Cybersecurity manager as a service

A cybersecurity manager who leaves evidence behind

We take on the cybersecurity manager role for entities in scope of NIS2 — Directive (EU) 2022/2555, independent of your IT operations, and we produce evidence for every obligation that will hold up under supervision. No Word files and verbal assurances: every control, risk, incident and decision lives in a system whose records cannot be rewritten after the fact.

The framework we work in
NIS2 · 2022/2555 ISO/IEC 27001 ISO/IEC 27005 GDPR national transpositions
Art. 20

Management bodies are personally accountable

Management must approve the risk-management measures, oversee their implementation and undergo training. Accountability cannot be delegated to the IT department — and in most transpositions it cannot be insured away either.

24 / 72 h

Incident reporting deadlines

Early warning within 24 hours, notification within 72 hours, final report within one month (Art. 23). The clock starts when you become aware of the incident — not when someone gets around to it.

€10m / 2%

Upper limit of fines

For essential entities, at least up to €10 million or 2 % of total worldwide annual turnover, whichever is higher; for important entities at least €7 million or 1.4 % (Art. 34). Member states may go higher.

Who your manager will be

A named individual with a certificate, not „our team"

Regulators do not ask for a supplier — they ask for an assigned person who is independent of IT operations and development and who meets a demonstrable knowledge standard. That is why we give you a name and a certificate number at the outset, instead of a marketing line about an experienced team.

The certificate is issued by an accredited certification body under the certification scheme of the Slovak National Security Authority and is verifiable in that body's public register. You do not have to take our word for it — check it.

Every contract comes with a copy of the certificate, the appointment letter and a signed conflict-of-interest declaration. A named deputy is part of the service, so the role is never left vacant. Where a national transposition requires a specific statutory role or a locally licensed professional, we deliver that part together with local counsel and say so up front.

cybersecurity manager certificate — verifiable

Branislav Anwarzai, MSc. Eng.

Cybersecurity Manager

Certificate number0699/20/24/MKB/153/O-012
Certification bodyTÜV SÜD Slovakia s.r.o.
SNAS accreditation153/O-012 · ISO/IEC 17024
SchemeNSA of the Slovak Republic, v. 1.2
Valid until17 December 2027

How to verify it: the certification body publishes the register of certificate holders on its website. Search it for the certificate number above.

What makes us different

Three sentences nobody else in this market says

There is no shortage of outsourced cybersecurity managers. Their activity lists are nearly identical. The difference is what you are left holding after a year.

We are independent of your IT

We do not run your infrastructure, so we satisfy the independence expectation that runs through NIS2 transpositions. If your IT supplier holds the role, they are checking their own work — and that is a finding at audit.

The software is in the fee

You are not just buying consultant hours. The fee includes the Praetorix GRC platform, Vigil security monitoring and the lexpetra.pro legal layer. Competitors deliver documents — we deliver the system those documents live and are timestamped in.

Public pricing and measurable SLAs

Our prices are on this page, not „available on request after a free consultation". You know in advance what you get, by when and for how much — including a guarantee that you do not pay for delayed milestones.

Scope of service

Every obligation mapped to an article and to a concrete deliverable

This is the table your auditor will open. It shows which legal obligation we cover, what we actually do about it and what evidence is left behind.

Legal obligationWhat we doDeliverable / evidenceTool
Art. 20
governance and accountability of management bodies
appointed cybersecurity manager and deputy, appointment letter, evidence of qualification, management training appointment, CV, certificate, role and authority description, training records Praetorix
Art. 21(2)
risk-management measures (a) – (j)
gap analysis → remediation plan → implementation management → periodic effectiveness review control matrix with status, plan with owners and deadlines, quarterly effectiveness review Praetorix
Risk analysis
Art. 21(2)(a), ISO/IEC 27005
asset and threat identification, scoring, residual risk after exposure and control effectiveness, relationships between risks risk register, heat map, attack chains, re-assessment due dates Praetorix
Art. 21(2)(d)
supply chain security
supplier inventory, criticality classification, security clauses in contracts, DPAs, verification of compliance supplier register, clause set, list of contracts to be amended lexpetra.pro
+ Praetorix
Art. 23
incident reporting
intake, classification, incident handling, drafting of notifications, communication with the CSIRT and competent authority incident file with a timeline, submitted notifications, lessons learned Vigil
Audit and self-assessment self-assessment, preparation for an external audit, support throughout the audit self-assessment report, corrective action plan, audit-ready package Praetorix
Security documentation creation and maintenance of the policy set — security policy, risk management, incidents, continuity, access, suppliers, cryptography, hygiene, training 17+ documents, versioned and approved by management Praetorix
Art. 21(2)(g)
cyber hygiene and awareness
training plan, e-learning, phishing simulations, evaluation training records, simulation results, trend over time Vigil
Continuous monitoring log collection and correlation across key systems, detection, monthly report monthly report with records whose integrity can be verified Vigil
Art. 21(2)(b), (c)
incident handling and business continuity
incident response plan, backup and recovery review, crisis management, tabletop exercise response plan, exercise record, recovery test results Vigil
First 90 days

