Add your offcanvas content in here

The Company

Simplifying your IT-security journey.

External ISB

Whether it’s NIS-2, KRITIS, or BSI IT-Grundschutz: Information security requirements are increasing, and qualified professionals are in short supply. With mgm security partners, you can fill the role of Information Security Officer with experienced senior experts without having to build up internal capacity. We can take on the role entirely or supplement your team, providing ongoing support for your ISMS and ensuring it remains compliant with regulatory requirements.

ISB as a Requirement and a Bottleneck: NIS-2 and KRITIS require a functioning information security organization with clear responsibilities. An external ISB reliably fulfills this function, even if the organization lacks the time or the appropriate qualifications internally.

Background

Fundamentals

What an External ISB Does

The Information Security Officer (ISO) serves as the central point of coordination for all strategic and organizational issues related to information security. The ISO reports to senior management, oversees the Information Security Management System (ISMS), and ensures that regulatory requirements are met and risks are controlled. The role is demanding and requires both regulatory and technical expertise, which often cannot be maintained in-house on a permanent basis.

As an external ISB, we provide this service. You’ll have a dedicated point of contact with many years of experience, guaranteed coverage, and the support of an entire security team. We’ll continue to manage an existing ISMS in an organized manner or assist you in setting one up, guided by NIS-2, KRITIS, and BSI IT-Grundschutz, and tailored to your actual level of implementation.

Immediately
Experienced senior ISBs take on the role without a lengthy recruitment process
Representation
Continuity of the ISB function through established substitution procedures within the team
Independent
Advisory and oversight role, free from internal conflicts of interest
NIS-2 / KRITIS
With a strong regulatory foundation and experience from projects for government agencies and KRITIS operators

The challenge

Attention!
  • The ISB has a crucial role to play, but qualified professionals are scarce and expensive
  • NIS-2 and KRITIS require a robust information security organization
  • An employee is absent due to vacation, illness, or resignation
  • The ISMS must be maintained and kept up to date with regulatory requirements on an ongoing basis
  • Reporting requirements to the BSI are subject to tight deadlines and strict standards
  • Management bears personal responsibility for oversight

I am the reading text. I can be deselected below via the toggle. Lorem ipsum dolor sit amet sed Marcus is here today in the Colosseum. But where is Cornelia? She waits a long time. Finally she rejoices and laughs. There she is! There she sits!

Our Added Value

Result
  • Senior expertise available immediately, rather than months of recruiting
  • A dedicated point of contact with reliable backup within the team
  • Ongoing maintenance and further development of your existing ISMS
  • Monitoring of NIS-2, KRITIS, and BSI IT-Grundschutz, directly translated into your measures
  • Support with reporting requirements, audits, and regulatory inspections
  • Regulatory and technical expertise from a single source, with access to penetration testers and auditors

I am the reading text. I can be deselected below via the toggle. Lorem ipsum dolor sit amet sed Marcus is here today in the Colosseum. But where is Cornelia? She waits a long time. Finally she rejoices and laughs. There she is! There she sits!

What the external ISB Handles

Offer

From strategic consulting to ISMS maintenance and incident response support. We continuously coordinate specific priorities with you, based on your current situation and requirements.

  • Advising senior management and functional departments
  • Coordination with Data Protection, IT, and relevant departments
  • Promoting a Culture of Safety and Awareness Initiatives
  • Reports directly to senior management
  • Maintenance of action plans, guidelines, and risk assessments
  • Identification and Assessment of New Risks
  • Adapting Existing Measures to New Threat Scenarios
  • Based on the BSI IT-Grundschutz framework, tailored to your level of implementation
  • Monitoring of Legal and Regulatory Developments
  • Implementation of the Requirements Under NIS-2 and KRITIS Regulations
  • Support for management in fulfilling its supervisory duties under Article 20 of NIS-2
  • Preparation of Management Reports and Supporting Documentation
  • Support for Internal and External Audits
  • Preparation for Regulatory Inspections
  • Thorough preparation of documentation and supporting evidence
  • Preparation of Management Reviews by Senior Management
  • Assessment of Incidents from an Information Security Perspective
  • Coordination of reporting requirements to the BSI (24 / 72 h)
  • Support for Internal Communication
  • Documentation, Lessons Learned, and Prevention
  • Monthly Status Report on Activities and Open Issues
  • Quarterly Report on the Information Security Situation to Management
  • Ad-hoc Communication in Response to Relevant Events
  • Recommendations for Management
Role & Responsibilities

Advising, monitoring, coordinating

The external ISB serves in an advisory and coordinating capacity within your information security organization. It supports management and the functional departments without assuming any operational or disciplinary responsibility for technical operations. This ensures that the role remains independent and clearly defined. The regulatory framework consists primarily of the NIS 2 Directive as implemented at the national level (NIS2UmsuCG), the KRITIS regulations under the BSI Act, and the BSI IT-Grundschutz as a methodological framework.

  • Consulting & Governance: Strategic and operational consulting; development and maintenance of security-related policies and measures.
  • Documentation & Regulatory Compliance: Support with audits, management reviews, risk assessments, and regulatory reporting requirements.
  • Reporting: Coordinating the reporting requirements for security incidents to the BSI and other authorities.
  • Reporting: Regular reports to management and stakeholders on the security situation, risks, and measures.
  • Continuity: Guaranteed coverage during extended absences, with equally qualified consultants from the team.

Not included

  • Authority to issue instructions to internal employees or third parties
  • Responsibility for the effectiveness of individual measures within the company
  • Forensic analyses or active incident response measures
  • Penetration tests or technical audits, unless otherwise agreed
  • Operation of Technical Systems

I am the reading text. I can be deselected below via the toggle. Lorem ipsum dolor sit amet sed Marcus is here today in the Colosseum. But where is Cornelia? She waits a long time. Finally she rejoices and laughs. There she is! There she sits!

