Fractional CISO for Swiss SMEs

A CISO who understands your business. More protection. Fewer tools. Lower cost.

Senior security leadership on retainer for companies with 50 to 500 employees. Embedded with your team, fixed-price, vendor-independent. Operational within two weeks. ODCUS stays until the security program stands.

The gap

Security is no one's job. Until it lands on someone's desk.

Three gaps that show up in almost every SME once you look closely. Compliance is the symptom. Ownership is the problem.

01

No one owns it

IT keeps the lights on. Executives run the business. The team handles audits ad hoc. Security falls into the gap, and onto whoever happens to be standing there.

02

No one knows your business

Stock policies pulled from the internet. Consultants who do not know your supply chain. Frameworks copied through generically. Paper without substance.

03

No one says no to tools

Audits and sales pitches often end with another tool to buy. Licenses grow, risk stays. ODCUS starts every engagement with one question: what can go?

Security needs owners. Not inventory.
What happens in the engagement

Four things that run differently from day one

Included in every engagement. Depth and time allocation are set during scoping, but the pattern stays the same.

01

One voice inside and outside

Executive board, board of directors, customer security questionnaires, audit walkthroughs. One point of contact who has all of it covered.

02

Clean up first, invest second

Before new tools come in, the existing security landscape gets reviewed for effectiveness. Duplicate licenses go out.

03

Implementation in the team, not handoff by PDF

ODCUS implements measures with your IT instead of documenting them across 80 pages, and stays until the system runs.

04

Reporting in the language of the executive board

Four pages of steering each month. Quarterly report for the board. Risks, actions, trends, to the point.

Security as a sales argument

Your next enterprise customer audits your security before they buy.

Vendor audits, security questionnaires, ISO evidence: in many tenders, the security organization decides whether the deal happens. Answer fast and clean, and the deal moves. Improvise, and you lose weeks.

Handshake between business partners after a meeting
01

Questionnaires under control

ODCUS answers customer questionnaires and vendor audits within the engagement. With maintained evidence instead of all-nighters before the deadline.

02

Audit-ready toward customers

ODCUS accompanies walkthroughs and assessments directly, as your voice toward the customer. You negotiate the deal, not the firewall rules.

03

Evidence as a door opener

ISO 27001, SOC 2 or a working ISMS: the proof that sets you apart from competitors before price even comes up.

Run properly, security becomes a sales argument.
Standards as a tool

Frameworks help you. They do not replace you.

Which standard is mandatory and which one helps depends on the business model. What ODCUS has worked with operationally in recent years:

ISO 27001

International gold standard

Structured ISMS implementation, ready for certification and for demanding customer audits.

NIST CSF

Pragmatic for SMEs

Identify, Protect, Detect, Respond, Recover. Fast path to a picture of where you stand, without certification weight.

SWISS ISG · nDSG

Swiss legal duty

Information Security Act for federal context, revised Data Protection Act for everyone. Enforcement from end 2026.

NIS2

EU supply chain

Anyone supplying EU corporates inherits the requirements through contracts. Preparation beats reaction.

FINMA CIRC 2023/01

Financial services

Operational risk and resilience. Interface to supervision, internal audit and the risk committee.

SOC 2 · TISAX

On request

SOC 2 Type I/II for SaaS providers, TISAX for automotive suppliers. Where customers demand it, we deliver.

The Swiss ISG is in force. Three dates that matter.

Directly affected are nine sectors of critical infrastructure, from energy and hospitals to data centers. Their suppliers inherit the requirements through contracts. Details at the Federal Office for Cybersecurity (BACS).

Since 01.04.2025

Reporting duty

Operators of critical infrastructure must report cyberattacks to BACS within 24 hours.

Since 01.10.2025

Fines up to CHF 100'000

Ignoring a BACS order risks a fine. The transition phase is over.

By 31.12.2026

ISMS deadline

Organizations subject to the ISG need a working ISMS by end of 2026. This is the work a Fractional CISO takes on.

Three promises: fixed price instead of hourly billing. Implementation instead of recommendation. Vendor-independent, no commissions.
How an engagement runs

From kickoff to full operation. In six weeks.

The rhythm from our engagements: see first, then act, then scale. Prerequisite: access and contacts are in place from day one.

