Book an Appointment
ISB · CISO · AI Officer

ISB, CISO & AI Officer compared:
The right model for your organization

NIS2, DORA and the EU AI Act demand clear governance roles — with personal liability for executive management. We help you find and build the right role structure: internal, external or hybrid.

Valeri Milke — ISO 27001 & 42001 Lead Auditor, AI Officer, NIS2 & DORA expert
NIS2DORAEU AI ActISO 27001ISO 42001GDPR
Governance roles

Six roles — one goal: compliance & resilience

Each role carries clear responsibilities, regulatory requirements and personal accountabilities. Do you know your gaps?

ISB / vISB

Information Security Officer

Responsible for ISMS operation, risk management and compliance per ISO 27001 & BSI.

ISO 27001BSI IT-GrundschutzNIS2
CISO / vCISO

Chief Information Security Officer

Strategic steering, leadership responsibility, budget and reporting to executive management.

NIS2DORAISO 27001
AI Officer

AI Officer

Responsible for AI governance, risk classification and transparency obligations per EU AI Act.

EU AI ActISO 42001GDPR
DSB

Data Protection Officer

GDPR compliance, record of processing activities, data protection impact assessment.

GDPRBDSGEU AI Act
ISK

Information Security Coordinator

Internal contact who coordinates the implementation of security measures. Link between ISB and operational units.

ISO 27001NIS2
ISM

Information Security Manager

Operational steerer of the ISMS. Responsible for audits, risk assessments and continuous improvement.

ISO 27001BSI IT-GrundschutzDORA
Personal liability

NIS2, DORA & AI Act: who is bound by what?

Regulators hold executives personally liable. Missing or misplaced governance roles are not an operational issue but a board-level issue.

NIS2
ISB/CISOExecutive management

Risk management, reporting obligations, governance responsibility. Personal liability of management bodies up to €10M or 2% of annual turnover.

DORA
CISOISBExecutive management

ICT risk management, TLPT, third-party management in the financial sector. Personal liability of management bodies.

EU AI Act
AI OfficerExecutive management

AI risk classification, transparency, documentation. Fines up to €30M or 6% of global annual turnover.

Personal liability of management bodies — even without own involvement in security incidents.
Structure decision

Internal, external or hybrid?

The right structure depends on the size, budget and maturity of your organization. Our 24-month coaching approach builds internal competence — without creating dependency.

Internal

Advantages
  • Deep company knowledge
  • Full availability
  • Cultural integration
Challenges
  • Skill shortage
  • High cost (€80–150k+ p.a.)
  • Operational blindness
  • Lack of specialization

External (vCISO/vISB)

Advantages
  • Immediately operational
  • Broad expertise
  • Cost-efficient
  • Regulatorily up-to-date
Challenges
  • Limited availability
  • Dependency on vendor
Build ISK/ISM

From dependency to resilience — in 4 phases

Our structured 24-month coaching approach builds internal competence and creates real resilience instead of dependency.

01
Onboarding

vCISO/vISB takes over completely. ISK observes, learns and builds understanding.

02
Co-working

ISK takes over first operational tasks under supervision of the vCISO.

03
Transfer

ISK/ISM steers independently. vCISO acts in review mode as sparring partner.

04
Handover

Internal ISM/ISB takes over completely. vCISO remains as strategic advisor.

05
Audit-ready

Organization is resilient, compliant and independently positioned.

Our services

From role analysis to audit readiness

01

Role analysis & gap assessment

Systematic analysis of your current role structure, responsibilities and regulatory obligations.

02

vCISO / vISB as a Service

Full takeover of the strategic or operational CISO/ISB function — immediate, flexible, compliance-conformant.

03

AI Officer & AI governance

Build-up and operation of the AI Officer function per EU AI Act, ISO 42001 and GDPR.

04

Coaching & knowledge transfer

Structured 24-month build-up of internal competence — from introduction to independent steering.

05

Certification support

Preparation for ISO 27001, ISO 42001, BSI IT-Grundschutz and industry-specific audits.

06

Regulatory compliance

NIS2, DORA, EU AI Act, CRA, GDPR — we keep you compliant and personally liability-safe.

Deadlines

The clock is ticking — act now

Jan 2025
EU AI Act

Art. 4 & 5: bans on unacceptable AI systems in force.

Feb 2025
EU AI Act

GPAI governance requirements for general-purpose AI models.

Aug 2025
EU AI Act

High-risk AI systems: full requirements apply.

Aug 2026
EU AI Act

Art. 6(1) Annex I: further high-risk categories in force.

2027
AI Act / NIS2

Full enforcement, sharpened supervision & fines.

ISB, CISO or AI Officer?
Internal, external or hybrid?

Book a free initial consultation and find out which model fits your organization — before liability questions are brought to you.