Part of the role

Result
  • Consulting, Monitoring, and Coordination of Information Security
  • Maintenance and Further Development of the ISMS and Documentation
  • Coordination of Reporting Requirements and Communication with Government Agencies
  • Preparation for and Support During Audits and Inspections
  • Reporting to Management and Stakeholders

I am the reading text. I can be deselected below via the toggle. Lorem ipsum dolor sit amet sed Marcus is here today in the Colosseum. But where is Cornelia? She waits a long time. Finally she rejoices and laughs. There she is! There she sits!

Transparency & Reporting

Communication That Aligns with Executive Leadership

Transparent and tailored communication with management and stakeholders is an integral part of the engagement. You’ll always know the status of your security situation, what risks remain, and what measures are currently in place. We tailor the format, level of detail, and audience to your organization’s specific needs, ensuring that the information reaches the decision-makers.

In addition, the external ISB assists senior management in fulfilling its oversight and governance obligations in the area of information security in accordance with Article 20 of the NIS 2 Directive and prepares the necessary documentation and status reports.

  • Monthly Status Report: A brief written summary of the work performed, outstanding issues, and current risks, sent to your designated contact person.
  • Quarterly Report to Management: Comprehensive report on the information security situation, including the status of ongoing measures, regulatory developments, and specific recommendations for action.
  • Ad hoc communication: Immediate notification regarding security-related incidents, reporting requirements, or last-minute management decisions, within the agreed-upon service hours.

From Structured Onboarding to Ongoing Support

Approach

We will take over the ISB function in an orderly manner and without any gaps. Services are provided primarily remotely, though on-site appointments are possible by arrangement. Our collaboration is flexible and tailored to your actual needs.

  • 1 – Onboarding: A structured handover of documents, system access, and points of contact until the role is functioning completely independently.
  • 2 – Ongoing Support: Regular support, including monthly status meetings, ongoing consultation, and continuous maintenance of the ISMS.
  • 3 – Coordination & Prioritization: Ongoing coordination with you; tasks are prioritized jointly based on the company’s current situation and requirements.
  • 4 – Ongoing Development: Monitoring regulatory changes, adapting measures, and preparing for audits to ensure that your ISMS remains up to date at all times.

Reliable Service Hours

Clear service hours and response times give you the certainty you need for planning. We treat critical cases as a top priority.

  • Hours of Operation (Mon–Fri): We are available on weekdays from 9:00 a.m. to 5:00 p.m., except on federal holidays.
  • General Inquiries: Technical coordination, scheduling appointments, and document management are handled promptly during business hours.
  • Urgent Cases: Security-related incidents, reporting requirements under NIS-2 and KRITIS, and last-minute management decisions are treated as high priority.

The ISB in conjunction with your ISMS

Information

The external ISB oversees your management system and regulatory compliance. Depending on your specific situation, we combine this service with ISMS implementation, ISO 27001 certification, or NIS 2 consulting.

ISMS Implementation

Don't have a management system yet? We'll set up a streamlined, effective ISMS, which ISB will then maintain and further develop.

ISO 27001 Consulting

Are you looking to obtain certification? We’ll guide you through the ISO 27001 certification process, and ISB will subsequently maintain the ISMS on an ongoing basis.

NIS2 Consulting

Affected by NIS-2? We’ll determine the extent of your impact and provide a roadmap that the external ISB will implement for ongoing operations.

An entire security team supporting your ISB

  • Over 25 years of experience in IT security consulting
  • Thousands of penetration tests and security analyses conducted
  • ISO 27001 certified and TISAX-compliant
  • Experience from projects for government agencies and operators of critical infrastructure

mgm security partners covers the full spectrum of IT security, from consulting to security analyses and penetration tests to training. This means your external ISB is never on its own: When needed, it can draw on pentesters, auditors, and application security experts. We are ISO 27001 and TISAX certified and work for clients including the BSI, other federal and state agencies, and KRITIS operators.

External ISB: Quick Answers to Your Questions

Yes. The role of the information security officer can be outsourced to an external service provider. Overall responsibility for information security remains with management; the external information security officer performs advisory, monitoring, and coordinating functions and supports management in fulfilling its oversight and governance obligations.

Unlike with an in-house employee, we ensure the continuity of the role. In the event of a prolonged absence by the assigned consultant, we will, in consultation with you, provide a suitable replacement with comparable qualifications from our team. You will be notified in a timely manner.

No. The process begins with a structured onboarding phase during which all relevant documents, system access credentials, and points of contact are provided. This phase is considered complete once the external ISB is able to independently take over the ongoing tasks. This ensures a smooth transition without any gaps.

The external ISB acts as an independent consultant and assumes no operational or disciplinary responsibility for the operation of technical systems. It is up to you to implement any recommendations. If technical specialists are needed—for example, for penetration tests, forensic analyses, or incident response—we will bring them on board from the mgm team through a separate engagement.

Support is provided primarily remotely via video conference, email, and phone, with a monthly status meeting and regular reporting. On-site meetings are possible by arrangement. To ensure a successful collaboration, please designate an internal contact person with decision-making authority and ensure access to relevant information.

NIS-2 and KRITIS require an effective information security organization with clear responsibilities and reporting processes. Appointing a designated ISB is the standard way to centralize this responsibility. We will determine whether you are affected as part of our NIS-2 consulting services; the external ISB will then oversee the transition to routine operations.

Maximiliane Mayer

Your ISB functions in experienced hands. Contact us for a free initial consultation!