1
Before kickoff

Scoping & contract

Intro call, two-hour scoping, fixed-price offer within five working days. If the setup does not fit, ODCUS says so before you sign.

2
Week 1 to 2 · See

Discovery

Questionnaire and access are in place before kickoff. Stakeholder interviews, asset and risk register, review of tools, licenses and policies. Top-3 priorities set by end of week 2.

3
Week 3 to 6 · Act

First actions

Quick wins implemented (often: Conditional Access, MFA gaps, backup coverage). Steering runs from week 3, first report to the executive board by end of month 1.

4
From week 7 · Scale

Engagement in full operation

Security program in place. ISMS maintained, audits supported, quarterly board report. Vendor and customer questionnaires handled, continuous improvement.

Quick self-test

Is a Fractional CISO a fit for you?

Five statements from the day-to-day of Swiss SMEs. The more of them apply, the more a conversation is worth it.

  • You have 50 to 500 employees, and no one owns security as a clear responsibility.
  • Customer questionnaires and vendor audits keep piling up, and every time it is improvised.
  • The tool landscape has grown over years, but no one knows what protects you.
  • ISO 27001, Swiss ISG or NIS2 are on the horizon, and the experience is missing internally.
  • There is an IT lead, but executive reporting, audits and policies keep getting pushed back.

Two or more apply? Then the intro call is worth it. 30 minutes, free, no sales slides.

ODCUS brand illustration: cyber resilience with padlock, key and wave ribbon
Packages & pricing

Three packages. Fixed prices. No surprises.

Most engagements start with the Cyber Assessment. Those who already know where they stand jump straight to ISMS Implementation or the Retainer.

Sprint · 2 weeks
Cyber Assessment

An assessment your team can work with: prioritized plan, concrete actions.

CHF1'900one-time · excl. VAT · fully credited toward a follow-on engagement
  • Gap analysis against ISO 27001 and NIST CSF
  • Review of architecture, identities, tools, data flows
  • Risk register with top-10 themes
  • 90-day roadmap with effort and cost
  • Executive readout for board or executive committee
Start a sprint
Most popular
Engagement · monthly
CISO Retainer

Security ownership without a full-time hire. Embedded in the team, facing exec board and the directors.

from CHF4'900per month · excl. VAT · cancellable monthly after 6 months
  • Monthly steering, quarterly report for the board
  • ISMS maintenance, audit support, evidence management
  • Vendor risk and customer security questionnaires
  • Awareness, tabletops, incident readiness
  • Response within 48 hours, Slack or email
Discuss the retainer
Program · 90 days
ISMS Implementation

Information security that actually works day-to-day. Ready for ISO 27001, Swiss ISG or customer audits.

Price on requestFixed price after scoping · payable in tranches
  • Scope, context, roles, asset and risk register
  • Policies and processes aligned with IT and business
  • Action plan, implemented with your team
  • Awareness training for the workforce
  • Preparation for external audit or customer assessment
Discuss the program

All prices in CHF, excl. VAT. Fixed prices apply after joint scoping (free, max 2 hours). Minimum retainer term: 6 months.

Entry · 2 days per month
CISO Sparring

For companies with an existing IT or security lead: second opinion, coaching and preparation of executive and board meetings. Not an embedded engagement, but a senior at your side.

from CHF2'400per month · excl. VAT · cancellable monthly after 3 months
Discuss sparring
For context: a full-time CISO in Switzerland costs between CHF 150'000 and 250'000 per year (jobs.ch salary data), plus benefits, recruiting and months of searching. The CISO Retainer delivers senior security leadership from CHF 58'800 per year. Operational within two weeks, cancellable after six months.

Fractional CISO, consulting, interim or full-time hire?

Four models, four use cases. The difference lies in ownership, cost and time to start.

Fractional CISO Security consulting Interim CISO Full-time hire
Ownership Owns implementation within the engagement Recommends, implementation stays with you Owns it, full-time for a limited period Owns it permanently
Cost From CHF 4'900 per month, fixed price Time and materials, hourly rates Day rates on a full-time basis CHF 150'000 to 250'000 per year, plus overhead
Start Within two weeks Short notice Weeks to months Months of recruiting
Scope 1 to 4 days per week, scalable Project-based, selective 5 days per week, fixed term Full-time, permanent
Fits SMEs with 50 to 500 employees Well-defined single questions Vacancy or crisis Large companies from around 1'000 employees

Swipe sideways for all four models →

Full-time CISO salary band per jobs.ch.

