Virtual CISO
Security leadership, without the full-time hire. You get an experienced security executive in your business for a set number of days each month: setting strategy, sitting in your management meetings, answering to your board, and owning the roadmap.
Four reasons this lands on someone's desk.
Decided by whoever's least busy
Security decisions are being made by whoever is least busy, not by whoever should be making them.
A client or insurer asked
A client or an insurer has asked who your CISO is, and there wasn't a clean answer.
A diligence pack with no owner
You are raising, and the diligence pack has a security section nobody owns.
Not ready for a full salary
You know you need the role and cannot yet justify a full-time salary against it.
Ownership, not advice from the sidelines.
- 01Owns the security strategy and the roadmap, with a budget attached to it that finance can approve.
- 02Reports to your board in language it understands, and takes the questions.
- 03Runs the risk register and the decisions that come out of it, including the risks you choose to accept.
- 04Manages your vendors, including us. If a tool is not earning its licence, you will hear it.
- 05Leads incident response at the command level when something happens.
- 06Builds your internal capability. The goal is that you need this service less each year, not more.
Three levels of commitment. One minimum term.
| Level | Commitment | Suited to |
|---|---|---|
| Advisory | 2 days per month | Strategy, board reporting, and oversight of an existing team |
| Embedded | 5 days per month | Building the programme from a standing start, with hands on the work |
| Programme | 10 days per month | Certification, multi-market expansion, or post-incident rebuild |
Minimum engagement six months. Anything shorter produces a document, not a change.
A programme, not a slide deck.
- 01A security strategy and a costed 12-month roadmap, approved by your executive team.
- 02A risk register with named owners and agreed treatment decisions.
- 03A board-level reporting pack you can reuse every quarter.
- 04A clear answer to the question "who is accountable for security here", with a name attached.
Straight answers, before you ask.
How many days a month does a virtual CISO actually work with us?
It depends on the level: Advisory is 2 days a month for strategy, board reporting, and oversight of an existing team. Embedded is 5 days a month for building the programme from a standing start. Programme is 10 days a month for certification, multi-market expansion, or a post-incident rebuild.
What is the minimum engagement length?
Six months. Anything shorter produces a document, not a change.
What do we get in the first 90 days?
A security strategy and a costed 12-month roadmap approved by your executive team, a risk register with named owners and agreed treatment decisions, a board-level reporting pack you can reuse every quarter, and a clear, named answer to who is accountable for security.
Does the virtual CISO manage our existing security vendors?
Yes, including us. If a tool is not earning its licence, you will hear it — the role is accountable to your business, not to any one vendor's renewal.
Is this different from managed security operations?
Yes. A virtual CISO sets strategy, owns the roadmap, and answers to your board — it is a leadership role. Managed security operations is the team that runs the day-to-day programme underneath that strategy. Many clients use both together.
Put a name against security accountability.
Same NDA, same named executive, same 90-day deliverables described above — scoped to your business. Minimum engagement six months.
Virtual CISO.
Request received.
A named executive will reply within one business day to scope the NDA and the engagement level.