Reg. No. 40203410806VAT LV40203410806

Theme

Book a consultationBook

CISO-as-a-Service · client intake

Tell us how your security actually runs

This is the discovery questionnaire we open every CISO-as-a-Service engagement with. It maps your obligations, your posture and what it takes to switch the OffSeq platform on across your estate — and returns an indicative monthly retainer as you go.

Nothing is submitted automatically. When you finish, the form builds a summary you can email, copy or download — your answers stay in your browser until you send them. Required fields are marked *. Allow roughly 20 minutes; skip anything you're unsure of.

CISO-as-a-Service intake

01 of 13Company & contactThe basics, plus the two numbers that anchor the estimate: team size and how many legal entities are in scope.
02 of 13Business context & criticalityWhat you do, what cannot stop, and why you are engaging a CISO now.
What is driving this engagement?
03 of 13Regulatory & compliance scopeThis section drives your estimate. NIS2 essential/important status and DORA change both scope and fee.
Registered with the national authority (NKC / CERT)?
Has a cybersecurity self-assessment been submitted?
Are you a financial entity in scope of DORA?
Frameworks you hold or are targeting

Each framework beyond the first adds €450/mo of program effort.

04 of 13Governance & riskWho owns security today, and whether leadership has met its NIS2 duties.
Has management formally approved the risk-management measures?
Has the management body completed cybersecurity training (NIS2 Art. 20)?
Risk appetite defined & documented

1 = not in place · 5 = measured & improving

Is there a formal risk-assessment methodology?
Risk register maturity

1 = not in place · 5 = measured & improving

05 of 13Posture self-rating (NIST CSF 2.0)Rate each function 1 (nothing in place) to 5 (measured & improving). This becomes your roadmap heatmap.
Govern

1 = not in place · 5 = measured & improving

Identify

1 = not in place · 5 = measured & improving

Protect

1 = not in place · 5 = measured & improving

Detect

1 = not in place · 5 = measured & improving

Respond

1 = not in place · 5 = measured & improving

Recover

1 = not in place · 5 = measured & improving

06 of 13Identity & accessThe single most attacked surface — we look at reach, not just presence.
MFA is enforced on
Phishing-resistant MFA (FIDO2 / passkeys) in use?
Privileged access management maturity

1 = not in place · 5 = measured & improving

07 of 13Endpoints & devices — Pulse rolloutWhat it takes to deploy Pulse across your workstations for posture evidence and remote device control.
Operating-system mix
Any end-of-life / unsupported OS in use?
Endpoint management in place

Determines how quietly Pulse can be pushed.

08 of 13Infrastructure, assets & dataWhere things run and what matters most if it leaks.
IT environment
Cloud & major SaaS
Data-classification maturity

1 = not in place · 5 = measured & improving

Is any data stored outside the EU?
09 of 13Vulnerability & patch management — threat-finderWhat automated CVE scanning with threat-finder and Radar would cover.
Is credentialed scanning permitted?
Can you authorise OffSeq to scan your external assets?
10 of 13External surface & email security — Guard / BreachSeed values so Guard and Breach can start mapping your exposure on day one.
Are SPF and DKIM configured?
11 of 13Detection, response & incidentsWhether you can see an attack and meet the reporting clock.
24/7 security monitoring in place?
Incident-response plan tested in the last 12 months

1 = not in place · 5 = measured & improving

Could you meet NIS2 24-hour / 72-hour reporting?
Reportable incidents in the last 12 months?
12 of 13Resilience, suppliers & physicalBackups that actually restore, third-party risk, and the building.
Immutable / air-gapped backup copy?
Do you assess supplier security risk?
Physical & environmental controls
13 of 13OffSeq platform & engagementThe whole platform is included in the retainer — tell us where to start and how you want to work.
Platform capabilities of most interest
Roll Pulse out across workstations as a first step?
Add 24/7 on-call incident response?

Adds €600/mo to the estimate.

Do you carry cyber insurance?
AI / LLM usage & governance maturity

1 = not in place · 5 = measured & improving

Helpful tools

  1. 01Scope a testCreate a scoped brief in one minute
  2. 02NIS2 / DORA scope checkCheck whether the regulations apply to your organization
  3. 03Security maturity assessmentAssess your organization across six domains
  4. 04Sample reportA complete sample report with evidence-backed findings from Critical to Low, CVSS scoring, OWASP mapping and a prioritized remediation plan.