Outsourced CISO

How to choose your outsourced CISO firm?

8 essential criteria to select the cyber partner that will support your organization for 3 to 5 years.

01

Recognized certifications

Check both firm-level and individual certifications: ISO 27001 LI/LA, CISSP, CISM, EBIOS RM, PASSI (ANSSI).

02

Sector experience

The firm must have real experience in your industry (healthcare HDS, finance DORA, critical-operators NIS2).

03

Digital platform

Modern cyber steering requires an integrated GRC platform for asset register, risks, incidents, indicators.

04

SLA and responsiveness

Check availability commitments (24/7 on-call?), intervention delays and escalation procedures.

05

Contractual clauses

Liability, cyber professional insurance, GDPR sub-processor clauses, means vs results commitment.

06

Communication quality

Regular reporting, executive briefings, popularization for boards. A good CISO also knows how to dialog with the business.

07

Verifiable references

Ask for concrete case studies, testimonials from similar companies and ideally a chat with a reference customer.

08

Compatible company culture

The CISO will be your strategic counterpart for 3 to 5 years on average: human fit is essential.

Checklist: 5 questions to ask in interviews

  • Can you present 2 missions similar to my sectoral context?
  • What is the exact profile of the CISO who will be dedicated to our account?
  • How do you handle continuity if the consultant leaves?
  • What is your GRC steering platform and can I try it?
  • What are your SLA commitments and how do you measure your performance?
Notre approche

Une méthodologie éprouvée, alignée sur les référentiels

Nous appliquons les standards reconnus (ISO 27001, EBIOS RM, NIST CSF, ANSSI) et adaptons notre accompagnement à vos enjeux sectoriels : banque, assurance, santé, industrie, services, public.

Un expert dédié

Un expert dédié

Votre interlocuteur unique, présent à chaque COPIL et disponible en cas de crise.

Méthodologie cadrée

Méthodologie cadrée

Livrables standardisés, planning explicite, points réguliers — vous savez où vous en êtes.

Sectoriel adapté

Sectoriel adapté

Banque, santé, industrie, public : on adapte les mesures à vos obligations spécifiques.

Disponibilité

Disponibilité

Assistance réactive, gestion de crise, accompagnement lors des contrôles des autorités.

Référentiels appliqués dans nos missions

ISO 27001 ISO 27005 EBIOS RM NIST CSF ANSSI NIS 2 DORA TIBER-EU / TLPT