Cyberattacks, new regulations, rising expectations from customers, insurers, and management: information security is no longer a niche IT topic. Many medium-sized companies realize this at the latest when an insurer demands detailed evidence or a customer requires specific security standards. Those who neglect information security risk not only data, but also trust and business success.
We spoke with our Chief Information Security Officer (CISO), who regularly supports medium-sized companies as an external CISO-as-a-Service. A conversation about everyday reality and why pragmatism is often more important than perfection.
Mr. N., you work as an external CISO for several medium-sized companies. What do you encounter most frequently at the moment?
NIS2 is currently a big issue. How do you specifically support companies with the requirements of the directive?
Where are the biggest weaknesses in medium-sized businesses?
How do you typically start with new customers?
Many managing directors fear bureaucracy. Are they right to?
What role does top management play in your projects?
How do employees react to an external ISB?
What distinguishes a good CISO-as-a-Service from traditional consulting?
Finally, what is your most important advice for IT and business decision-makers?
What really matters in practice
The discussion clearly shows that the biggest challenges in cybersecurity for medium-sized businesses today lie less in a lack of technology than in a lack of structure, transparency, clear prioritization, and unambiguous responsibility. This is where the involvement of an external information security officer proves its worth. Not as a controller or theorist, but as someone who brings order to the topic, makes risks understandable, and acts as a translator between IT, management, insurers, and regulators.
A good ISO does not think in terms of standard chapters, but in terms of decisions: What is really critical? What needs to happen now? What can be deliberately put on hold? They ensure that information security does not remain a reactive crisis issue, but becomes an ongoing, controllable process. With clear responsibilities and measures that also work in everyday life.
This is particularly crucial for medium-sized companies. They don't need a maximalist security strategy, but pragmatism and reliability. An external CISO who provides regular support and has access to broad expert knowledge can fill this gap and thus become a reliable sparring partner for both IT and management.
More information on a CISO-as-a-Service
If you don't know where to start.
In our webinar “Check Your Security Status,” you will receive a practical overview of different cybersecurity assessments. We share proven approaches from SMEs, for SMEs – and show you how you can develop your security strategy efficiently and purposefully.
Webinar | Check Your Security Status
A practical overview of the most important cybersecurity assessments
January 27, 2026 | 10:00 a.m.
In just 45 minutes, Alexandra Steinmayr and Carsten Keil will show you which assessment formats – from maturity analyses to penetration tests – are truly relevant for your company.
You will learn how to use the analyses in a targeted manner to derive concrete measures and reliably meet regulatory requirements such as CRA and NIS2 – in a concise, compact, and practical way.
Rapid Risk · NIS2 Readiness · CRA Readiness · Pentest · Compromise Assessment