External ISB: When the information security officer is worthwhile as a service
An external information security officer closes a gap that many companies only notice during the NIS 2 audit. This article shows when ordering externally is faster, cheaper and more audit-proof than an internal solution.
With the national implementation of the NIS 2 guideline in the NIS2UmsuCG and the full effectiveness of the ISO/IEC 27001:2022 standard since October 2025, the role of the information security officer (ISB) in German companies has gone from nice-to-have to mandatory for around 29,500 affected companies. The supervisory authority expects a named, qualified and independent person, a documented reporting line to management and a functioning information security management system (ISMS) with 93 Annex A controls. Anyone who wants to meet these requirements with internal on-board resources will in most cases run into a personnel and qualification bottleneck.
This article compares the external ISB with internal solutions along six criteria that are actually tested in NIS 2 audits and ISO certifications: appointment and independence, qualifications and representation, response time to security incidents, cost structure, distribution of liability and audit sensitivity. It is written for the typical German medium-sized constellation with 80 to 500 employees, in which a full-time CISO is not economically viable, but a pure IT manager dual function is legally critical. CIVAC delivers the operating model as a compliance platform and officer-as-a-service with German legal orientation.
Key Takeaways
- An external ISB is usually operational within 2 working days with an appointment certificate, deputy and reporting line, compared to 2 to 6 weeks via classic channels.
- The 24-hour early warning and 72-hour follow-up notification according to NIS-2 require a functioning reporting path to the BSI, which external ISBs provide from the start of the contract.
- Licence the workspace for your internal representatives, or have our representatives order it; the dual CIVAC model makes the choice flexible.
Legal framework: NIS-2, BSI law and ISO/IEC 27001:2022
The ISB is not a single legal term, but rather a collective term for several obligations that collectively require a designated person with security responsibility. Firstly, the BSI law in the NIS 2 version: Operators of critical systems, essential and important facilities must take security measures, provide early warning of incidents within 24 hours and report them fully within 72 hours. Secondly, the ISO/IEC 27001:2022 standard: the ISMS requires a designated role for the operation, effectiveness control and continuous improvement of the 93 Annex A controls.
Thirdly, sector-specific regulations: BAIT for banks, VAIT for insurers, KAIT for capital management companies, ZAIT for payment service providers, B3S for KRITIS sectors, TISAX for automotive suppliers. Fourthly, contractual obligations towards major customers, who regularly require a named ISB with a documented order in supplier contracts. The external ISB fulfils all four requirements frameworks from an order, provided that the contract and appointment certificate precisely reflect the respective scope.
CIVAC issues a written appointment certificate for each external information security officer, with scope of application, reporting line to management, named deputy and response time agreement. The appointment certificate, signed, filed, verifiable. This formal basis is the first check point in the NIS 2 audit.
Independence and avoidance of conflicts of interest
The ISB must be able to act independently of operational IT responsibility because it checks the IT measures, evaluates them and reports to management. If the head of IT is also the ISB, he audits his own work, and this is problematic under both NIS-2 and the ISO/IEC 27001:2022 standard. BaFin explicitly formulates in BAIT paragraph 4.5 that an appropriate separation of functions between information security management and IT operations must be ensured, and the supervisory authority has noted this separation several times in audits.
In practical terms, this means: in companies with fewer than 500 employees, a clean separation is difficult to demonstrate internally because a dedicated ISB position would exceed personnel costs and the dual role with the IT manager remains a compliance risk. The external ISB solves this structurally: it has no operational IT role and no vested interest in whitewashing findings. The reporting line goes directly to the management, documented with a time stamp and recipient in the workspace, and is available for every review in seconds.
A second advantage is the distance from day-to-day political business. Internal ISBs are under pressure to prioritise actions that their internal stakeholders prefer. External representatives evaluate according to standards and law, not according to internal power relations, and management receives an unfiltered risk assessment. Others run compliance like a filing cabinet. We run it like software.
Qualifications and representation: the silent ordering risk
The NIS 2 requirements and the ISO/IEC 27001:2022 standard expect an ISB with proven qualifications. Certifications such as ISO/IEC 27001 Lead Implementer and Lead Auditor, CISM, CISSP or the TÜV certification as an information security officer are common in the industry, each with documented professional experience of at least three years in information security or IT audit. Internal reinforcement through weekend training rarely meets this expectation and is noted as a weakness in NIS 2 audits.
The second, often overlooked risk is substitution. The ISB must be reachable, even if the main person is sick, on vacation or has left the company. Internal solutions often lack a qualified deputy and the system breaks at the first incident during vacation time. CIVAC consistently works in a team model: each mandate has a named main person responsible and an equally qualified deputy, both documented in the appointment certificate and stored in the workspace with contact details.
