Since October 2024, EU management bodies carry direct personal accountability for cybersecurity governance failures — not just their IT department. Our independent vCISO partner absorbs that operational burden: real NIS2/GDPR/DORA mapping, board-grade reporting, and defensible decisions, at a fraction of a full executive hire.
You can outsource your IT operations. Since NIS2 took direct effect, you can no longer outsource the accountability that sits with it — Article 20 makes your management body personally answerable for how cybersecurity risk is governed, not just how it's patched.
This isn't theoretical. Germany's BSI began issuing formal enforcement notices in Q4 2025. Belgium set its first conformity-assessment deadline for April 2026. The Netherlands, Poland, and Italy have each moved from legislation to active supervision within the last two quarters.
A vCISO is how a mid-market business gets an executive who actually owns this — without the €150K–€260K+ salary line a full in-house hire requires in most Western European markets.
Or 2% of total global annual turnover, whichever is higher. Important entities face up to €7M / 1.4%.
Cumulative fines since 2018 now exceed €7.1B — and enforcement has expanded well past Big Tech into finance, healthcare, and the public sector.
Down from €4.9M in 2024 — but only for organizations with mature detection. Slower responders still pay the old price.
Member states with national NIS2 law now in force, as of early 2026 — with active enforcement already underway in three of the largest.
NIS2 is a directive, not a regulation — every member state transposed Article 20's personal-liability requirement into its own law, with its own teeth. What your board is actually exposed to depends on where you're registered.
The NIS2UmsuCG imposes direct personal liability on Geschäftsführer and Vorstand members, including individual fines separate from the corporate penalty. The BSI began issuing formal enforcement notices (Anordnungen) in Q4 2025.
D.Lgs. 138/2024 lets the ACN impose a temporary "incapacity to perform managerial functions" on board members of repeat-offending essential entities — a director-level operating ban, not just a corporate fine.
The Cyberbeveiligingswet requires governing bodies to formally approve and actively oversee security measures — delegating entirely to IT creates direct personal exposure, escalating to disqualification for serious non-compliance.
What we're seeing in the market: some in-house CISO hires in Germany and the Netherlands are now negotiating monthly "liability stipends" — typically €1,200–€2,000 — specifically to offset the personal D&O exposure that comes with the title. A vCISO engagement structures that risk differently: the operational execution sits with an independent, insured advisor rather than a single named employee.
Article 21 sets ten mandatory risk-management measure categories for every essential and important entity. Most businesses have fragments of several. Almost none have all ten mapped, owned, and evidenced.
A documented information-system security policy, reviewed against actual risk — not a downloaded template.
Detection, response, and the notification workflow that hits the 24-hour / 72-hour reporting clock.
Backup management, disaster recovery, and a crisis-management plan that's actually been tested.
Security requirements built into supplier and vendor relationships, not bolted on after signing.
Security across acquisition, development, and maintenance of systems, including vulnerability handling.
Policies for actually measuring whether your risk-management measures work — not just that they exist.
Basic practices and security awareness training, extending to board-level cybersecurity training.
Policies on when and how encryption is applied, matched to actual data sensitivity levels.
Human-resources security, formal access-control policy, and asset-management discipline.
Multi-factor authentication, and secured voice, video, and text channels for emergency use.
Regulated financial entity? DORA runs on a parallel but distinct track from NIS2 for banks, insurers, investment firms, and payment providers — with its own ICT risk-management, third-party, and resilience-testing requirements. Where DORA applies, it takes precedence over NIS2 for the same entity; we map both so nothing falls in the gap between them.
Most mid-market security programs fail not from a lack of tools, but from a lack of someone whose job it is to own the whole picture. That's the actual gap a vCISO closes.
Most exposure isn't in the systems IT tracks — it's in the spreadsheet on someone's laptop, the SaaS tool finance signed up for without a review, the admin account nobody rotated. We map the real asset and data footprint before we map anything else.
NIS2, GDPR, and — for financial entities — DORA don't come with an implementation checklist. We translate directive language into the specific technical controls, documentation, and reporting cadence your national regulator actually expects.
NIS2's supply-chain provisions mean your obligations now extend to your vendors' security posture. We run that assessment, negotiate the contractual security terms, and complete the client due-diligence questionnaires that used to sit unanswered in someone's inbox.
Article 20 requires the management body to approve and oversee cybersecurity measures — which means they need to understand them. We turn technical posture into risk metrics, budget cases, and documented sign-off trails a board can defend under audit.
