe Akademie, golem.de
What is the difference between a Fractional CISO and an IT security officer?
The IT security officer is often an internal person with limited time and experience. A Fractional CISO brings senior experience from many mandates, takes on strategic leadership, and reports directly to management and the board.
How quickly can a mandate start?
Usually within two to four weeks after the initial conversation. We start with a short situation assessment and the most pressing topics.
What happens at the end of the mandate?
We build things so that they keep running without us. At the end you have a working security management setup, documented and anchored in daily operations, not a report in a drawer.
How many days per week does an SME need?
Usually 1 to 2 days per week. More at the start or in intense phases, often less later. We adapt the cadence to the actual need, not to a fixed package.
From what size does a Fractional CISO make sense?
In our experience from around 50 employees, at the latest when a major customer, a cyber insurer, or the board requests proof of security. Below that, occasional consulting is often enough.
What is the difference from a vCISO or CISO as a Service?
The terms mean essentially the same thing: external security leadership on a mandate basis. What matters more than the label is that someone actually carries the responsibility and stays until it stands.
"ODCUS accompanies us as a partner on questions and challenges around IT and ensures that the digital and technological resources we use are secure and protected."
Security leadership that stays
Discuss without obligation whether a Fractional CISO mandate fits your company. In 30 minutes you will know where you stand.