Operated by ODCUS AG

ODCUS. IT security, right-sized.

Fractional CISO is a service of ODCUS AG. A Swiss boutique for cybersecurity, ISMS and compliance. Focus on SMEs with 50 to 500 employees.

The thesis behind ODCUS: most companies do not have a security problem. They have a sizing problem. Too many tools, too little overview, too much cost for too little actual protection. Every engagement starts with the question of what stays and what goes, before anything new gets added.

The practice: 15 years at the intersection of security, operations and executive leadership. Active CISO mandate for more than two years at an industrial company with 1'600 employees. Led ransomware recovery. M365 security reviews at more than ten companies. Zero-Trust trainer at heise, haufe, golem, ComConsult and isits.

Learn more about ODCUS →

Practitioner, not consultant

Background in design engineering and implementation, not PowerPoint. Stays until it stands.

More protection, fewer tools

Duplicate licenses go before new ones come in. Most engagements lower cost and raise protection at the same time.

Vendor-independent. Contractual.

No commissions from tool vendors. Recommendations follow fit, not margin. If an existing tool does the job, it stays.

Senior delivery, no handoff

The senior you meet in the conversation is the one who does the work. No junior handoff after signing.

FAQ

What Swiss SMEs most often ask before onboarding

Conversation at a meeting table
How is a Fractional CISO different from a classic consulting firm?

Consulting firms write recommendations. A Fractional CISO owns the result. On retainer, ODCUS steers the security program like an employed CISO. Defined time allocation, no fixed costs, no junior handoff.

How much does a Fractional CISO cost compared to a full-time CISO?

A full-time CISO in Switzerland costs between CHF 150'000 and 250'000 per year (jobs.ch salary data), plus benefits, recruiting and months of searching. The CISO Retainer starts at CHF 4'900 per month, so CHF 58'800 per year, cancellable after six months. Operational within two weeks instead of after months of recruiting.

We already pay for many security tools. Will this make it more expensive?

Usually not. First step in every engagement: what do you already have, what works, what can go. In most engagements license costs go down while coverage goes up. Cost optimization is part of the engagement, not an add-on.

We are only 80 employees. Aren't we too small for a CISO?

For a full-time CISO, often yes. For a fractional one, that is exactly the target audience. ODCUS works with companies from 50 employees, typically 1 to 4 days per week, 3 to 12 months.

What if we already have an IT lead or security officer?

Common case, good setup. ODCUS complements the line function with methodology and reporting and takes the interface to executive board and audits. Your team keeps day-to-day responsibility but gains time and depth. Also available as pure sparring: second opinion, coaching and preparation of executive and board meetings. Bookable as its own package: CISO Sparring, from CHF 2'400 per month.

What if we already have an ISMS that nobody actually follows?

The most frequent case. ODCUS does not produce new paper but reactivates what exists: what is still current, what must go, where processes are missing, who owns what. Documentation often shrinks by half and the rest becomes workable.

Which frameworks and regulations do you cover?

ISO 27001, NIST CSF, CIS Controls, Swiss ISG, Swiss nDSG, NIS2, DORA, FINMA Circular 2023/01. SOC 2 and TISAX on request.

How quickly can you start?

Intro call within one week. Scoping plus fixed-price offer within five more working days. Kickoff within two weeks of contract signing, depending on scope.

Do you recommend compliance or ISMS tools?

When size and maturity fit, yes. ODCUS is vendor-independent and does not accept commissions from vendors. The tool that gets recommended depends on context, not on a margin. If an existing tool does the job, it stays.

What is the minimum term? What if it does not fit?

The retainer is cancellable monthly after 6 months. Cyber Assessment and ISMS Implementation are fixed-price projects with defined endpoints. If after the first month it becomes clear the setup does not work, ODCUS says so and ends cleanly.

Next step

Ready to give security an owner?

30 minutes on the phone. You describe the situation. ODCUS says honestly whether the engagement fits. If not, you get a referral. Free, no sales slides.

Pick a slot directly in the calendar · 30 minutes · no sign-in needed

info@odcus.com · +41 43 217 86 70 · Switzerland