Contact
Silhouette of a person in front of an illuminated blue circle against a dark background

Library

CISO as a Service

Share via

When is CISO as a Service the right choice?

A CISO on demand is an experienced Chief Information Security Officer who works a fixed number of days per month, or for the duration of an engagement. The remit does not change, from security strategy through to reporting to executive management and the board.

The Dutch Cybersecurity Act has been in force since 15 August 2026 and places ultimate responsibility for cyber risk with the board. That board approves the measures and supervises their implementation. Someone has to hold that brief, including where there is no full-time CISO.

In some cases a full-time CISO is simply not needed. A part-time CISO takes nothing away from the quality. It is the same role, with fewer hours and a sharper focus.

In this article

What does a CISO do exactly?

A CISO determines which risks weigh heaviest, who decides on them and what shows that measures work. The work underneath is familiar and covers security strategy, risk analyses, policy, governance, supplier risk, audits, incident preparation and reporting to executive management and the board. Little of that is new to an IT manager. The difference lies in the coherence, and in the question of who is accountable for it.

At new clients we rarely find a shortage of measures. A penetration test has been carried out, monitoring is running, policy is in place and IT is working hard on improvements. What is missing is the order of priority. Nobody can say which three things come first, and why.

What the Dutch Cybersecurity Act changed

The Dutch Cybersecurity Act is the national implementation of NIS2. Organisations in scope take on obligations around registration, duty of care, incident reporting, risk management, governance and supervision. The heaviest shift sits in the boardroom, because the board approves the measures and supervises their implementation.

A steering committee no longer covers that. A director who approves a package of measures has to be able to explain why that package is sufficient. For that he needs a risk picture he can weigh himself.

For a large organisation a permanent CISO is the logical choice. For mid-sized organisations it is harder, because the responsibility is there while the volume of work does not always justify a full-time position. IT can carry a great deal, but rarely governance, compliance, the threat picture, supplier risk, audit questions and strategy at the same time.

When is a CISO on demand the right fit?

Legislation is the most common trigger. An organisation falls under the Dutch Cybersecurity Act, or expects to, and notices that the questions are becoming governance questions rather than technical ones.

Outside pressure for evidence plays a part as well. Auditors, clients, insurers and supervisors no longer ask whether policy exists, but whether it is applied. That evidence consists of risk analyses, measures, reports, incident processes and improvement plans. ISO 27001, DORA and the GDPR each set their own requirements here.

Change is the third reason. Growth, a merger, a migration to cloud or an OT environment connected to the corporate network shifts the risk profile faster than the internal organisation can follow. Experience, speed and flexibility on demand are then highly desirable.

What the role is not

The board's ultimate responsibility does not transfer. It is assigned in law and stays inside the organisation. That shapes how an engagement is set up, because advice without a decision changes nothing.

A CISO does not replace the IT organisation either. The CISO asks the question, IT implements and the board decides. Once that triangle blurs, responsibility exists without a mandate.

How we set up an engagement

DeepBlue Security & Intelligence staffs CISO as a Service with senior people only. That is a specialist who can move without friction between a director, an auditor and a systems administrator in the same week.

We start with a baseline assessment, a risk analysis or a maturity review, depending on what is already in place. Prioritisation, governance design, board reporting and the guidance of improvement measures follow from there. The pace depends on what the board has to be able to decide next.

A fixed reporting rhythm puts cyber risk on the board agenda structurally. Decisions then rest on trend, progress and substantiation, rather than only on an incident. When the board and executive management see the same overview every quarter, they can ask better questions and steer more precisely.

What does it deliver?

Access to senior expertise without a permanent appointment is the benefit most often named. We consider independence to weigh heavier. An external CISO assesses existing choices, suppliers and priorities without an interest in the outcome.

Speed counts as well. Recruiting an experienced CISO takes months, while an audit question or an incident pays no attention to that lead time. The commitment also scales. One day a month is often enough for prioritisation and reporting, and around an audit, a merger or a testing programme more is needed.

From policy to evidence

Policy only gains value once it is tested. We therefore connect plans to technical validation, logging, incident preparation, supplier assessments and concrete improvement actions. Penetration testing establishes whether measures hold up under realistic attack conditions, and compliance and governance records what makes a board decision defensible.

Three questions show whether that translation has worked. Which risks weigh heaviest for this organisation? Who decided on them? What shows that the measures work?

If one of the three stays unanswered, there is policy but no direction. In complex IT and OT environments that shows up fastest. Directors rely there on a risk picture they cannot verify themselves, and technical teams wait for priorities that nobody sets.

Conclusion

CISO as a Service fits organisations that have to govern cyber risk without a full-time CISO being justified. The role delivers direction, interpretation and progress at the point where pressure builds from legislation, clients, auditors or threat.

The boundary stays the same. We advise, structure and report, and the decision remains with the board. What the role adds is that the board can take that decision on a substantiated basis.

Sources

Cyberbeveiligingswet, Bulletin of Acts 2026, 187 | NCTV, Cyberbeveiligingswet legislation and regulations | NCSC, Cbw and Wwke in force from 15 August 2026 | Directive (EU) 2022/2555, NIS2 | Regulation (EU) 2022/2554, DORA | ISO/IEC 27001, Information security management systems

Last reviewed: 4 September 2026.

← Back to library

Direct access to senior cybersecurity expertise

Discuss a security requirement, active risk or complex IT or OT environment with one of our senior specialists. The initial conversation focuses on the technical context, operational constraints and the most appropriate course of action.

  • No mailing lists or automated sales follow-up
  • Information is handled confidentially

Urgent assistance required?

Call +31 (0) 70 290 6 290
or email  info@deepbluesecurity.nl

Thank you. The message has been received and will be reviewed by one of our specialists.
The form could not be submitted. Please try again or contact info@deepbluesecurity.nl.