Stage 3 · Ongoing Operations

External CISO / ISMS-as-a-Service

You have the obligation, but rarely the position. We take on the security officer role or support your internal CISO.

Duration:ongoing, from 12 months
Price from:€890/month excl. VAT
Enquirekontakt@maplee.de

from €890/month

excl. VAT · ongoing, from 12 months

Get in touch

The certificate is on the wall, the project team is back in day-to-day operations — and a year later the surveillance audit is approaching while the risk assessment dates from last year and half the measures are overdue. This is the normal case, not the exception. An ISMS rarely fails in the build; it almost always fails in operation.

We take over this operation — as your external information security officer or as support for your internal CISO. Reliably, with a fixed rhythm, at a predictable monthly rate.

Who it's for

  • Companies that need a security officer function but don't want to create a headcount — the typical case between 50 and 500 employees
  • Companies with an internal CISO in a part-time or dual role who needs relief and expert backing
  • Freshly certified companies that don't want operations to go dormant again
  • Companies where the security officer role depends on one person and who want to hedge that risk

The situation

An ISMS is not a project. It is an operational state. An external security officer at conventional providers spends a significant part of their time hunting down information. In a system that answers these questions itself, that work disappears — and the same monthly fee buys you substantially more substantive value.

How it works

  1. 01

    Ongoing ISMS operations

    Maintenance of risks, measures, and controls · monitoring of deadlines and review cycles · following up on overdue measures · updating the asset and risk register · maintaining controlled documents including approval cycles.

  2. 02

    Governance and reporting

    Quarterly report to management with KPIs, open risks, and decision items · annual management review, prepared and facilitated · updating security objectives.

  3. 03

    Audit cycle

    Preparation of surveillance audits · assembly of evidence · attendance during the audit · tracking of findings through to closure.

  4. 04

    Point of contact in emergencies and daily life

    Support during security incidents — assessment, documentation, reporting process as required · answering security questionnaires · expert input on new initiatives and suppliers.

What you receive

ErgebnisForm
Package S: 0.5 day/month · risk, measure, and control maintenance · quarterly report · management reviewfrom €890/month excl. VAT
Package M: 1 day/month · everything in S plus active measure management · preparation of surveillance auditsfrom €1,650/month excl. VAT
Package L: 2 days/month · everything in M plus assumption of the named CISO role · incident supportfrom €2,900/month excl. VAT

Details

Term12 months, renewed annually
Notice period3 months before term end
Prerequisiteexisting ISMS or simultaneous build via the ISMS Implementation
IdealISMS in Jira and Confluence — more substance per hour
Availabilitybusiness days during office hours, named point of contact

Not included

We are your security officer, not your IT department: technical operations, hardening measures, patch management, and system administration remain with you or your IT provider. Also not included: 24/7 on-call, forensic analysis, data protection officer function, and legal advice.

Frequently asked questions

Yes, the function can be held externally — common practice in mid-market companies. Management's own responsibility remains unaffected: it can delegate tasks but not its duty to approve and oversee.

Interested? Get in touch.

We typically respond within one working day.

kontakt@maplee.de