Our dedicated, independent vCISO partner is based in Slovenia, enabling responsive on-premise boardroom engagements anywhere in the EU/EEA, backed by fully remote day-to-day governance work between sessions.
Not a generic estimate — figures benchmarked against 2026 European executive compensation data and current NIS2 enforcement practice.
| Strategic Vector | The vCISO Model | Full-Time In-House Hire |
|---|---|---|
| Annual Investment | Fractional retainer scoped to actual days needed — benchmarked at €1,050–€1,950 per day across major Western European markets. | €130,000–€260,000+ base salary at 2026 EU rates, often 1.4–2.2× base once bonus, pension, and benefits land — plus recruiter fees. |
| Time to First Output | Governance review and initial risk mapping begin within days of a signed engagement. | 3–6 months to source and hire a qualified CISO in the current EU market, before onboarding even begins. |
| Regulatory Breadth | Concurrent exposure to national NIS2 variants — Germany's NIS2UmsuCG, the Dutch Cyberbeveiligingswet, Italy's D.Lgs. 138/2024 — across live client mandates. | Fluent in exactly one national transposition: whichever one your registered office happens to sit under. |
| Personal Liability Structure | Execution risk sits with an independent, insured external advisor rather than one named employee. | Increasingly requires a negotiated monthly liability stipend — commonly €1,200–€2,000 — on top of salary to offset Article 20 exposure. |
| Vendor Objectivity | No internal politics, no incumbent vendor relationships to protect — procurement recommendations are ruthlessly vendor-agnostic. | Subject to internal politics and legacy vendor bias that builds up over years in a single seat. |
| Continuity If It Ends | Clean, documented off-ramp — all frameworks, playbooks, and registers remain your organization's property. | Departure opens a governance vacuum until a replacement is hired — the 3–6 month cycle above, repeated. |
Figures reflect 2026 European executive-compensation benchmarks, published NIS2 national transposition tracking, and current market reporting on Article 20 liability arrangements. Individual engagements vary by scope, sector, and jurisdiction.
A rough shape of the first quarter — adjusted to your actual entity classification, sector, and starting maturity.
Confirm whether you're classified essential or important under NIS2, which national law binds you, and where GDPR or DORA obligations overlap.
A brutally honest audit against the 10 mandatory NIS2 control areas — incident handling, supply chain, access control, encryption, and the rest.
A prioritized, budgeted plan the board can actually approve — sequenced by real risk reduction, not vendor sales pressure.
Recurring, documented sign-off cycles that satisfy Article 20's oversight requirement — and hold up under a supervisory audit.
The management body itself must approve and oversee cybersecurity measures — that obligation can't be fully delegated away. What a vCISO does is give that board something real to approve: documented risk assessments, a funded roadmap, and recurring sign-off cycles, instead of a compliance binder nobody reads.
An IT manager keeps systems running. A vCISO owns risk governance, regulatory mapping, vendor due-diligence, and board reporting — a different job, usually held by someone with no bandwidth to do it inside an existing IT role. We work alongside your IT team, not instead of it.
Your vCISO coordinates directly with our Incident Response team, who deploy within 8–12 hours. Because your governance documentation and asset maps already exist, response is faster and the mandatory NIS2 incident-notification timeline — 24-hour early warning, 72-hour follow-up — is easier to hit.
Broadly: medium or large organizations (50+ staff or €10M+ turnover) in one of 18 NIS2-covered sectors. But thresholds, sector definitions, and additional national inclusions vary by member state — classification is one of the first things we confirm in week one, against your specific registered jurisdiction.
Most clients run a monthly retainer scoped to a set number of days, scaling up during audits, incidents, or major initiatives and down once governance stabilizes. Some engagements start as a fixed-scope initial assessment before converting to ongoing retainer — we'll recommend whichever fits your actual starting point.
Engagement Lead Credentials
All engagements operate under strict confidentiality principles. SC Consulting does not publish client logos, strategic initiatives, or operational environments without explicit written authorization. We believe trust is earned through absolute discretion.
Organizations can reach out for strategic consultations, offensive assessments, compliance initiatives, AI security reviews, monitoring services, incident response planning, or general cybersecurity advisory.
We believe in measurable risk reduction over theoretical security. Our teams operate seamlessly alongside yours to engineer resilience that sustains the reality of modern business.