Know where you stand
A structured posture assessment, a risk register, a prioritised roadmap, a policy set and one framework mapped. A fixed engagement with a defined end, not a subscription.
What you get: a decision-ready picture of where you are.
Most virtual CISOs advise on an estate they have never looked inside, working from what you told them in a workshop. Ours sits on top of a SOC that has been watching it around the clock, so the risk register is built from evidence rather than recollection.
Most organisations that need a CISO cannot justify one, and most that hire one too early get an expensive person writing documents nobody reads.
The job is not really technical. It is deciding what matters, in what order, with the money available, and then being accountable for that decision in front of a board, an insurer, a regulator or a customer running a due-diligence questionnaire. That is a few days a month of judgement, not a full-time salary.
What makes it hard to buy is that the market sells it two ways and neither works well. A consultancy sells you a senior name who appears quarterly and has no idea what changed in between. A cheaper provider sells you a template: the same risk register, the same policy pack, the same roadmap everybody else got, with the logo changed.
Ask a vCISO how they built your risk register and the honest answer is usually: from a workshop, an asset list somebody exported, and a questionnaire your team filled in at the end of a Friday.
That is not incompetence, it is the shape of the engagement. An advisor who is not operating anything has no independent view of the estate, so the risk register records what the organisation believes about itself. The gaps that matter are precisely the ones nobody knew to report.
Where we also run detection and response, the advisory side inherits the operational one. What is actually connected, what actually fires, which controls are actually deployed and which are deployed and silent - that is observed rather than asked about. The risk register starts from evidence, and the roadmap gets re-sequenced when the estate proves something different from what the workshop said.
If you already have a SOC you are happy with, the vCISO service still stands on its own. It is simply better informed where we can see the estate, and we would rather say which version you are buying.
The reason vCISO engagements disappoint is almost always that the senior person spent the days producing documents instead of making decisions.
Assessment, risk register, policy set, task plan, framework mapping, board pack. That is most of a traditional vCISO month, it is largely mechanical, and you are paying a senior day rate for it. We run a specialist platform that produces all of it, operated by us as part of the service, so those days buy judgement instead of formatting.
It also makes the service continuous rather than quarterly. The assessment is re-run rather than rewritten, remediation is tracked between meetings instead of rediscovered at the next one, and the mapping across frameworks updates itself when a control changes. You are not licensing or learning any of it.
A structured assessment of where you actually are, run against the frameworks you are held to rather than a generic maturity model.
A risk register and a roadmap sequenced by consequence and cost, with the reasoning recorded so a board can challenge it.
Policies, standards and the framework mapping behind them, generated and kept current rather than written once and left to rot.
Remediation tracked to closed between meetings, with your named advisor chasing it rather than reporting on it.
Board packs, customer questionnaires and audit evidence produced from the same live picture rather than assembled the week before.
Most people start with the assessment because it answers the question they actually have, and it is a fixed piece of work with an end.
A structured posture assessment, a risk register, a prioritised roadmap, a policy set and one framework mapped. A fixed engagement with a defined end, not a subscription.
What you get: a decision-ready picture of where you are.
Baseline made continuous, with a named advisor in your meetings, reassessment on a cycle, remediation tracked to closed, multi-framework mapping and board reporting.
What you get: a named person accountable for the programme.
The vCISO service plus a named framework driven to audit-ready, with evidence collected as you go. For when a customer, an insurer or a regulator is the reason this is happening.
What you get: the evidence pack, and somebody to defend it.
Third-party risk is a module rather than a tier, and can be added to any of them or bought on its own. Nothing is priced before the scope is agreed in writing.
A senior security leader you buy by the day rather than employ. They set the strategy, own the risk register, drive the programme and answer to your board, insurer and customers. Also sold as CISO as a service or a fractional CISO; the three terms describe the same job.
A consultant delivers a piece of work and leaves. A vCISO holds a standing accountability: the same named person, in your meetings, owning the programme between them. The test is whether anyone is answerable for security when nothing in particular is happening.
Most organisations of a few hundred people land between two and four days a month once the initial assessment is done, and more during an audit, a funding round or after an incident. We size it after the Baseline assessment rather than guessing at the start.
A named person. They are in your meetings, they know your estate and they answer your board. There is a team behind them for depth and for cover, but the accountability sits with one individual rather than rotating.
No, and the service stands on its own. It is materially better informed where we also run detection and response, because the risk register is then built from what your estate is actually doing rather than from what a workshop reported. We will tell you which version you are buying.
The common ones and most of the uncommon ones: ISO 27001, NIS2, DORA, SOC 2, NIST CSF, CIS, GDPR and the NCSC frameworks among others. Controls are mapped across frameworks rather than assessed separately, so answering one largely answers the next.
Yes, and for most organisations that is one of the first things that pays for the service. The evidence sits in one current place rather than being reassembled by three people every time a large customer asks.
Your vCISO leads from your side: decisions, stakeholders, disclosure and the write-up afterwards. Where we run your SOC the technical response is already underway, so there is no cold start and no explaining your estate to somebody new at the worst moment.
Baseline is a fixed engagement with a defined end. It answers the question you actually have, and it tells both of us how many days a month the ongoing service really needs.