A week-by-week plan with acceptance criteria

The market tells you „implementation takes 4 – 12 weeks". We tell you what you get in which week and how you will know it was actually finished.

Week 1

Appointment, access, kick-off

Appointment letter, evidence of the knowledge standard, split of responsibilities (RACI).

Acceptance: the appointment is signed by management.
Weeks 1 – 2

Inventory of assets, services and suppliers

Asset register and supplier register — without these neither risk analysis nor supply chain work is possible.

Acceptance: at least 95 % of critical systems are in the register.
Weeks 2 – 3

Gap analysis against Art. 21 and the local transposition

Control matrix with compliance status and the ten most serious gaps ranked by impact.

Acceptance: reviewed with management.
Weeks 3 – 4

Risk analysis

Risk register with residual scoring and a heat map, including relationships between risks (attack chains).

Acceptance: approved by management.
Weeks 4 – 6

Security documentation set

17+ policies and procedures, versioned, with an approval workflow.

Acceptance: approved and published.
Weeks 5 – 6

Monitoring onboarding

Logs from key systems, alerting and an audit log with guaranteed integrity.

Acceptance: first monthly report delivered.
Weeks 6 – 7

Supply chain

Security clauses under Art. 21(2)(d), list of contracts to be amended, GDPR data processing agreements.

Acceptance: handed over to legal or procurement.
Weeks 7 – 8

Incident process and drill

Incident response plan, CSIRT and authority contacts, a drill of the 24-hour and 72-hour notifications.

Acceptance: simulated incident handled successfully.
Weeks 8 – 10

Training and phishing simulation

Training records and a simulation evaluation with recommendations.

Acceptance: at least 80 % of staff trained.
Weeks 10 – 12

Self-assessment and remediation plan

Self-assessment report and a corrective action plan with deadlines and owners.

Acceptance: handed to management, ready for the authority.

Milestone guarantee

If we fail to deliver the week 1 – 8 milestones within 90 days of signature, the monthly fees for the period of delay are not invoiced. This is not a gesture — it is the only way a promise about deadlines can be verified.

Software included

Three systems, one chain of evidence

These are not three products sitting side by side. A penetration test finding raises the exposure of an asset, that recalculates the risk, the risk calls for a control, the control becomes a contractual obligation on a supplier — and the whole path stays in the audit log.

Praetorix
GRC — „the auditor opens the system and it is all there"
  • Registers of assets, threats, risks and controls, with an automatically generated Statement of Applicability.
  • Residual risk = inherent × exposure × control effectiveness; relationships between risks reveal attack chains.
  • Risk re-assessment due dates with „overdue / due soon" flags — this is the first question at audit.
  • Change trail: who changed what and when on every risk and control — hash-chained with append-only protection, exportable to PDF.
  • Group model for holdings: a consolidated view across entities with data isolation.
Vigil
Monitoring — „we can prove the monitoring actually ran"
  • Log collection and correlation, detection, alerting; monthly report with verifiable record integrity.
  • Incident module with statutory deadlines — the system counts the 24-hour, 72-hour and one-month deadlines and escalates on its own.
  • Tamper-evident audit log (anchored hash chain) — nobody can rewrite history retroactively, including us.
  • Penetration test orchestration and finding management with automatic impact on risk scores.
  • Client portal: your status, reports, DPAs and SLA performance in one place.
lexpetra.pro
Legal layer — „we do not do the legal part from a desk"
  • Legislative change monitoring with impact analysis mapped to your specific controls.
  • Security clauses for supplier contracts and GDPR data processing agreements.
  • Review of existing supplier contracts and a list of those that need amending.
  • Register of deadlines and obligations — registration, controls, self-assessment, audit — with advance reminders.
The combined effect. This is the thing a standalone consultant or a standalone SOC cannot give you — a single source of truth across technology, governance and law: pentest finding → asset exposure → recalculated risk → control → supplier obligation → evidence in the audit log
Pricing

Our prices are published. The rest of the market's are not.