The third aspect is ongoing further training. Information security is a field with a high rate of change, from new attack patterns to updates to the ISO/IEC 27001 standard and EU regulations. External ISB amortize the ongoing training over many mandates, internal representatives bear the training costs of 5,000 to 12,000 euros per year themselves, and in many companies this budget is cut first when other priorities arise.
Response time: 24 hour early warning, 72 hour reporting
The NIS 2 guideline requires an early warning within 24 hours of becoming aware of a significant security incident and a complete incident report within 72 hours, in each case to the BSI. The clock starts on awareness. For classic external representatives without a platform connection and without a workspace, this deadline is usually untenable because the escalation chain runs via telephone and email and the report texts are only formulated once the incident has occurred.
A professionally set up external ISB has configured the reporting path from day one: the reporting form is in the workspace, the recipient address at the BSI is stored, the escalation chain to management is documented with telephone numbers and representation regulations, and the The deputy is automatically integrated as a backup. At CIVAC, the NIS-2 24/72 reporting path is part of the standard workspace, and the first mandate enters the configuration into the system long before the first incident occurs.
Response time SLA and availability are included in the appointment certificate. 24/7 availability for security-related incidents, a guaranteed initial response within 60 minutes and a written evaluation within 4 hours are realistic values for medium-sized mandates. The auditor calls, the evidence is ready. This order also applies to the BSI auditor after an incident.
Cost comparison over 36 months
The cost comparison between internal and external ISB is only honest if all components are recorded, not just the gross salary. For a medium-sized company with 150 to 350 employees, a medium level of IT complexity and an NIS 2 classification as an important facility, the following picture emerges over 36 months. Internal ISB full-time: gross salary 85,000 to 110,000 euros per year, employer contribution 20 to 25 percent, training and certification maintenance 8,000 to 12,000 euros per year, ISMS tooling and audit software 10,000 to 25,000 euros per year, reserve for deputy 15,000 euros per year.
Total costs 36 months for the internal full-time variant: 380,000 to 510,000 euros. Internal ISB as a dual function with IT manager: lower direct personnel costs, but compliance risk from the lack of separation of functions, limited audit sensitivity at BaFin and BSI audits and a high risk premium in the internal assessment. External ISB via CIVAC: annual service fee 12,000 to 36,000 euros depending on the scope, including appointment certificate, representative, 490 audit templates, NIS 2 reporting path and ISMS statement of applicability. 36 months total 36,000 to 108,000 euros.
The cost advantage of the external model is structural, not promotional, because external providers amortize the qualification and tooling over many mandates. For companies with around 2,000 employees or more with their own CISO team, the calculation is reversed; the internal solution becomes competitive and often the better choice. For medium-sized businesses, the external ISB generally remains the economically and legally superior solution.
Audit sensitivity: 93 controls and the statement of applicability
The ISO/IEC 27001:2022 standard requires a Statement of Applicability (SoA) that evaluates all 93 Annex A controls individually: applicable or not applicable, with justification, implemented or not implemented, effectiveness control, responsible party and evidence. The SoA is the central document of the certification and the transition period from ISO/IEC 27001:2013 to 2022, the effectiveness of which has been final since October 2025. An internal ISB without dedicated tools builds the SoA in Excel, and Excel is the weakest link in the chain in the audit.
An external ISB with platform connection delivers the SoA from the workspace, with annual maintenance, documented changes for each control, stored effectiveness controls and a consolidated report to the management. CIVAC's 490 audit templates cover the typical evidence per control: policy statements, measures, control evidence and reporting templates. In the certification audit, the auditor asks for exactly these documents, and the delivery time from the workspace is minutes, not days.
In day-to-day business, this means: the annual re-certification according to ISO/IEC 27001:2022 can be planned and achieved without a last-minute sprint, the NIS 2 certificate to the BSI is up-to-date and audit-proof, and the supplier audits by major customers can be operated with the same package of documents. Audit-proof, documented, NIS-2-proof, ISO 27001-proof. This is the standard by which an external ISB must be measured.
When an internal solution still makes sense
External ISB is not always the right answer, even if the statistics are clear for medium-sized companies. Three scenarios speak for an internal appointment. Firstly, large companies with 2,000 or more employees with their own security organisation, dedicated budget and multiple locations. A full-time CISO with a team is the standard model here; the external ISB is only added as a supplementary audit perspective. The cost curve and availability requirements clearly speak for internal.
Secondly, highly regulated industries with daily supervisory interaction such as banks under BAIT, insurers under VAIT or KRITIS sectors under BSI specifications with constant audit pressure. Proximity to day-to-day business is crucial here, and an internal ISB can react better to ongoing changes. Thirdly, highly sensitive research and development environments in which, for confidentiality reasons, it is difficult to provide external representatives with the necessary access without taking commercial risks.
