Cybervize

Meet NIS-2, DORA, ISO 27001. With a CISO you don't have to hire.

Cybervize takes on the CISO function in two ways. As a Virtual CISO permanently, with a fixed capacity of two to six days per month, from 3,600 euros per month. As an Interim CISO for a fixed term, when the role is vacant or an incident has to be worked through; that route is priced per engagement. Alongside it the ISMS platform OdySecure for IT and OT, from mid-market to enterprise: ISMS, BCM, Assessment and Third-Party Risk Management with security assessments against ISO 27001, IEC 62443, IT-Grundschutz, NIST or your own standards. AI under your own control, data residency in Germany.

We take on the CISO function. Interim until the role is filled, or permanently. As a vCISO from €3,600 per month.

Intro call: free, 30 minutes, with a senior CISO.

References

  • Moonfare: Cybervize as Interim CISO for the DORA implementation and the ISO 27001 audit
  • Support with the introduction of NIS-2 in the energy sector
  • Carve-out as Interim CISO: building up information security at an international mechanical engineering company
  • Support for several acquisitions with M&A cybersecurity assessments for an insurance company

Memberships, programmes and partnerships

  • BSI Allianz für Cyber-Sicherheit
  • CISPA Helmholtz-Zentrum für Informationssicherheit
  • TeleTrusT - Bundesverband IT-Sicherheit
  • IT Security Made in Germany - TeleTrusT
Virtual CISO

The CISO function, filled.

A senior CISO takes on the role in your organisation and leads your NIS-2, DORA or ISO 27001 work until it can be evidenced.

What you get

A filled function

We carry out the work and keep your executive board informed (C-level reporting).

Evidence in OdySecure

The work runs on our platform. The licence is included in the mandate.

Support through audits

We prepare audits and inspections with you and support you on the day.

Three tiers
  • Basicfrom €3,600 a month, approx. 2 days
  • Standard€4,900 a month
  • Seniorapprox. €8,500 a month, 5 to 6 days

Minimum term 6 months, then cancellable monthly.

What each tier includes
Three typical situations
  • Regulatory requirementsNIS-2, DORA or ISO 27001 must be met and evidenced. vCISO
  • VacancyYour CISO post is open. An interim CISO bridges the gap for a fixed term, project-based at €8,000 to €15,000 a month. Interim CISO
  • Acquisition or carve-outAfter closing, build the security function in the acquired company or in the carved-out unit. M&A support
vCISO and platform

Your vCISO works with OdySecure.

Your vCISO runs your information security management system in OdySecure, our own platform. The requirements that apply to your organisation, for example from NIS-2, DORA or ISO 27001, sit there alongside risks, measures and evidence in a single data set. That is why evidence is produced in day-to-day operations rather than in the days before the audit, and why the monthly report to your management board comes from the same data. The platform is included in the mandate. Cybervize developed it from its own consulting practice, funded by the German federal government's StartupSecure programme and in a 14-month partnership with the CISPA incubator, the Helmholtz Center for Information Security.

Platform included in the mandateEvidence in operations, not before the auditCISPA partnership
Our story

Two routes, one firm

The vCISO mandate fills your CISO role and implements the regulatory requirements your organisation faces, with OdySecure as our tool. If the role is already filled on your side, license the platform on its own. Both run on the same data foundation, are operated in Germany and stay under your control.

Vacancy or crisis? An Interim CISO takes over for 3 to 12 months, on-site if needed. Go to Interim CISO

Only need to know whether NIS-2 applies?

In the risk check we establish in 30 minutes whether NIS-2 applies to your company and which five gaps matter most. Free and without obligation.

Book the risk check The journey in 5 stations

Looking for cybersecurity for mid-market companies? That page brings vCISO, NIS-2, ISO 27001 and our other services together.

Your vCISO's tool: five modules, one data set

We call the model behind it the ISMS operating system: requirements, risks, measures and evidence come together in one connected data model. Compliance is created in operations, not next to them.

OdySecure

OdySecure amplifies the effectiveness of your security lead or team. ISMS, risk management, assessments, BCM and third-party risk management in one system. With built-in LLMs, Made in Germany.

Discover the platform
OdySecure dashboard with risk heatmap, incidents and KPI cards

Everything in one place

No switching between tools. From assessment gaps you create measures with one click, BIA data validates BCM plans, supplier risks link to assets.

AI as a teammate

Integrated LLM service assists with risk assessment, contract analysis and assessment summaries. Hosting exclusively in Germany.

50frameworks as a catalogue in the platform:standards and frameworks, regulatory requirements, requirement records per entry.See the full list

What the AI takes over

You do not fill in an ISMS. You feed it your documents.

OdySecure derives what applies in your organisation from your documents and your structure: from business process to security process, each station a proposal a human accepts. Under a vCISO mandate, your vCISO does this for you.

Your documents: process descriptions, network plans, contracts, existing policies
  1. 1Business process
  2. 2Asset
  3. 3Risk
  4. 4Measure
  5. 5Control
  6. 6Policy
  7. 7Security process

A human decides at every station. The AI proposes; you accept the proposals one by one or per station, and each approval records who signed it off.

How the derivation works

Where do we stand? Sourced answers instead of gut feeling.

The AI that names its sources and says no when data or read permission is missing. Questions are logged for audit.

Management teams, supervisory boards and auditors all ask the same question. The AI layer of OdySecure answers it from your real data, not from assumptions.

OdySecure Navigator: sourced answers

Available

The assistant answers questions like "What are our biggest risks?" or "Are we audit-ready?" from your tenant's real data: around 25 vetted queries, every answer with source and metric, strictly within read permissions. If there is no data or no read permission, it says exactly that. Read-only is the deliberate limit of the answer: it never acts on its own. It prepares actions; only your confirmation triggers them.

AI agents: acting with approval

Design-partner programme

AI as an employee: its own account, roles, a visible AI-agent badge. Suggesting is the default; acting is limited to narrowly defined fields and requires four-eyes approval. Hard locks always apply: no closing incidents, no risk acceptance, no approvals, no granting of rights. First use case: initial incident triage with indicative NIS-2 deadline hints.

Sovereign in operation, humans stay accountable

This is how the AI layer is built (OdySecure Navigator available, AI agents in a design-partner programme, not yet generally available):

  • Sovereign mode: local LLM operated in Germany, no data passed to external model providers.
  • AI system inventory: every agent is added automatically; a human classifies and confirms before activation. This is your own record, not a filing with any authority.
  • Human in the loop: a kill switch pauses any agent instantly, access keys expire at the term set for them, actions are in the audit log.

Ask first, then act, always verifiable.

Client voice

Moonfare
“Alexander Busse supported us with Cybervize as Interim CISO in the DORA implementation and the ISO 27001 audit. We achieved both.”
Lorenz Jüngling, Co-CEO & Managing Director, MoonfareTranslated from the German original.A reference call is available on request, arranged through us.

Talk to us about your CISO function.

In the intro call we establish which requirements apply to your organisation and how we would fill the CISO role. Free, 30 minutes, with a Senior CISO.

Book an intro call

The Cybervize Podcast

Cybersecurity insights: Interviews with CISOs from Vodafone, Red Bull, Trade Republic and more.

28 Episodes
Top CISOs as Guests
Practice over Theory
Discover all episodes

Cybervize Podcast on Spotify

Spotify sets cookies. By clicking you consent to data transfer to Spotify.