zemITis / advisoryConnected expertise.
Expertise by your side.
Information Security Officer

Outsourced Information Security Officer IBF

A registered, CISA/CISM-qualified security officer, backed by senior experts, for a predictable monthly fee. Ongoing NIS2, DORA and ISO 27001 compliance support at a fraction of the cost of a full-time hire.

Senior expertise. Personal accountability. A dedicated information security officer, for a predictable monthly fee.

Predictable monthly fee Ready to start Big Four methodology
Who needs a security officer?
Instant estimate Security officer service

How much does an outsourced security officer cost?

Adjust the sliders and answer a few questions to see your estimated monthly fee.

Number of employees 49 employees
0502501000+
Cybersecurity maturity 3Developing
Core policies are maintained, a risk assessment has been completed and a system inventory exists. Regular reviews, audits and training are still missing.
Has your organisation previously registered an Information Security Officer?
Is your organisation subject to DORA?
Are you planning NIS2 preparation within the next year?
Are you planning ISO 27001 preparation within the next year?
Estimated monthly fee
HUF 300,000–360,000
Indicative monthly fee · excluding VAT
What does the monthly fee cover?View the full scope
Free consultation Response within 24 hours GDPR compliant

This estimate is indicative. We confirm the monthly fee and scope of service in a tailored proposal following a free initial consultation.

The first step

Let’s start with
a clear picture.

Understand the likely costs. Answer a few questions for an instant estimate, then we will work through the details together.

The essentials

What is an Information Security Officer, and who needs to appoint one?

The Information Security Officer, known in Hungary as the IBF, is the named person registered with the supervisory authority to oversee cybersecurity compliance. They maintain policies, coordinate risk assessments, oversee incident management, prepare regulatory notifications and liaise with the authority and auditors, helping turn requirements into working controls.

Act LXIX of 2024

Hungary transposed NIS2 through Act LXIX of 2024 on Cybersecurity. Organisations within its scope must, among other requirements:

  1. register with the supervisory authority,
  2. implement cybersecurity measures proportionate to their risks,
  3. undergo regular cybersecurity audits,
  4. and appoint an Information Security Officer, notifying the relevant supervisory authority. For commercial organisations, this is the Supervisory Authority for Regulated Activities (SZTFH).

The officer may be an employee or an external expert engaged under a service agreement.

Who is subject to the requirement?

The requirement covers medium-sized and larger organisations in sectors of high criticality and other critical sectors, typically those with at least 50 employees or annual turnover or balance sheet total above €10 million. Some providers, including certain digital infrastructure entities, are covered regardless of size.

Sectors of high criticality

8 sectors
  • Energy
  • Transport
  • Healthcare
  • Drinking water and wastewater
  • Digital infrastructure
  • ICT service management
  • Space
  • Certain banking and financial market entities

Other critical sectors

7 sectors
  • Postal and courier services
  • Waste management
  • Chemicals
  • Food production and distribution
  • Manufacturing (medical devices, electronics, machinery and vehicles)
  • Digital providers (online marketplaces, search engines and social platforms)
  • Research
Unsure whether your organisation is in scope? We can clarify your position in a free 30-minute consultation.

What are the risks of having no appointed officer?

Failure to register, appoint an officer or implement required measures can result in regulatory penalties. NIS2 provides for fine ceilings of up to €10 million or 2% of worldwide annual turnover for essential entities, and €7 million or 1.4% for important entities. Significant incidents require an early warning within 24 hours, a notification within 72 hours and a final report within one month. Clear ownership is critical to meeting these deadlines.

€10m / 2%
Maximum fine framework for essential entities
€7m / 1.4%
Maximum fine framework for important entities
Following a reportable incident
  1. 24 hoursearly warning
  2. 72 hoursincident notification
  3. 1 monthfinal report

Updated: September 2026

Included in your monthly fee

What does our monthly security officer service cover?