Prices are final — we are not VAT registered; they assume a 12-month term. The onboarding package is a one-off fee covering the effort of the first 6 – 10 weeks, during which the documentation, the risk analysis and the monitoring onboarding are produced.

Start

Important entity, up to 100 employees, 1 – 2 sites
€690 / mo.
Onboarding package €2,900
8 h response · business days
  • 8 manager hours per month
  • Praetorix GRC — 1 entity
  • Vigil Starter
  • Legislative monitoring
  • Annual self-assessment
  • Annual training (online)
  • Quarterly management reporting
  • Representation before the authority and CSIRT
Free assessment
Most popular

Standard

Essential or important entity, 100 – 500 employees, multiple systems
€1,490 / mo.
Onboarding package €6,900
4 h response · 24/7
  • 20 manager hours per month
  • Praetorix GRC + extended registers
  • Vigil Standard
  • Contract clauses + DPAs
  • Annual self-assessment
  • Training 2×/year + phishing 2×
  • Monthly reporting + quarterly for management
  • Representation before the authority and CSIRT
Free assessment

Essential Entity

Essential entity with heightened supervisory exposure
€2,900 / mo.
Onboarding package €14,900
1 h response · 24/7
  • 40 manager hours per month + on-call
  • Praetorix GRC + group reporting
  • Vigil Enterprise
  • Supplier contract review
  • Self-assessment + audit preparation
  • Training 4×/year + phishing 4× + tabletop exercise
  • Monthly reporting and on demand
  • Representation before the authority, on-site during incidents
Free assessment

Group / On-prem

Holding with multiple entities or a requirement to run inside your own network
from €4,500 / mo.
Onboarding package individual
1 h response · per SLA
  • Manager capacity per agreed SLA
  • Praetorix — group model, on-prem
  • Vigil Enterprise / on-prem
  • Full legal layer
  • Self-assessment per entity
  • Training per plan
  • Monthly reporting
  • Representation before the authority and CSIRT
Free assessment

Add-on services

Audit by a certified auditor

Delivered by a partner cybersecurity auditor.

from €4,900one-off

Penetration testing

Findings feed asset exposure and recalculate the risk register.

from €3,900one-off

Phishing campaign

Simulation with evaluation and training recommendations.

€390per campaign

Management training

Half a day — management accountability under NIS2 Art. 20.

€890half day

GDPR / DPO package

Data protection officer alongside the cybersecurity manager role.

from €390per month

Incident response retainer

Outside the Essential Entity plan, where it is already included.

€490per month

Discounts: 24-month term −8 % · annual prepayment −5 % · second and each further entity in a group −30 %.  ·  All prices are final — we are not VAT registered. The stated scope assumes the client's cooperation in providing access to documents and systems.

Why these numbers. An in-house cybersecurity manager costs €40,000 – 72,000 a year including employer contributions, plus 3 – 6 months of recruitment and the risk that they leave. Standard works out at €17,880 a year and the software is included. We are deliberately above the „paperwork" segment starting at €30 a month — the obligations of a regulated entity cannot be met for that — and below the integrators and consultancy brands that start at €2,500 a month without software.
Comparison

Four ways to fill the cybersecurity manager role

All four are lawful. Not all four survive an audit, and not all four are cheaper than they first appear.

In-houseTypical outsourcedIT supplierPraetorix
Annual cost€40 – 72k€10 – 30k„included in support"€8.3 – 34.8k
Independence from IT operationsoften notyesno — conflict of interestyes
Availability from signature3 – 6 months' hiring2 – 4 weeksimmediatewithin 5 working days
Cover during leave and sicknessnonerarelyyesnamed deputy included
GRC platform includednononoyes — Praetorix
Monitoring and integrity-proof audit lognonopartly (SOC)yes — Vigil
Legal layer and contract clausesnononoyes — lexpetra.pro
Public price listnonoyes
Measurable SLA and milestone guaranteerarelyrarelyyes
Commitments

What we guarantee in writing

The following points go into the contract exactly as they are written here.

Availability and response

Start: business days 08:00 – 17:00. Standard: 24/7 by phone during an incident. Essential Entity: 24/7 with a one-hour response. We draft the early warning within 12 hours of incident classification — the law allows 24, and that margin is yours.

Reporting

Monthly report by the fifth working day of the following month. Quarterly management report within 10 working days of quarter end. The report also covers what was missed — not only what went well.

Data protection

Processing on our infrastructure inside the European Union, or on-premise at your site. Data processing agreement under Art. 28 GDPR. We do not send the content of your documents to external AI services. An NDA is signed before first access to your data.

