Proposal
CISO and BISO as a Service
You engage the function itself. The CISO, the chief information security officer, answers for security across the whole company and takes the subject to the board in the board's own language. The BISO, the business information security officer, sits inside one business area and translates security into the context of that operation, which is where the decisions actually happen. In both cases the level of dedication is agreed with you, and the person belongs to DM11 while answering as if they were yours.
No price appears on this page. Scope does: what we do, how we run it, who runs it and what is not included. The people who read your request are the ones who will look after you, and they come back with the proposal and with time to talk it through.
CISO and BISO as a Service
The security leadership seat, without hiring an executive.
How we run it
What this work consists of
You hire the security leadership function, not a seat on the org chart. The CISO owns security for the entire company and brings the topic to the board in the board's language. The BISO sits inside a business area, product or operations, and translates security into the context where the risk-creating decision is actually made. The person is from DM11, the time commitment is agreed, and they answer as if they were yours.
The work opens with a baseline diagnostic and continues as an ongoing operation: a security plan with defined priorities and owners, periodic reporting to decision makers, and follow-up meetings at the agreed cadence. In the CISO seat, that includes representing the company before clients, auditors, and regulators; in the BISO seat, it includes being the bridge between the business area and corporate security.
On your side, we need the mandate: access to the board, the business areas, and the information the role requires. Security without a seat at the table becomes an ignored recommendation, and that is exactly what this service exists to prevent. What you get is the topic with an owner: plan, priorities, reporting, and someone who answers when a client or auditor asks.
How we conduct it, stage by stage
Opening assessment
A snapshot of the starting point: what exists, what is written down and what actually works. Progress will be measured against it at the end of the period, so we record it with method, not from memory.
Continuous operation
Throughout the contract we keep what was built alive: we review it at every relevant change, run what is on the calendar and report at the agreed frequency. It is what separates a delivered document from a practice still worth something a year later.
What is not included
- Tool operation, technical on-call, and ticket handling, which stay with the technical team or a managed operations provider
- Statutory executive liability for the company, which cannot be outsourced
- Implementation projects, which are quoted separately and delivered by our technical team
- The data protection officer (DPO) role, which is a distinct position with its own obligations under Brazil's LGPD
- Final budget and investment decisions: the CISO prioritizes and makes the case, your board approves
- Signing vendor contracts on the company's behalf: we recommend and evaluate, you sign
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.