A role you will not fill with an advert on Pracuj.pl

The Polish labour market is short of information security specialists. The global shortfall runs to four million people, and the situation in Poland is no better — the competition for qualified people is fought between a private sector offering salaries counted in tens of thousands of zloty and a public sector offering a pay scale and a thirteenth-month bonus. The outcome of that contest is a foregone conclusion.

Meanwhile the obligations keep growing. The Regulation on the National Interoperability Framework (KRI), in §19, requires public entities to designate a person responsible for maintaining and improving the information security management system (ISMS). The amendment to the Polish NIS-2 implementing act (the KSC Act), which transposes the NIS-2 Directive, extends that requirement to water companies, heating plants and municipal companies. And ISO 27001:2022 — increasingly required in tenders — assumes that someone competent is watching over the system day to day.

The answer that more and more organisations are reaching for is to outsource the function. It is a good solution — provided it is done with care. Because a badly chosen external information security officer can do more harm than having none at all.

When outsourcing makes sense — and when it is an excuse

Outsourcing the information security officer role works in organisations that meet at least one of the following conditions: they are unable to recruit a suitably qualified employee onto the payroll; they need access to a wider team of experts than a single person; or they want an independent view of the state of their security — free of internal dependencies and habits.

In practice this applies to most local government units and their subordinate bodies — social welfare centres, district family support centres, libraries, schools — as well as to municipal companies: water utilities, heating plants, waste management plants and transport operators.

Outsourcing does not, however, make sense where an organisation treats it as a way of making the problem go away. An external officer does not relieve management of responsibility for information security — neither legally nor in practice. This is a partner, not a substitute.

Five criteria that separate a partner from a supplier

A team, not a person with a briefcase

Information security is an interdisciplinary field. It calls for competence in law (GDPR, KRI, NIS-2, the KSC Act), IT (networks, systems, infrastructure), OT technology (SCADA, PLC — if we are talking about water utilities or heating plants), risk management and audit.

No single person will master all of that to a sufficient level. That is why the key question when choosing a partner is: who stands behind this person? Does the officer have a support base — a lawyer, an IT specialist, an auditor — or are they a lone consultant who promises everything and delivers PowerPoint presentations?

A firm offering to take on this function should have a team whose competences complement one another. The auditor does not have to configure the firewall — but someone on that team should be able to do it when the need arises.

Sector experience — not every sector is the same

A water utility is not a law firm. A commune office is not an e-commerce business. A school is not a bank. The specifics of the public sector — public procurement procedures, multi-year financial plans, dependence on grants, staff turnover after local elections — require the officer to have not just technical knowledge but an understanding of the context in which the organisation operates.

Ask about concrete experience: how many local government units does this firm serve? Has it worked with water and sewerage companies? Does it know the line-of-business systems — eDokumenty, BeSTi@, population register systems? Does it understand that in a commune office serving three thousand residents, the entire cybersecurity budget amounts to what a corporation spends on a single licence?

Availability and response times

An officer who appears once a quarter, signs a review record and disappears is not an officer — they are a signature on a document. Real availability means a clearly defined incident response time (ideally counted in hours, not days), regular visits or video calls, and continuous operational contact with a designated IT person inside the organisation.

The contract should contain a specific SLA: response time to an incident report, maximum time for delivering a report, frequency of reviews. Generalities such as "we provide ongoing support" are not enough — and in the event of an inspection or audit they may prove worthless.

Transparent reporting

A good officer does not hide behind jargon. Reports for management should be intelligible to non-technical people — the head of the commune, the mayor, the company's managing director. They should contain a clear assessment of the state of security, a list of the risks identified, prioritised recommendations, and progress on earlier recommendations.

Ask candidates for sample reports (anonymised). The way someone reports says a great deal about the way they work — if the report is a thirty-page document full of tables and acronyms that nobody reads, then something is wrong with the approach, not just the format.

A partnership, not a subordinate relationship

An external officer should treat the organisation as a partner — knowing its people, understanding its constraints, proposing solutions matched to what it can actually do. They cannot impose procedures copied from a corporate template that will be a dead letter in a commune office.

