Finding and retaining a senior Information Security Officer is a significant recruitment challenge. CISA/CISM-level specialists are scarce and command substantial salaries. NIS2 has also made the function a requirement for many organisations. An outsourced security officer, known in Hungary as an IBF, is therefore a realistic alternative. Which model best suits your business?
What does an Information Security Officer do?
The officer oversees information security governance. Typical duties include:
- developing and maintaining security policies and procedures;
- risk assessment and treatment;
- incident management and regulatory liaison where necessary;
- organising security awareness training;
- preparing for and supporting NIS2, DORA and ISO 27001 audits;
- reporting to management on the organisation’s security posture.
For many entities under NIS2, the function is required. The practical question is how to provide it: internally or through an external service.
When does outsourcing make sense?
The outsourced model is often attractive when:
- the function is needed, but not a full-time executive;
- senior CISA/CISM expertise is needed immediately, without recruitment;
- a predictable monthly fee is preferable to salary, contributions and staff turnover costs;
- compliance requires project support, such as NIS2 or ISO 27001 preparation;
- independence matters, with an external officer less exposed to internal pressures.
Comparing the two models
| Factor | In-house officer | Outsourced officer |
|---|---|---|
| Cost | Salary, employer contributions and training | Predictable monthly fee |
| Expertise | Depends on one person | Team experience and multiple qualifications |
| Availability | Leave and absence create gaps | Continuity under agreed service levels |
| Start-up | Recruitment can take months | Can begin within days |
| Independence | Internal interests may influence decisions | External, objective perspective |
| Scalability | Capacity is harder to adjust | Can expand as needs change |
An internal officer may have deeper organisational knowledge. Outsourcing offers speed, predictable delivery and concentrated expertise.
What should a good outsourced service include?
A substantive service provides concrete outputs as well as availability:
- ongoing access to an expert;
- gap analysis and annual or quarterly action plans;
- regular risk assessment and review;
- documented security officer reports;
- policy development and updates;
- audit support and incident management;
- business continuity, disaster recovery and awareness training support.
What does management gain?
Management receives a clear picture of the security posture, while the provider performs the agreed expert duties. The organisation and its leadership remain legally accountable and must continue to provide decisions, resources and oversight. Our appointment guide explains the requirements.
What does it cost?
Monthly fees depend on size, cybersecurity maturity and scope. NIS2 or ISO 27001 preparation can be incorporated where needed. Start with an estimate, then refine it through a free consultation around your actual requirements.
How do we begin?
A short assessment establishes the capacity needed and your compliance goals. On our security officer service page, you can get an estimate in a few clicks and discuss whether an internal or outsourced model is the better fit.