A named zemITis expert becomes your organisation’s registered Information Security Officer. The monthly fee typically includes around 24 dedicated expert hours, adjusted to your size and security maturity. Your proposal specifies the agreed capacity, covering the following activities:

01

Management systems and policies

  • ISMS design and maintenance: we design an information security management system around your operations, risks and legal obligations. This includes policies, procedures, records and supporting documentation; defined responsibilities and controls; risk management and review processes; and expert implementation support.
  • IT security policy: reviewing and updating your policy, or developing one where needed, and maintaining alignment with legal requirements.
  • Security classification: classifying electronic information systems and maintaining their register.
  • Policies and contracts: reviewed from an information security perspective.
02

Risk management and planning

  • Risk assessment: delivery, coordination and follow-up of treatment plans.
  • Business impact analysis (BIA): prepared with input from the relevant business functions.
  • Annual IT security plan: development and regular updates.
  • Vulnerability management: tracking remediation activities through to completion.
03

Incident management and regulatory liaison

  • Security incident response: expert support and, where required, preparation of regulatory notifications within the 24-hour and 72-hour deadlines.
  • Regulatory liaison: coordination with SZTFH, NBSZ NKI and relevant sectoral bodies, including mandatory annual information security reviews and cybersecurity audits.
04

Awareness and management reporting

  • Two security awareness sessions each year for employees and management.
  • Monthly status updates and quarterly management reports, with ongoing expert advice on issues as they arise.

A named expert, backed by a team

Your registered officer is a named individual, supported by senior information security and compliance advisers. All documentation is reviewed by a second expert before delivery. This gives you broader expertise and continuity while reducing the capacity and knowledge risks of relying on one person.

  1. Monthly Status report
  2. Quarterly Management report
  3. Twice a year Training
  4. Annually Review, IT security plan and risk assessment
Compare your options

In-house or outsourced? What is the true cost?

Recruiting a CISA/CISM-qualified security executive with NIS2 experience can take 3–6 months. Salary, employer contributions, training and certification maintenance typically add up to several million forints per month. Relying on one person also creates gaps during leave, illness or a change of role, while regulatory deadlines continue to apply.

Szempont Full-time in-house security officer zemITis kiszervezett IBF
Monthly cost Gross salary of around HUF 1.5–2m, plus employer contributions, training and certifications: approximately HUF 2–2.5m per month (estimate) Predictable monthly fee, typically HUF 300,000–400,000 plus VAT, depending on size and maturity
Getting started 3–6 months for recruitment and onboarding Ready to begin as soon as the contract is signed
Availability No built-in cover for leave, illness or resignation A team supports your registered officer, keeping the function operational
Professional expertise One person’s knowledge and experience CISA, CISM and ISO 27001 Lead Auditor expertise, with Big Four audit methodology
Quality assurance No independent review All documentation is independently reviewed under the four-eyes principle. We also hold professional indemnity insurance.
Regulatory and auditor relationships A learning curve based on individual experience Established experience as the registered officer for multiple organisations, with knowledge of SZTFH, MNB and NBSZ NKI expectations
Scalability Fixed capacity Monthly hours can be adjusted to your needs, with NIS2, ISO 27001 or DORA projects added where required
Independence Internal organisational relationships An external, objective perspective informed by audit experience

Our outsourced service provides a continuously supported security officer function with senior expertise and predictable fees, at a fraction of the cost of a full-time hire.

Why choose zemITis?

Why entrust your security officer function to zemITis?

Recruiting, integrating and retaining an in-house officer takes time and investment. We offer a practical service that is ready to begin when you are.

Senior expertise

Our advisers bring international and Big Four consulting experience, applying rigorous methods to every engagement.

Recognised qualifications

CISA, CISM and ISO 27001 Lead Auditor specialists help you build and demonstrate audit readiness.

Business focus

We connect legal and regulatory requirements, audit expectations and IT risk management at a strategic level.

Your expert

Who will be your organisation’s registered Information Security Officer?

Dávid Meisitz, CISA, CISM, ISO 27001 Lead Auditor and registered Information Security Officer
CISA CISM ISO/IEC 27001 Lead Auditor

Dávid Meisitz

Senior IT Compliance and NIS2 Readiness Expert, CISA, CISM, ISO/IEC 27001 Lead Auditor

Dávid has over ten years of experience in cybersecurity governance, IT compliance and risk management at multinational organisations. He began his career in Deloitte’s IT audit and security team, where he spent five years. He led general IT control audits, ISO 27001 ISMS implementation and pre-certification reviews, and ISAE 3402 Type II and SOC 2 assurance engagements for banking, telecommunications and energy clients.

As an adviser, he has led NIS2 and DORA programmes for groups operating critical infrastructure, covering current-state assessment, regulatory gap analysis, target operating models and implementation roadmaps. As the contracted, registered Information Security Officer for several organisations, he coordinates security strategy, risk management, incident reporting, supply chain security and regulatory communication.

