Highly critical sectors
8 sectors- Energy
- Transport
- Healthcare
- Drinking water and wastewater
- Digital infrastructure
- ICT service management
- Space
- Certain banking and financial market participants
The information security officer (IBF, the Hungarian abbreviation) is the designated professional who coordinates the protection of the organisation’s electronic information systems and the operation of its cybersecurity processes. The officer brings together risk management, governance and incident management activities, supports management decisions, and liaises with the authority, the incident response centre and the auditor. The IBF helps ensure that information security requirements are applied in day-to-day operations. This includes supporting the identification and treatment of risks, keeping security policies up to date, and tracking implementation of the necessary measures. The role can be fulfilled by an employee or an external expert. Through our outsourced IBF service, a named, qualified professional supports your organisation, backed by an expert team and cover arrangements.
Organisations within the scope of the Hungarian Cybersecurity Act are required to appoint an IBF. For businesses operating in highly critical and other critical sectors, important considerations when assessing applicability include a workforce of at least 50 employees or annual net turnover exceeding the HUF equivalent of EUR 10 million. Certain providers are subject to the requirements regardless of their size. We assess precise applicability individually, based on the organisation’s activities and the legal conditions.
For organisations required to appoint an information security officer, the absence of an appointee represents a compliance gap and creates risks in day-to-day operations. Without clear professional coordination, it is harder to track security measures, manage incidents and demonstrate fulfilment of the requirements.
Failure to fulfil the appointment obligation may lead to regulatory measures and fines. The consequences depend on the applicable rules and the specific omission.
Without accountable coordination, assessment of events, internal cooperation and preparation of authority notifications may take longer, putting fulfilment of mandatory deadlines at risk.
Policy reviews, risk tracking and documentation of measures may be overlooked. These gaps can make it harder to demonstrate compliance during an audit.
Unmanaged security risks may increase the costs of operational disruption, data loss and recovery, while weakening the confidence of customers and business partners.
Our outsourced IBF service provides ongoing expert support for directing information security activities, allowing management and your internal IT team to devote more attention to business operations. We help turn requirements into clear tasks and identified risks into actionable plans that can be tracked. From keeping policies up to date and supporting incident management to preparing for audits, we coordinate the necessary activities and provide regular management reports to support informed decisions. Our qualified experts and cover arrangements also ensure continuity of delivery without the need to employ a full-time information security professional. We tailor the precise responsibilities to your organisation’s operations, maturity and regulatory obligations, so that the service strengthens the security of everyday operations alongside compliance. Our engagement can cover the following areas.
Design and maintenance of the information security management system, and preparation or review of policies, procedures, responsibilities and registers.
Gap assessments, risk assessments, business impact analysis, security classification of systems, and preparation of prioritised action plans and annual security plans.
Development of the incident management process, professional classification of events, coordination and documentation of the response, and preparation of notifications required by law.
Professional preparation of the necessary notifications, liaison with competent bodies, and coordination of cybersecurity and certification audits.
Security awareness training, regular management status reports, summaries supporting decisions, and ongoing professional advice.
Ongoing IBF activities can be combined with NIS2, DORA and ISO 27001 readiness, audit support and the necessary technical security improvements.
Establishing the information security officer role is a long-term operational decision. It is worth choosing professional support that addresses everyday tasks as well as changing requirements, audit preparation and unexpected security events. An internal IBF offers a direct presence within the organisation and detailed knowledge of company processes, while the outsourced model can provide experience across several disciplines, independent professional oversight and organised cover arrangements. When making the choice, consider the costs of recruitment, further training, availability and continuity of delivery alongside salary or service fees. Either solution can be appropriate; the decision should reflect your organisation’s size, risks, internal capacity and expected support needs.
An employee is familiar with the organisation’s systems, business priorities and decision-making processes. They can work directly with management and the IT team, bringing security considerations into daily discussions and developments. This model can be particularly beneficial where the volume of work consistently justifies dedicated internal capacity and the organisation can provide the necessary professional support.
An outsourced service gives your company access to a dedicated IBF expert and a supporting team without recruiting a full-time professional. We provide coordinated support for governance, risk management and audit activities, building the necessary organisational knowledge through regular discussions. The service reduces the burden on the internal team and helps management achieve information security objectives through a clear division of responsibilities.
We deliver IBF activities with experts holding CISA and CISM qualifications, drawing on Big Four methodological experience. The appointed IBF is backed by a team with cover arrangements, documents are reviewed under the four-eyes principle, and our work is supported by professional indemnity insurance. Through a designated contact, clients can access expertise across several disciplines, while an organised professional team supports continuity of delivery. During the engagement, we get to know your company’s operations, business priorities and existing IT environment so that the recommended measures are practical to implement.
We approach the IBF role as part of the organisation’s wider operations. We connect management decisions, governance, risk management, audit and technical implementation so that documented compliance also strengthens the organisation’s actual security. We prioritise identified gaps according to their risk and business significance, then turn them into trackable tasks and action plans. This helps direct available resources towards the security objectives that matter most to the company.
