External Information Security Officer

Your information security in expert hands

We support you and your internal information security officer or, as your external partner, we take on the entire implementation project.

  • Certified experts and specialized lawyers
  • Proactive vulnerability analysis and effective NIS-2 compliance
  • For every size of company – from start-ups to conglomerates
ISO 9001
BvD member
GDD member
Made in Germany
20 years of experience
  • Federal Office for Information Security
  • Compliant with GDPR
  • BvD member
  • GDD member
  • Made in Germany
✓ Interdisciplinary team ✓ certified experts ✓ pragmatic implementation
Consultant

Marvin Süß

Signature Asmus Eggert

What the external information security officer takes on for you

We appoint an external information security officer as a permanent, central point of contact for all information security issues.

This includes the establishment and development of your security organization, the maintenance of security policies and guidelines, and the management of security needs assessment, risk management, service providers, and the supply chain. The information security officer supports IT projects, internal and external audits, and security incidents, including reporting obligations, coordinates vulnerability management and scans, and monitors the effectiveness of adopted measures. In addition, it identifies training needs, plans awareness measures, and reports to the management, which it supports in its leadership duties.

Prices & Packages

Our packages for your
Information Security Consulting

In all packages

Multilingual support

Personal contact person

Certified information security experts

Light

For small businesses

from 1.250€

/Month

net

  • External Information Security Officer (ISB)
  • Conducting a needs analysis and risk assessment
  • Creation of an information security policy
  • Drawing up a plan of action
  • Expert guidance and advice on establishing an ISMS
  • Access to ISMS templates
  • Contactability by phone or email

Pro

Popular

For growing companies

from 2.400€

/Month

net

All services from Light, plus:

  • One fixed contact person with representation
  • Monitoring and control of the ISMS
  • Consulting and support in the drafting of guidelines
  • Concrete recommendations for optimizing the process
  • Audit preparation
  • Training
  • Response times within one business day
  • Monthly status reports
  • An annual internal audit

Individual

For individual requirements

individual

Offer
upon request

  • Tailored to your exact requirements
  • Consulting as needed

Lawyers of Eggert & Partner Lawyers · Service in Germany · All prices are net excluding VAT.

our approach

How to get started with an external information security officer

We look forward to working with you. Please do not hesitate to contact us.

Step 01

Free initial consultation

We offer a free initial telephone consultation to discuss with you the current state of information security in your company.

Step 02

Needs analysis

Together we understand the current state, risks, and goals – both technically and organizationally.

Step 03

Customized offer

Based on your current situation and the coordinated approach, we will create an offer that is tailored directly to your needs.

Step 04

Start of consulting

After signing the consulting contract, our information security experts will begin the consulting process.

Step 01

Free initial consultation

We offer a free initial telephone consultation to discuss with you the current state of information security in your company.

Step 02

Needs analysis

Together, we understand the current state, risks, and goals – both technically and organizationally. Often, an advanced information security checkup is useful to assess the current situation.

Step 03

Customized offer

Based on your current situation and the coordinated approach, we will create an offer that is tailored directly to your needs.

Step 04

Start of consulting

After signing the consulting agreement, our information security experts begin the consulting process – usually with a kick-off meeting including a presentation of all the participants.

Asmus Eggert, CEO and lawyer of mip Consult GmbH
Asmus Eggert · CEO & Attorney

Do you need an external information security officer?

Non-binding · 15 minutes · Free

Frequently asked questions

Is appointing an information security officer legally required?

Not for most companies. The BSIG requires affected facilities to take risk management measures, but does not specify any specific role. Designation is mandatory for operators of critical facilities and in certain regulated industries. The role is nevertheless useful: Without designated responsible parties, implementation cannot be held up by anyone.


Can our data protection officer take on the role?

This is legally controversial. According to Article 38(6) GDPR, additional tasks are only permitted if they do not create a conflict of interest and the supervisory authorities assess this case differently: Thüringen rejects the combination, Lower Saxony advises against it, Saxony is nuanced, the BSI calls it „not uncritical“. It gets critical as soon as the same person decides on measures and budget that they would have to control as data protection officer – then they control themselves. We look at your specific situation before you make a decision.


When does a company need information security advice?

The need for information security management arises not primarily from legal regulations (exception: critical infrastructure), but rather from the individual assessment of one’s own vulnerability or threat.

The impact of NIS-2 on an organization depends on its cybersecurity maturity: Highly regulated industries such as healthcare may already meet many of the requirements, while less regulated sectors could face major challenges.

Does our management need to be trained themselves?

Yes, if your company falls under the BSIG. The management must approve the risk management measures, arrange for their implementation and monitor it, and participate in regular training. The law does not specify a fixed frequency. The management is personally liable for breaches of duty towards the company.


What does the external information security officer take on, and what stays with us?

It’s up to you: We support you and your internal information security officer, or we, as your external partner, take on the entire implementation project. We discuss what is appropriate in your case in the needs analysis, and together we understand the current situation, risks, and goals, both technically and organizationally.


Other services

Information security services,
that suits your company.