Roles we fill
Some seats the law requires you to fill. We can sit in them.
Regulation increasingly names a person, not just a control — an officer, an owner, a designated contact. Most of those regimes expressly allow that person to be external. We take the seat with a named professional, a defined cadence, and documentation your supervisory authority will accept.
| Roles we fill | Basis |
|---|---|
| ICT Risk Control-Function Owner | DORA Art. 6(4) and 6(10) |
| Cybersecurity Officer (NIS2) | National NIS2 transpositions |
| Data Protection Officer | GDPR Art. 37(6) |
| Information Security Officer | ISO/IEC 27001 Clause 5.3 |
| AI Governance Officer | ISO/IEC 42001 · EU AI Act Art. 26 |
| Third-Party / ICT Risk Manager | DORA Arts. 28–30 |
| Business Continuity Manager | ISO 22301 · DORA Arts. 11–12 |
| Incident Reporting Coordinator | NIS2 · DORA · CRA reporting deadlines |
| Whistleblowing / Speak-Up Officer | Directive (EU) 2019/1937 |
| Interim cover for your own officer | Continuity of a mandated role |
Every role above is delivered under one of the tiers below — the seat is the same, the amount of senior time is what you choose.
Retainers are time-boxed
A named officer role is an allowance of senior time each month, not unlimited availability. We publish the allowance so you can compare us honestly with anyone else.
| Tier | Per month | Included |
|---|---|---|
| Advisor | €1,400 | 1 day per month |
| Programme | €2,600 | 2 days per month |
| Embedded | €4,900 | 4 days per month |
| Published day rate | €950 |
- Unused time rolls over for one month, up to half of that month’s allowance.
- Additional days are billed at the published day rate — no renegotiation.
- 4-hour response in business hours for critical issues, one business day otherwise.
- No 24/7 promise. Where you need it, a vetted partner provides it and we say so up front.
- 30 days’ notice to cancel, at any time.
Roles bundle — and should. A cybersecurity officer, a data protection officer and an incident-reporting coordinator are one person, one cadence and three obligations discharged. We price bundles at a visible discount rather than stacking three retainers.
One rule we will not break: where we build or run something, we will not also audit it. If we hold your ICT risk control-function seat, we will not act as your ICT auditor. If we build your management system, we will not assess it. That separation costs us a second retainer and protects you — the body that built a system must not be the body that certifies it works. We state it in writing before you engage us.
Discuss which seat you need filled