We provide management with clear information that supports decisions on open risks, progress with measures and the next steps required. Working with the internal IT team and service providers, we coordinate professional activities and help substantiate completed work with organised, accessible documentation when preparing for audits. Maintaining compliance can then become a planned process in which the organisation’s staff participate through a clear division of duties.
With our company, you can rely on a professional partner who supports your business from interpreting requirements to tracking implementation. We tailor the service scope to current needs and include related readiness or technical security activities where required. Our aim is to give management a clear view of the organisation’s information security position and provide the internal team with practical professional support for everyday tasks.
We review the organisation’s activities, regulatory applicability, current security maturity, existing documentation and related NIS2, DORA or ISO 27001 objectives.
We define the IBF’s duties, internal contacts, service levels, regular reporting and any related readiness projects.
We prepare the professional documents needed for appointment and authority notification, and support the organisation in completing the process.
We assess the current position, identify gaps and create a trackable action plan prioritised according to risk and business considerations.
We maintain the compliance framework, track measures, support incident management, deliver training and reports, and prepare the organisation for audits.
As an information security provider, we consistently apply to our own operations the principles we recommend to clients. System information, risk assessments and internal policies accessed during IBF activities may contain sensitive business information, making their handling an essential part of the engagement. At the outset, we agree what information is needed, who will participate in the work, and the rules for handling and handing over materials. The following principles support transparent, controlled professional cooperation.
We request access only to the information and systems needed to perform the duties, with the narrowest possible permissions. Access needs are tailored to the specific task, and we agree with the client which information and documents are required. Where sufficient, we work from documents or summaries. This reduces the amount of information shared while providing the background needed for professional assessment.
We handle client materials separately with controlled access, and establish retention and handover rules at the start of the service. Organised documentation helps the experts involved work with the appropriate client materials and their current versions. When defining handover arrangements, we also take the client’s internal rules into account so that completed materials can be incorporated into their own records.
Key documents and professional opinions are independently checked by a senior expert before delivery. The review also considers professional consistency, evidence supporting findings and the clarity of recommended measures. This helps identify potential inaccuracies and supports the delivery of documentation that management, the internal team and the auditor can all use.
We work under contractual confidentiality, with professional delivery supported by indemnity insurance and documented workflows. The contract sets out the agreed duties, responsibilities and terms of cooperation so that both parties understand the service scope. We treat the handling of confidential information as part of professional delivery, and align handover and retention of materials with the rules agreed in advance.
Applicability must be assessed against the organisation’s activities, size and the relevant legal conditions. Certain providers may be subject to the requirements regardless of size, so sector classification alone is not sufficient. During the initial consultation, we review the relevant information and help clarify the next steps.
Yes. Hungarian cybersecurity legislation allows the role to be fulfilled through an agreement with an external person. The natural person actually performing the duties must still be named, and the applicable eligibility, appointment and notification requirements must be met. At the start of the service, we support the preparation of the necessary documents and notification.
NIS2 readiness is typically a project with a defined objective: it identifies gaps and supports the implementation of the required measures. The IBF is an ongoing role that coordinates and tracks the related governance, risk management, incident management and reporting activities. The two services can be combined, providing professional support for maintaining the processes established during the readiness project.
The IBF supports the professional direction and coordination of information security activities, working with the internal IT team and service providers. System operations, technical improvements and the technical remediation of incidents are separate responsibilities. We clearly define the division of duties in the contract and can include related technical security services where required.
The organisation and its management remain responsible for fulfilling their legal obligations; outsourcing does not remove that responsibility. The appointed IBF supports management by performing the duties required by the applicable rules and the contract, providing regular reports and preparing information for decisions. At the start of the engagement, we define the responsibilities and the necessary internal involvement.
The IBF supports assessment of the event, coordination and documentation of the response, and preparation of the required authority notifications. The officer works with the organisation’s IT team, service providers and competent bodies. Responsibilities for technical remediation, availability and agreed response times are defined in the service agreement, taking the organisation’s applicable notification deadlines into account.
Yes. The service scope can be supplemented with NIS2, DORA or ISO 27001 readiness, audit support and technical security solutions. The related activities are agreed separately based on the organisation’s obligations and objectives. The IBF service alone does not constitute certification or automatic compliance with every requirement.
The appointed IBF is backed by cover arrangements and senior experts who support continuity of delivery. We define the arrangements for cover, communication and urgent tasks within the engagement. If the named appointee changes, the necessary appointment and notification steps must also be completed.
Pricing depends on the organisation’s size, the complexity of its systems, its security maturity and the scope of the agreed duties. We also consider the expert capacity required, reporting needs and any related readiness projects. Following the initial consultation, we set out the service scope and pricing in an individual proposal.
An internal contact, access to relevant system information and documents, and management participation in decisions and approval of action plans are required. Involvement from the internal IT team and business functions is also important for implementing the agreed activities. We jointly define responsibilities and the arrangements for meetings at the start.
We request only the information and access needed for the agreed duties, with permissions defined together with the client. Where sufficient, we work from documents and summaries. Client materials are handled separately, and confidentiality, retention and handover conditions are established at the start of the engagement.
Contact us and, during an initial consultation, we will review your organisation’s regulatory applicability, current position and the appropriate service scope.
Request a consultation