At the same time, they should have the courage to say uncomfortable things. If the head of the commune is using a personal USB stick holding residents' data, the officer should raise it — politely, but firmly. A partner who always agrees does not protect the organisation. They protect their contract.

Pitfalls to watch out for

The shell company — a certificate with nothing behind it

There are firms on the market offering an "outsourced officer" that amounts to signing a contract, handing over documentation templates and minimal contact thereafter. The documents look correct — until an inspection by Poland's data protection authority (UODO) or an ISO 27001 certification audit arrives and it turns out that the policies do not reflect the reality of the organisation, the risk analysis is a copy from another body, and employees cannot remember their last training session.

The safeguard: the contract should set out specific obligations — the number of visits or meetings, a requirement to tailor the documentation, an obligation to deliver training with confirmation of attendance.

Conflict of interest — auditor and implementer in one

If the same firm that acts as information security officer is also selling the organisation IT hardware, software licences or other services, a conflict of interest arises. The officer should recommend the solutions that are best for the organisation, not for their own profit and loss account.

This does not mean the firm cannot provide both services — but the line must be clearly drawn. The officer's recommendations should be independent of the firm's commercial offering, and the organisation should have the right to have them independently verified.

Lack of continuity — consultant turnover

Outsourcing assumes that the organisation gains a stable partner. If the contact person changes every six months, knowledge of the organisation's specifics has to be built up from scratch each time. That is not just wasted time — it is a security risk, because the new consultant does not know the incident history, does not understand the context of earlier decisions and is not familiar with the nuances of the local infrastructure.

It is worth stipulating in the contract a minimum period of continuity for key personnel, together with a knowledge handover procedure in the event of a change.

How to protect your interests in the contract

A contract with an external firm acting as information security officer should contain — beyond the standard provisions — several elements specific to this type of service.

The first is a precise scope of duties, split between recurring tasks (reviews, training, reports) and reactive ones (handling incidents, support during inspections). The second is measurable service quality indicators (KPIs): the number of training sessions delivered, incident response time, timeliness of reports, the proportion of recommendations from the previous review that have been implemented.

The third element is an exit clause — a procedure for ending the relationship and handing over the documentation. The contract should state precisely what happens once it is terminated: who takes over the ISMS documentation, in what format and by what deadline the materials will be handed over, and what the transition period looks like. The organisation must not become hostage to its supplier — the full documentation, registers, audit results and training materials must remain the property of the client.

The fourth element is a confidentiality undertaking — extended to the whole team with access to the organisation's information, not just to the person holding the officer role.

The fifth is an escalation and dispute resolution mechanism, allowing operational problems to be resolved before they turn into a legal conflict.

From practice — what works in the real world

A local government unit of some tens of thousands of residents, with a half-time IT employee and an IT budget covering mainly the upkeep of existing infrastructure, decided to outsource the information security officer role after two years of unsuccessfully trying to recruit a specialist. The result: an ISMS implemented and maintained, an internal audit carried out, employees trained — at a saving of around 40% compared with employing someone separately.

A district heating company that had passed an ISO 27001:2022 certification audit decided to outsource the officer role after certification — to maintain and improve the system. The decisive selection criterion was the partner's experience in OT environments, where the update cycle is measured in years and a maintenance window has to be planned several weeks in advance.

How Fib.Code delivers this service

Fib.Code offers outsourcing of the information security officer function in a model that combines continuous availability with a multidisciplinary support base. Behind every organisation we serve stands a team: an information security auditor, a lawyer specialising in data protection, and an IT specialist with experience of infrastructure in local government units and municipal companies.

We work with local authorities, water companies, heating plants, schools and subordinate bodies. We know the line-of-business systems, we understand public procurement procedures, we know that the cybersecurity budget in a small commune looks nothing like the one in an energy sector company — and we are able to deliver real value within that budget.

Our terms of engagement are transparent: a defined scope, measurable KPIs, a clear exit clause, full handover of documentation once the contract ends. Because if a client stays with us, it should be because they want to, not because they have to.

We have written at greater length about the vCISO model — the virtual chief information security officer, which extends the officer service with a strategic component — in the article vCISO — the virtual information security director.

We would be glad to talk about how we can support your organisation: l.grabowski@fibcode.com | fibcode.com/en/contact