..

This design element requires flash & JavaScript to be enabled to play. Download the latest version of flash from Adobe.com.

Outsourced CISO

commissum Managed Security services allow us to free up your resources and lighten your workload with our first-class range of management services. These include our outsourced CISO offering, Managing your alignment to ISO27001, helping you to manage critical Business Continuity, and at a more technical level, regular managed testing of your network, applications, and blended code review.

Chief Information Security Officer (CISO)

commissum's Chief Information Security Officer offers expert information security recommendations.

A Chief Information Security Officer (CISO) plays a key role in the management of an organisation’s information security profile, particularly in the light of the ever-increasing number of information security-related regulations that organisations large and small are expected to comply with.

The role of the CISO is complex. It requires considerable experience, both business and technical, to be successful in balancing business risk with environmental and financial objectives, while taking into consideration business constraints and organisational culture.

Today’s extended enterprise includes clients, suppliers, outsourcing partners, stakeholders and joint ventures. Together these form a complex matrix of operational, cultural, legislative and reputational risks.

Often the ability to demonstrable compliance with the Data Protection Act and ISO 27001 becomes a requirement to join a project or bid for work. Only the largest organisations have the resources for these challenges.

Mid-market and SME organisations, however, are frequently unable to dedicate in-house resources to address their information security challenges. They either do nothing, or implement point control in a way that is less than coherent and bypasses strategic thought. Co-opting a junior or inexperienced employee to fill the CISO role often proves worse than doing nothing at all.

commissum's outsourced CISO offering avoids this problem by providing a highly experienced CISO with relevant qualifications, such as ISACA’s Certified Information Security Manager (CISM) or CGEIT (Certified in the Governance of Enterprise IT), to help your business to do the following:

  • Meet globally accepted best practices.
  • Develop a robust and reliable Information Security Management System (ISMS).
  • Optimise technology.
  • Maximise return on investment.
  • Maintain compliance.
  • Develop a security culture.
  • Provide technical expertise using the knowledge of our consulting pool, or by themselves becoming a consultant for an appropriate task.
  • Provide intellectual leadership and advice to senior management and the Board.
  • Identify, analyse and communicate security-related risks.
  • Develop a sustainable security strategy.

Each organisation's requirements are unique. An hour is spent delineating the current state of your information security with an expert commissum consultant at no charge.

The commissum consultant will then define a set of potential high-level objectives and functions that act as input for a (chargeable) half-day workshop at the client's premises, where these objectives will be tabled for discussion by the relevant role players, and a final list of objectives will be agreed.

The output of this workshop will be a remedial roadmap, compiled by the consultant and delivered to the client, which will encompass the objectives agreed in the workshop.

The benefits:

  • Best possible ROI for your information security budget.
  • Compliance with relevant legal and regulatory requirements.
  • Robust and best practice approach to information security management.
  • Sustainability of your ISMS in the future.

Get in touch with one of our security consultants today

  • No obligation
  • Expert advice
  • Tailored solutions
"commissum continues to deliver a professional and high standard of service to us. We have used them for several years and really appreciate their flexibility on changing timescales and project requirements. Having tried several other companies who offer seemingly comparable services prior to working with commissum we can happily say that we have found a long-term partner who consistently delivers where others don't.”

Paul N, Security Manager, UK Financial Services

Latest News

cyber-war

Leading USA military contractor QinetiQ hacked and ransacked by Chinese hackers for three years

A new report from Bloomberg, the business information provider (www.bloomberg.com/news/2013-05-01/china-cyberspies-outwit-u-s-stealing-military-secrets.html) outlines how hackers from China stealthily infiltrated the computer systems of QinetiQ North America, a leading espionage and military contractor to the US government, and the US branch of the British defence technology company QinetiQ. A vast range of highly ...
Wed 08 May, 2013 // Briony
cyber-tanks

Suspected hacker arrested after “biggest-ever DDoS attack”

Police in Spain have arrested a Dutch national on suspicion of launching the largest-ever “Distributed Denial of Service” (DDoS) attack. Sven Olaf Kamphuis, 35, was arrested on April 25th near Barcelona, Spain. At the time, he was in possession of a specially-equipped van set up as a mobile computing and ...
Tue 30 Apr, 2013 // Briony
masked-attacker

Hackers break into large cloud provider, claim to have credit card details

Some days ago, hackers gained access to computers owned by Linode, a company providing cloud services in the form of virtual Linux servers. The hackers gained access by using a “zero-day vulnerability” (a previously unsuspected security weakness) in Adobe ColdFusion, the software used in running the Linode web server. It ...
Fri 26 Apr, 2013 // Briony