For the other constellations, which make up around 80 to 90 percent of the companies subject to NIS 2 in Germany, the external ISB is structurally the better choice: ordered quicker, cheaper in terms of overall effort, more audit-proof thanks to a dedicated platform and templates, and provided with a representative, which can rarely be organised internally. The decision becomes sustainable with a 90-minute inventory in which the six criteria are gone through in a structured manner.
Integration with DPO, compliance officer and other officers
The ISB rarely stands alone. In the typical medium-sized business landscape, several roles coexist: data protection officer according to Art. 37 GDPR, compliance officer according to IDW PS 980, whistleblower reporting office according to HinSchG since July 2023, ESG officer for CSRD reporting from 2026 and 2027, industry-dependent money laundering officer according to AMLA, dangerous goods officer according to GbV and others. CIVAC covers 25 of these officer roles, all live on a single compliance platform and Officer-as-a-Service.
The integration advantage is operational. A data breach according to Art. 33 GDPR and a security incident according to NIS-2 often arise from the same event, the same forensic trace and the same affected systems. If the ISB and the data protection officer are in different organisations with different evidence bases, the 24 and 72 hour deadlines are difficult to maintain operationally. On a platform with a common document base, the same event triggers both workflows, with clear responsibility and clean time stamps.
Companies that order an external ISB without a platform and cover the remaining roles through separate law firms and freelancers regularly discover the integration gap during the first cross-departmental audit. The costs of subsequent consolidation are higher than the costs of the correctly set up platform solution, and the change can hardly be planned sensibly during ongoing audits.
Order the external ISB within 2 working days
The practical process of an ISB order at CIVAC is tailored to 2 working days and follows a defined scheme. Day 1, morning: Inventory of the current security situation, NIS 2 classification as an essential or important facility, overview of existing ISMS documents and ongoing audits or re-certifications. Day 1, afternoon: Determination of the scope, selection of the main person and the deputy from the CIVAC pool, draft contract and appointment certificate. Day 2, morning: Countersigning, setting up the workspace, activating the 24/72 reporting path to the BSI.
CIVAC positions itself as a compliance platform and officer-as-a-service. Licence the workspace for your internal representatives, or have our representatives order it. Both variants share the same platform, the same 490 templates, the same reporting paths and the same EU data residency, and switching between the two models is provided for in the model contract, without data loss and without breaking the audit trail. This is the decisive advantage over a pure law firm solution or an isolated solution in SharePoint.
For a specific recommendation for your situation, an effort estimate with a fixed price and a draft appointment certificate with a named representative, write to info@civac.de or use the contact form on civac.de/faq. Turn reading into an assignment.
FAQ
When does a company have to appoint an information security officer?
According to the NIS2UmsuCG, essential and important facilities, KRITIS operators and sector-specific regulated companies are obliged to appoint a person responsible for security. The ISO/IEC 27001:2022 standard requires an ISMS role for operations, effectiveness control and continuous improvement. Major customer contracts in the B2B sector often contractually require a named ISB with a documented order and reporting line.
Can the IT manager also be an information security officer?
In most constellations not without considerable risks. In BAIT paragraph 4.5, BaFin calls for a separation of functions between information security and IT operations. The ISO/IEC 27001:2022 standard expects an independent assessment of the ISMS, which is structurally not possible with personal identity. External ordering resolves the conflict cleanly and is much easier to defend in the NIS 2 audit.
How much does an external ISB cost for a medium-sized company?
For a company with 150 to 350 employees and medium IT complexity, the annual service fee is typically between 12,000 and 36,000 euros. Includes appointment certificate, named representative, 37 audit templates, NIS-2 reporting path and ISMS statement of applicability. Over 36 months there is an advantage of around 300,000 euros compared to an internal full-time solution.
How quickly is an external ISB ready for use?
CIVAC works with a 2-working day SLA from contract conclusion to appointment certificate issued and workspace activated. The NIS-2 24/72 reporting path is configured from day one, the deputy is integrated and the reporting line to management is documented. Classic routes via law firms and freelancers usually require 2 to 6 weeks until operational readiness.
Is the external ISB personally liable in the event of a security incident?
According to Section 130 OWiG, the management is liable for breaches of supervisory duties; the ISB can be held liable under civil law for grossly negligent advice errors. External providers such as CIVAC carry financial loss liability of at least 5 million euros per claim, documented in the sample contract. Internal ISBs are subject to labour law consequences that often complicate their risk position.
What happens if the external ISB is sick or on vacation?
CIVAC fills each mandate with a main person and a named deputy from the internal officer pool, both documented in the appointment document. The deputy has the same access to the workspace and automatically takes over if the main person is not available. The response time to security-related incidents remains unchanged, and the reporting path to the BSI works without interruption.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.