Regulatory focus
NIS2DORAISO/IEC 27001NIST Cybersecurity FrameworkOperational resilience
Control areas
Identity and access management (IAM/PAM)General IT controlsSAP Security & GRCSegregation of duties (SoD)Internal audit
Sector experience
Critical infrastructureBanking and financial servicesInsuranceTelecommunicationsEnergetikaTechnologyConstruction

“As a registered security officer, I take personal responsibility for the compliance work entrusted to me, backed by a team. Every document we deliver has also been reviewed by a senior colleague. That is the quality expected in a Big Four audit, and difficult for a one-person internal function to provide.”

Dávid Meisitz
Our process

How do we get started?

1
Step 01 30 minutes

Free consultation

We establish whether Hungary’s Cybersecurity Act applies, assess your starting maturity and review any existing security officer appointment and NIS2, ISO 27001 or DORA obligations.

2
Step 02 within 24 hours

Scope and proposal

We agree monthly capacity, responsibilities and any related projects, then provide a tailored proposal with a fixed monthly fee.

3
Step 03

Contract, appointment and regulatory notification

Alongside the contract, we prepare the appointment document and notification to the supervisory authority, SZTFH, ready for your signature.

4
Step 04 first 30 days

Gap analysis and action plan

We assess your current position against legal and standards requirements, prepare a prioritised action plan and establish your information systems register.

5
Step 05

Ongoing delivery

Monthly status updates, quarterly management reports, annual reviews and training keep compliance audit-ready, with prompt expert support for regulatory enquiries.

Is a certification or regulatory deadline approaching? We will align the start of our work with your deadline.
Book a consultation

Your information is secure with us

As information security advisers, we apply the same principles to our own work that we recommend to clients.

  • Least-privilege access We access sensitive business information only to the extent required for our work, using restricted, typically read-only permissions.
  • Segregated storage We manage and store each client’s documentation separately in a controlled Microsoft 365 Business Premium environment with enhanced security settings.
  • Four-eyes review Every document is independently reviewed by another expert before delivery.
  • Confidentiality We work under a non-disclosure agreement (NDA) included in our contract.
FAQ

Common questions about outsourced security officer services

Preparation is a one-off project to establish compliance and support a successful audit. The Information Security Officer (IBF) then provides ongoing monthly support to maintain and oversee compliance.
The fee depends on headcount, cybersecurity maturity and the agreed scope. Our calculator provides an instant estimate. We confirm the final monthly fee after a free consultation and scope review.
Yes. Indicate in the calculator if you plan NIS2 or ISO 27001 preparation within the next year. The monthly estimate will then include full audit preparation and audit support. You can also estimate NIS2 preparation as a standalone project on our NIS2 page.
We can begin as soon as the contract is signed. The initial gap analysis and action plan are typically ready within a few weeks.
No. This service gives you senior, CISA/CISM-qualified expertise without recruiting and retaining a full-time executive.
Yes. The law requires the role to be fulfilled; it does not require an employment relationship. An external expert can perform the work under a service agreement and be registered with the authority in the same way as an employee. A named zemITis expert will act as your registered officer.
The legal obligations remain with your organisation and its management and cannot be transferred through outsourcing. zemITis takes contractual responsibility for the professional delivery of the assigned security officer duties, supporting management with regular reports and decision-making material.
Your registered officer is available within the response time agreed in the contract, supports incident handling and classification, and prepares the 24-hour early warning, 72-hour notification and final report. Your IT team or provider carries out technical containment and recovery; the officer coordinates and documents the response.
The service is designed for continuous compliance, so contracts typically run for an initial 12 months and continue on an open-ended basis thereafter. Your proposal sets out the exact terms.
Obligations must be assessed for each legal entity. The same expert may serve several organisations within a group, with separate appointments where needed. We identify the entities in scope during the consultation and tailor monthly capacity accordingly.
A DPO oversees compliance in the processing of personal data under the GDPR. An Information Security Officer focuses on electronic information system security under Hungary’s Cybersecurity Act and related requirements. The roles complement each other, and some organisations need both. Our outsourced DPO service
DORA sets detailed ICT risk management requirements for the financial sector, supervised in Hungary by the MNB. For clients subject to DORA, our service also covers this framework. You can indicate this in the calculator.
We need an internal contact, usually the IT lead or managing director, access to relevant system information and documents, and management participation in quarterly reporting and annual reviews. We handle policy drafting, records and preparation of regulatory communications.
Get started

Senior security expertise, without a full-time hire.

A free 30-minute consultation and a tailored proposal within 24 hours.