Book an Appointment

vCISO and External Information Security Officer

What distinguishes a CISO from an ISB, what requirements ISO 27001 and NIS2 place on assigning the role – and when filling it externally as a vCISO or vISB makes sense.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

5.3clause in ISO/IEC 27001:2022 – assign and communicate responsibilities
20NIS2 article – management bodies approve and oversee the risk management measures
38§ in the new BSIG (in force since 6 December 2025) – obligations of the management
3operating models established in practice: retainer, interim, project-based

Information security needs a clearly designated role equipped with real authority: BSI Standard 200-2 provides for the appointment of an Information Security Officer (ISB), ISO/IEC 27001 requires in Clause 5.3 that responsibilities be assigned and communicated, and NIS2 explicitly anchors responsibility for security with the management bodies. Not every organisation can or wants to fill this role internally on a full-time basis – skills shortages, insufficient workload in smaller organisations and role conflicts with IT often argue for an external arrangement as a vCISO or virtual ISB. This article puts the role profiles into context, describes the task catalogue and the common operating models – and shows where the limits of delegation lie.

The Essentials at a Glance

Six topic blocks — tap to expand.

Operating models compared

Three basic models have become established in practice – regardless of the model, a written appointment, a role and interface description, deputisation arrangements and confidentiality agreements are part of a clean implementation.

permanent
  • The external vCISO/vISB holds the role permanently with a fixed monthly quota of hours or days.
  • Predictable for recurring tasks such as risk management, reporting and awareness.
  • Complemented by contractually defined response times for incidents.
risk managementreportingawarenessresponse times

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2017

BSI-Standard 200-2: IT-Grundschutz-Methodik

Chapter 4.4 describes the appointment, tasks and requirements profile of the Information Security Officer as well as the role's organisational anchoring with a direct reporting line to management.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

Online-Kurs IT-Grundschutz, Lerneinheit 2.4: Der Informationssicherheitsbeauftragte

BSI online course (accessed 07/2026) with the ISB's task catalogue, the warning about role conflicts when the role is integrated into IT, and guidance on combining it with the DPO function.

ISO/IEC · 2022

ISO/IEC 27001:2022 – Information security, cybersecurity and privacy protection – Information security management systems – Requirements

Clause 5.3 requires responsibilities for security-relevant roles to be assigned and communicated, in particular for ISMS conformity and performance reporting to top management.

Amtsblatt der EU / EUR-Lex · 2022

Richtlinie (EU) 2022/2555 (NIS2)

Art. 20 (governance) obliges the management bodies to approve and oversee the risk management measures under Art. 21 and to attend regular training, and establishes their liability for infringements.

Bundesgesetzblatt (BGBl. 2025 I Nr. 301) · 2025

Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung (neues BSIG)

German NIS2 transposition, promulgated on 5 December 2025 and in force since 6 December 2025; § 38 BSIG governs the management's implementation, oversight and training obligations as well as their internal liability under corporate law.

Filling the role – internally or externally?

If you are assessing whether a vCISO or external ISB is the right path for your organisation, we are happy to walk through requirements and operating models with you in a no-obligation initial consultation.