Exit without lock-in

On request, a complete data export — registers, documentation, audit log — within 10 working days, in open formats. The documentation remains yours after the engagement ends.

Milestone guarantee

If the first eight weeks' milestones are not delivered within 90 days, we do not invoice the monthly fees for the period of delay.

Continuity of the role

A named deputy is part of the service. The role is not left vacant during leave or sickness — which is the single most common finding with in-house appointments.

FAQ

The questions we get most often

We have an IT provider — can they take the role?+

They can, but they would be assessing their own work. Independence from IT operations runs through NIS2 supervisory practice, and in several member states — Slovakia and Czechia among them — it is written directly into the law. If your IT supplier holds the role, they approve their own controls, which is a finding that is hard to defend.

We work with your IT supplier, assign tasks and verify delivery. But we assess them independently, because we do not manage them and have no stake in their invoicing.

Who exactly will be our cybersecurity manager?+

Branislav Anwarzai, MSc. Eng., holder of Cybersecurity Manager certificate no. 0699/20/24/MKB/153/O-012 issued by TÜV SÜD Slovakia s.r.o. — a certification body accredited by the Slovak National Accreditation Service under 153/O-012 to ISO/IEC 17024, under the certification scheme of the National Security Authority of the Slovak Republic, version 1.2. Valid until 17 December 2027.

The certificate is verifiable in the public register of holders published on the certification body's website. A copy of the certificate, the appointment letter and a conflict-of-interest declaration are attached to the contract.

Does a Slovak certificate work in our country?+

NIS2 itself does not prescribe a specific certificate for the role — Art. 21 requires appropriate and proportionate measures, and national transpositions require demonstrable knowledge and independence from operations. We present the certificate as third-party-verifiable evidence of that knowledge standard, not as a local statutory licence.

Where your transposition does require a specific statutory role or a locally licensed professional — a security audit by a nationally qualified auditor, for example — we say so during the assessment and deliver that part with a local partner. We will not claim a qualification we do not hold.

It is expensive.+

An in-house cybersecurity manager costs €40,000 – 72,000 a year including employer contributions. Our Standard plan works out at €17,880 a year and the software is included. You also avoid 3 – 6 months of recruitment and the risk of the person leaving a year later, taking the know-how with them.

The other side of the equation: under Art. 34 of NIS2, essential entities face fines of at least up to €10 million or 2 % of worldwide turnover, important entities at least €7 million or 1.4 %.

We can do it ourselves, we have templates.+

Templates are not the problem — they can be bought. The problem is demonstrating performance: a risk analysis with re-assessment dates, training records, an incident timeline and, above all, evidence that records were not altered after the fact.

That is exactly what a template cannot give you. An auditor does not ask whether a document exists. They ask when it was created, who approved it and what has changed since.

Why not a large consultancy brand?+

You get the same articles for roughly three times the price, usually without a system for the outputs to live in, and with a junior consultant doing the daily work. We have a public price list, measurable SLAs and a milestone guarantee.

If you need a big brand name for your board, that is a legitimate reason to go elsewhere — and we will tell you so directly.

What are our deadlines?+

NIS2 sets the reporting deadlines directly: 24 hours for the early warning, 72 hours for the notification and one month for the final report (Art. 23).

Registration, implementation of measures and audit or self-assessment deadlines follow your member state's transposition and differ between countries. We determine the ones that apply to you during the initial assessment, in writing.

Can we see references?+

References are available on request. We deliberately do not publish them — in cybersecurity, a client list is itself sensitive information, and we name clients only with their explicit consent.

After the initial assessment we will put you in direct contact with a reference client from a comparable sector, so you can ask them rather than us.

What happens if we part ways?+

Within 10 working days you receive a complete export of all data — registers, documentation and the audit log — in open formats. The documentation is yours. No vendor lock-in and no exit fees.

No-obligation request

Find out what the law actually requires of you

Fill in the form — we create a tracked ticket and get back to you within 24 hours. The first step is a 30-minute obligations assessment: whether you are in scope, as an essential or important entity, which deadlines are running and what is missing today.

  • No obligation and no cost
  • Tracked ticket with a reference number
  • Assessment of classification and deadlines under NIS2
  • If you are out of scope, we will say so
  • References available on request

New ticket — vCISO

PRX-DEMO-••••

Submitting creates a tracked ticket. We reply within 24 hours.

The role has to be filled in a way that holds up

Risk analysis and approval of documentation need calendar time on your side too — this is not work that can be squeezed into the final month before a deadline.