ACTIVE INCIDENT? CONTACT US
ACTIVE INCIDENT? ENGAGE TEAM
Fractional Executive Governance · EU/EEA

NIS2 Made Compliance Personal.
We Make It Manageable.

Since October 2024, EU management bodies carry direct personal accountability for cybersecurity governance failures — not just their IT department. Our independent vCISO partner absorbs that operational burden: real NIS2/GDPR/DORA mapping, board-grade reporting, and defensible decisions, at a fraction of a full executive hire.

€10M / 2% turnover — max NIS2 fine, essential entities €1.15B in GDPR fines issued across the EU in 2025 alone 22 of 27 member states have now transposed NIS2 Germany, France, Netherlands: enforcement already active €3.87M average breach cost in Germany, 2025 Art. 20: personal liability for management bodies 84% of in-scope organizations admit they aren't ready
// REGULATORY REALITY

Governance Just Stopped Being Optional.

You can outsource your IT operations. Since NIS2 took direct effect, you can no longer outsource the accountability that sits with it — Article 20 makes your management body personally answerable for how cybersecurity risk is governed, not just how it's patched.

This isn't theoretical. Germany's BSI began issuing formal enforcement notices in Q4 2025. Belgium set its first conformity-assessment deadline for April 2026. The Netherlands, Poland, and Italy have each moved from legislation to active supervision within the last two quarters.

A vCISO is how a mid-market business gets an executive who actually owns this — without the €150K–€260K+ salary line a full in-house hire requires in most Western European markets.

NIS2 Max Penalty — Essential Entities
€ 0 M

Or 2% of total global annual turnover, whichever is higher. Important entities face up to €7M / 1.4%.

GDPR Fines Issued EU-Wide, 2025
€ 0 B

Cumulative fines since 2018 now exceed €7.1B — and enforcement has expanded well past Big Tech into finance, healthcare, and the public sector.

Average Breach Cost, Germany 2025
€ 0 M

Down from €4.9M in 2024 — but only for organizations with mature detection. Slower responders still pay the old price.

NIS2 Transposition Across the EU
0 / 27

Member states with national NIS2 law now in force, as of early 2026 — with active enforcement already underway in three of the largest.

// ARTICLE 20 IN PRACTICE

Your Exposure Depends On Your Postcode.

NIS2 is a directive, not a regulation — every member state transposed Article 20's personal-liability requirement into its own law, with its own teeth. What your board is actually exposed to depends on where you're registered.

Germany

Personal Fines & Management Bans

The NIS2UmsuCG imposes direct personal liability on Geschäftsführer and Vorstand members, including individual fines separate from the corporate penalty. The BSI began issuing formal enforcement notices (Anordnungen) in Q4 2025.

Italy

Suspension From Management Duties

D.Lgs. 138/2024 lets the ACN impose a temporary "incapacity to perform managerial functions" on board members of repeat-offending essential entities — a director-level operating ban, not just a corporate fine.

Netherlands

Escalating Director Disqualification

The Cyberbeveiligingswet requires governing bodies to formally approve and actively oversee security measures — delegating entirely to IT creates direct personal exposure, escalating to disqualification for serious non-compliance.

What we're seeing in the market: some in-house CISO hires in Germany and the Netherlands are now negotiating monthly "liability stipends" — typically €1,200–€2,000 — specifically to offset the personal D&O exposure that comes with the title. A vCISO engagement structures that risk differently: the operational execution sits with an independent, insured advisor rather than a single named employee.

// ARTICLE 21, IN PLAIN LANGUAGE

What NIS2 Actually Requires You To Do.

Article 21 sets ten mandatory risk-management measure categories for every essential and important entity. Most businesses have fragments of several. Almost none have all ten mapped, owned, and evidenced.

01

Risk Analysis & Policy

A documented information-system security policy, reviewed against actual risk — not a downloaded template.

02

Incident Handling

Detection, response, and the notification workflow that hits the 24-hour / 72-hour reporting clock.

03

Business Continuity

Backup management, disaster recovery, and a crisis-management plan that's actually been tested.

04

Supply Chain Security

Security requirements built into supplier and vendor relationships, not bolted on after signing.

05

Secure Development

Security across acquisition, development, and maintenance of systems, including vulnerability handling.

