Book an Appointment

vCISO and External Information Security Officer

What distinguishes a CISO from an ISB, what requirements ISO 27001 and NIS2 place on assigning the role – and when filling it externally as a vCISO or vISB makes sense.

Information security needs a clearly designated role equipped with real authority: BSI Standard 200-2 provides for the appointment of an Information Security Officer (ISB), ISO/IEC 27001 requires in Clause 5.3 that responsibilities be assigned and communicated, and NIS2 explicitly anchors responsibility for security with the management bodies. Not every organisation can or wants to fill this role internally on a full-time basis – skills shortages, insufficient workload in smaller organisations and role conflicts with IT often argue for an external arrangement as a vCISO or virtual ISB. This article puts the role profiles into context, describes the task catalogue and the common operating models – and shows where the limits of delegation lie.

The Essentials at a Glance

01

Role profiles: CISO and ISB compared

The Information Security Officer (ISB, Informationssicherheitsbeauftragter) is the role established in German-speaking countries under BSI IT-Grundschutz: it steers and coordinates the security process, supports management with the security policy, coordinates the creation of the security concept, investigates security-relevant incidents and reports directly to top management (BSI Standard 200-2, chapter 4.4). The BSI standard names Chief Information Security Officer (CISO) and Information Security Manager (ISM) as common alternative titles for the same role; in international usage, CISO moreover often denotes a strategic leadership role with responsibility for security strategy, budget and organisation, frequently with its own team and a position directly below executive management. In practice the two profiles overlap heavily, and in smaller organisations one person often covers both perspectives. What matters is less the title than the clear assignment of tasks, authority and reporting lines.

02

Requirements from ISO 27001 Clause 5.3 and NIS2 Art. 20

ISO/IEC 27001:2022 requires in Clause 5.3 that top management assign and communicate responsibilities and authorities for security-relevant roles – in particular for the ISMS's conformity with the standard and for reporting on its performance to top management; Annex A control 5.2 additionally calls for defined security roles. The standard does not prescribe a specific title such as “CISO”. NIS2 (Directive (EU) 2022/2555) obliges, in Art. 20, the management bodies of essential and important entities to approve the risk management measures under Art. 21 and oversee their implementation; they can be held liable for infringements and must attend training. In Germany, the new BSIG (NIS2 Implementation Act), in force since 6 December 2025, transposes these obligations: § 38 BSIG obliges the management of particularly important and important entities to implement the risk management measures, monitor their implementation and attend training on a regular basis.

03

Task catalogue of an ISB/CISO

At the core of the role is steering the entire security process: contributing to the security strategy and policy, building and maintaining the body of policies, and coordinating the security concept. Added to this are risk management (methodology, risk analyses, action plans and their follow-up), initiating and coordinating awareness and training measures, and investigating security-relevant incidents. Towards management, the role owns management reporting – status reports, key figures and input to the management review under ISO/IEC 27001 Clause 9.3. It also covers providing security support for projects and procurement as well as preparing internal and external audits.

04

When an external appointment makes sense

BSI Standard 200-2 explicitly provides in chapter 4.11 for having key roles such as the ISB performed by qualified external specialists if they cannot be filled internally – especially in small companies and public authorities, drawing on an external ISB can be expedient. Common triggers are a lack of qualified staff, a role that does not sustain a full-time position, or a vacancy that needs to be bridged at short notice. The required independence can also be an argument: the BSI explicitly warns of role conflicts when the ISB is integrated into the IT department and cannot perform its oversight duties free from influence; combining the role with that of the data protection officer is, in the BSI's view, not uncritical and only acceptable where the interfaces between both duties are clearly defined. External role holders also bring experience from many organisations and certification procedures. The prerequisite is that an internal point of contact is designated and the external role holder is given access to committees, information and decision-making channels – without that integration, the role remains ineffective.

05

Operating models: retainer, interim, project-based

In practice, three basic models have become established. In the retainer model, the external vCISO/vISB holds the role permanently with a fixed monthly quota of hours or days – predictable for recurring tasks such as risk management, reporting and awareness, complemented by contractually defined response times for incidents. The interim model bridges a vacancy with a high level of presence, is clearly time-limited and ends with the position being refilled or handed over. Project-based models support an initiative with a defined goal, such as building an ISMS to certification readiness; hybrid variants combine the external role with coaching an internal junior until handover. Regardless of the model, a written appointment, a description of the role and its interfaces, deputisation arrangements and confidentiality agreements are part of a clean implementation.

06

Limits: overall responsibility stays with executive management

Neither internally nor externally can responsibility for information security be handed off entirely: under BSI Standard 200-2, overall responsibility remains with the top management level – it decides how risks are handled and provides the resources, even when it delegates operational tasks. NIS2 Art. 20 and § 38 BSIG explicitly address the approval or implementation and oversight of the risk management measures, as well as training participation, to the management bodies themselves; § 38 Abs. 2 BSIG attaches to this an internal liability of managing directors under the rules of corporate law. An external vCISO/vISB advises, steers the security process and prepares decisions – risk acceptance, approval of the policy and budget decisions are taken by executive management itself. Credible operating models make this division of labour explicit, for instance through defined escalation and reporting channels and a documented decision paper for each risk.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2017

BSI-Standard 200-2: IT-Grundschutz-Methodik

Chapter 4.4 describes the appointment, tasks and requirements profile of the Information Security Officer as well as the role's organisational anchoring with a direct reporting line to management.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

Online-Kurs IT-Grundschutz, Lerneinheit 2.4: Der Informationssicherheitsbeauftragte

BSI online course (accessed 07/2026) with the ISB's task catalogue, the warning about role conflicts when the role is integrated into IT, and guidance on combining it with the DPO function.

ISO/IEC · 2022

ISO/IEC 27001:2022 – Information security, cybersecurity and privacy protection – Information security management systems – Requirements

Clause 5.3 requires responsibilities for security-relevant roles to be assigned and communicated, in particular for ISMS conformity and performance reporting to top management.

Amtsblatt der EU / EUR-Lex · 2022

Richtlinie (EU) 2022/2555 (NIS2)

Art. 20 (governance) obliges the management bodies to approve and oversee the risk management measures under Art. 21 and to attend regular training, and establishes their liability for infringements.

Bundesgesetzblatt (BGBl. 2025 I Nr. 301) · 2025

Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung (neues BSIG)

German NIS2 transposition, promulgated on 5 December 2025 and in force since 6 December 2025; § 38 BSIG governs the management's implementation, oversight and training obligations as well as their internal liability under corporate law.

Filling the role – internally or externally?

If you are assessing whether a vCISO or external ISB is the right path for your organisation, we are happy to walk through requirements and operating models with you in a no-obligation initial consultation.