Roles we fill

Some seats the law requires you to fill. We can sit in them.

Regulation increasingly names a person, not just a control — an officer, an owner, a designated contact. Most of those regimes expressly allow that person to be external. We take the seat with a named professional, a defined cadence, and documentation your supervisory authority will accept.

Roles we fillBasis
ICT Risk Control-Function OwnerDORA Art. 6(4) and 6(10)
Cybersecurity Officer (NIS2)National NIS2 transpositions
Data Protection OfficerGDPR Art. 37(6)
Information Security OfficerISO/IEC 27001 Clause 5.3
AI Governance OfficerISO/IEC 42001 · EU AI Act Art. 26
Third-Party / ICT Risk ManagerDORA Arts. 28–30
Business Continuity ManagerISO 22301 · DORA Arts. 11–12
Incident Reporting CoordinatorNIS2 · DORA · CRA reporting deadlines
Whistleblowing / Speak-Up OfficerDirective (EU) 2019/1937
Interim cover for your own officerContinuity of a mandated role

Every role above is delivered under one of the tiers below — the seat is the same, the amount of senior time is what you choose.

Retainers are time-boxed

A named officer role is an allowance of senior time each month, not unlimited availability. We publish the allowance so you can compare us honestly with anyone else.

TierPer monthIncluded
Advisor€1,4001 day per month
Programme€2,6002 days per month
Embedded€4,9004 days per month
Published day rate€950 
  • Unused time rolls over for one month, up to half of that month’s allowance.
  • Additional days are billed at the published day rate — no renegotiation.
  • 4-hour response in business hours for critical issues, one business day otherwise.
  • No 24/7 promise. Where you need it, a vetted partner provides it and we say so up front.
  • 30 days’ notice to cancel, at any time.
Roles bundle — and should. A cybersecurity officer, a data protection officer and an incident-reporting coordinator are one person, one cadence and three obligations discharged. We price bundles at a visible discount rather than stacking three retainers.
One rule we will not break: where we build or run something, we will not also audit it. If we hold your ICT risk control-function seat, we will not act as your ICT auditor. If we build your management system, we will not assess it. That separation costs us a second retainer and protects you — the body that built a system must not be the body that certifies it works. We state it in writing before you engage us.
Discuss which seat you need filled