06

Effectiveness Assessment

Policies for actually measuring whether your risk-management measures work — not just that they exist.

07

Cyber Hygiene & Training

Basic practices and security awareness training, extending to board-level cybersecurity training.

08

Cryptography & Encryption

Policies on when and how encryption is applied, matched to actual data sensitivity levels.

09

HR & Access Control

Human-resources security, formal access-control policy, and asset-management discipline.

10

MFA & Secure Comms

Multi-factor authentication, and secured voice, video, and text channels for emergency use.

Regulated financial entity? DORA runs on a parallel but distinct track from NIS2 for banks, insurers, investment firms, and payment providers — with its own ICT risk-management, third-party, and resilience-testing requirements. Where DORA applies, it takes precedence over NIS2 for the same entity; we map both so nothing falls in the gap between them.

// THE FRAMEWORK

Four Vectors, One Accountable Owner.

Most mid-market security programs fail not from a lack of tools, but from a lack of someone whose job it is to own the whole picture. That's the actual gap a vCISO closes.

Vector 01

Find Out What You Actually Have

Most exposure isn't in the systems IT tracks — it's in the spreadsheet on someone's laptop, the SaaS tool finance signed up for without a review, the admin account nobody rotated. We map the real asset and data footprint before we map anything else.

Vector 02

Turn Legal Text Into a Work Plan

NIS2, GDPR, and — for financial entities — DORA don't come with an implementation checklist. We translate directive language into the specific technical controls, documentation, and reporting cadence your national regulator actually expects.

Vector 03

Own the Vendor Risk You've Been Ignoring

NIS2's supply-chain provisions mean your obligations now extend to your vendors' security posture. We run that assessment, negotiate the contractual security terms, and complete the client due-diligence questionnaires that used to sit unanswered in someone's inbox.

Vector 04

Give the Board Something They Can Actually Use

Article 20 requires the management body to approve and oversee cybersecurity measures — which means they need to understand them. We turn technical posture into risk metrics, budget cases, and documented sign-off trails a board can defend under audit.

DEPLOYMENT CAPABILITY

On-Premise EU & Remote First

Our dedicated, independent vCISO partner is based in Slovenia, enabling responsive on-premise boardroom engagements anywhere in the EU/EEA, backed by fully remote day-to-day governance work between sessions.

// THE ARITHMETIC

What It Actually Costs, In Euros.

Not a generic estimate — figures benchmarked against 2026 European executive compensation data and current NIS2 enforcement practice.

Strategic Vector The vCISO Model Full-Time In-House Hire
Annual Investment Fractional retainer scoped to actual days needed — benchmarked at €1,050–€1,950 per day across major Western European markets. €130,000–€260,000+ base salary at 2026 EU rates, often 1.4–2.2× base once bonus, pension, and benefits land — plus recruiter fees.
Time to First Output Governance review and initial risk mapping begin within days of a signed engagement. 3–6 months to source and hire a qualified CISO in the current EU market, before onboarding even begins.
Regulatory Breadth Concurrent exposure to national NIS2 variants — Germany's NIS2UmsuCG, the Dutch Cyberbeveiligingswet, Italy's D.Lgs. 138/2024 — across live client mandates. Fluent in exactly one national transposition: whichever one your registered office happens to sit under.
Personal Liability Structure Execution risk sits with an independent, insured external advisor rather than one named employee. Increasingly requires a negotiated monthly liability stipend — commonly €1,200–€2,000 — on top of salary to offset Article 20 exposure.
Vendor Objectivity No internal politics, no incumbent vendor relationships to protect — procurement recommendations are ruthlessly vendor-agnostic. Subject to internal politics and legacy vendor bias that builds up over years in a single seat.
Continuity If It Ends Clean, documented off-ramp — all frameworks, playbooks, and registers remain your organization's property. Departure opens a governance vacuum until a replacement is hired — the 3–6 month cycle above, repeated.

Figures reflect 2026 European executive-compensation benchmarks, published NIS2 national transposition tracking, and current market reporting on Article 20 liability arrangements. Individual engagements vary by scope, sector, and jurisdiction.

// HOW IT ACTUALLY STARTS

No Ninety-Day Onboarding.

A rough shape of the first quarter — adjusted to your actual entity classification, sector, and starting maturity.

Week 1

Entity & Exposure Mapping

Confirm whether you're classified essential or important under NIS2, which national law binds you, and where GDPR or DORA obligations overlap.

Weeks 2–4

Baseline Risk Assessment

A brutally honest audit against the 10 mandatory NIS2 control areas — incident handling, supply chain, access control, encryption, and the rest.

Month 2

Remediation Roadmap

A prioritized, budgeted plan the board can actually approve — sequenced by real risk reduction, not vendor sales pressure.

Ongoing

Standing Board Reporting

Recurring, documented sign-off cycles that satisfy Article 20's oversight requirement — and hold up under a supervisory audit.

Genuinely A Good Fit
  • ✓ 50–1,000 employee EU/EEA businesses now in scope for NIS2, GDPR, or DORA with no dedicated security executive.
  • ✓ Organizations that just discovered they're classified "essential" or "important" and need a governance owner fast.
  • ✓ Boards that need documented, defensible sign-off trails ahead of a supervisory audit or client due-diligence review.
  • ✓ Businesses that already have IT/engineering talent but nobody translating regulation into a funded work plan.
Probably Not, And We'll Say So
  • – Enterprises large enough to justify and retain a full-time, in-house CISO with a dedicated team already.
  • – Businesses that need hands-on-keyboard SOC monitoring or 24/7 detection — that's a managed security function, not governance.
  • – Anyone looking for a rubber-stamp compliance certificate rather than an actual reduction in operational risk.
  • – Organizations mid-way through an active, unremediated breach — that's our Incident Response service, engaged first.
// COMMON QUESTIONS

Before You Ask.

Does a vCISO actually satisfy Article 20's oversight requirement?

The management body itself must approve and oversee cybersecurity measures — that obligation can't be fully delegated away. What a vCISO does is give that board something real to approve: documented risk assessments, a funded roadmap, and recurring sign-off cycles, instead of a compliance binder nobody reads.

We already have an IT manager. Why do we need this too?

An IT manager keeps systems running. A vCISO owns risk governance, regulatory mapping, vendor due-diligence, and board reporting — a different job, usually held by someone with no bandwidth to do it inside an existing IT role. We work alongside your IT team, not instead of it.

What happens if we have an incident mid-engagement?

Your vCISO coordinates directly with our Incident Response team, who deploy within 8–12 hours. Because your governance documentation and asset maps already exist, response is faster and the mandatory NIS2 incident-notification timeline — 24-hour early warning, 72-hour follow-up — is easier to hit.

How do we know if we're an "essential" or "important" entity?

Broadly: medium or large organizations (50+ staff or €10M+ turnover) in one of 18 NIS2-covered sectors. But thresholds, sector definitions, and additional national inclusions vary by member state — classification is one of the first things we confirm in week one, against your specific registered jurisdiction.

Is this a monthly retainer, or a fixed-scope project?

Most clients run a monthly retainer scoped to a set number of days, scaling up during audits, incidents, or major initiatives and down once governance stabilizes. Some engagements start as a fixed-scope initial assessment before converting to ongoing retainer — we'll recommend whichever fits your actual starting point.

Engagement Lead Credentials

M.Sc. Cybersecurity CISSP ISO 27001 Lead Auditor Based in Slovenia, EU

Strict Confidentiality Directive

All engagements operate under strict confidentiality principles. SC Consulting does not publish client logos, strategic initiatives, or operational environments without explicit written authorization. We believe trust is earned through absolute discretion.

INITIATE COMMAND

Command Your
Perimeter.

Organizations can reach out for strategic consultations, offensive assessments, compliance initiatives, AI security reviews, monitoring services, incident response planning, or general cybersecurity advisory.

Location Tallinn, Estonia • Remote First
Response Initial response within 6-12 hours

Direct Inquiry

Encrypted & Standard Communications
Primary Email
contact@sc.consulting
Direct Line + WhatsApp
+372 54 677 688
Signal Protocol
scconsulting.01
Element Matrix
Request via Email
Initiate Scoping Request

We are not checking boxes.
We are closing gaps.

We believe in measurable risk reduction over theoretical security. Our teams operate seamlessly alongside yours to engineer resilience that sustains the reality of modern business.