Report an Incident Become a Partner Careers Contact
Book a Demo
Consultancy · virtual CISO

A vCISO who can see
the estate.

Most virtual CISOs advise on an estate they have never looked inside, working from what you told them in a workshop. Ours sits on top of a SOC that has been watching it around the clock, so the risk register is built from evidence rather than recollection.

Programme · month 3continuous
ASSESSPosture re-run, not rewrittencurrent
POLICYFramework mapping updated automaticallymapped
SOCControl deployed but producing no telemetryobserved
RISKRegister updated from the estate itselfre-ranked
BOARDReal incident volumes, not benchmarksreported
NAMEDOne advisor, accountableyours
What a vCISO is for

Somebody senior
who owns the answer.

Most organisations that need a CISO cannot justify one, and most that hire one too early get an expensive person writing documents nobody reads.

The job is not really technical. It is deciding what matters, in what order, with the money available, and then being accountable for that decision in front of a board, an insurer, a regulator or a customer running a due-diligence questionnaire. That is a few days a month of judgement, not a full-time salary.

What makes it hard to buy is that the market sells it two ways and neither works well. A consultancy sells you a senior name who appears quarterly and has no idea what changed in between. A cheaper provider sells you a template: the same risk register, the same policy pack, the same roadmap everybody else got, with the logo changed.

  • A named person, not a rotating bench, who is in your meetings and answers your board.
  • A risk register built from your estate rather than from a questionnaire.
  • A roadmap that is sequenced by consequence and cost, not by framework order.
  • Policies and standards that exist, are current, and are mapped to the frameworks you are held to.
  • The answers to customer security questionnaires, without a fire drill each time.
  • An escalation path to an incident responder who is already watching your estate.
Why it matters that we run the SOC

Advice about an estate
nobody has looked at.

Ask a vCISO how they built your risk register and the honest answer is usually: from a workshop, an asset list somebody exported, and a questionnaire your team filled in at the end of a Friday.

That is not incompetence, it is the shape of the engagement. An advisor who is not operating anything has no independent view of the estate, so the risk register records what the organisation believes about itself. The gaps that matter are precisely the ones nobody knew to report.

Where we also run detection and response, the advisory side inherits the operational one. What is actually connected, what actually fires, which controls are actually deployed and which are deployed and silent - that is observed rather than asked about. The risk register starts from evidence, and the roadmap gets re-sequenced when the estate proves something different from what the workshop said.

The 24/7 managed AI SOC

The register starts from the estate
Coverage gaps, unmonitored systems and controls that exist on paper but produce no telemetry are visible to us directly rather than self-reported.
Incidents feed the roadmap
What actually happened to you this quarter changes what gets prioritised next quarter. That is a closed loop rather than an annual refresh.
The board pack is not a guess
Real incident volumes, real response times and real coverage, from the operation rather than from an industry benchmark slide.
Escalation is already in place
When something serious happens there is no cold start: the analysts are already there, and average time to an L1 verdict across our SOC is 3m 30s.

If you already have a SOC you are happy with, the vCISO service still stands on its own. It is simply better informed where we can see the estate, and we would rather say which version you are buying.

How the service runs

The paperwork is automated
so the judgement is not.

The reason vCISO engagements disappoint is almost always that the senior person spent the days producing documents instead of making decisions.

Assessment, risk register, policy set, task plan, framework mapping, board pack. That is most of a traditional vCISO month, it is largely mechanical, and you are paying a senior day rate for it. We run a specialist platform that produces all of it, operated by us as part of the service, so those days buy judgement instead of formatting.

It also makes the service continuous rather than quarterly. The assessment is re-run rather than rewritten, remediation is tracked between meetings instead of rediscovered at the next one, and the mapping across frameworks updates itself when a control changes. You are not licensing or learning any of it.

  1. 01

    Assess

    A structured assessment of where you actually are, run against the frameworks you are held to rather than a generic maturity model.

  2. 02

    Prioritise

    A risk register and a roadmap sequenced by consequence and cost, with the reasoning recorded so a board can challenge it.

  3. 03

    Document

    Policies, standards and the framework mapping behind them, generated and kept current rather than written once and left to rot.

  4. 04

    Drive it

    Remediation tracked to closed between meetings, with your named advisor chasing it rather than reporting on it.

  5. 05

    Report

    Board packs, customer questionnaires and audit evidence produced from the same live picture rather than assembled the week before.

How to buy it

Three ways in,
and the first one is finite.

Most people start with the assessment because it answers the question they actually have, and it is a fixed piece of work with an end.

Baseline

Know where you stand

A structured posture assessment, a risk register, a prioritised roadmap, a policy set and one framework mapped. A fixed engagement with a defined end, not a subscription.

What you get: a decision-ready picture of where you are.

vCISO

Somebody owns it

Baseline made continuous, with a named advisor in your meetings, reassessment on a cycle, remediation tracked to closed, multi-framework mapping and board reporting.

What you get: a named person accountable for the programme.

Assurance

Prove it to someone else

The vCISO service plus a named framework driven to audit-ready, with evidence collected as you go. For when a customer, an insurer or a regulator is the reason this is happening.

What you get: the evidence pack, and somebody to defend it.

Third-party risk is a module rather than a tier, and can be added to any of them or bought on its own. Nothing is priced before the scope is agreed in writing.

Third-party risk management

Questions

vCISO, answered.

What is a vCISO?

A senior security leader you buy by the day rather than employ. They set the strategy, own the risk register, drive the programme and answer to your board, insurer and customers. Also sold as CISO as a service or a fractional CISO; the three terms describe the same job.

How is this different from a consultant?

A consultant delivers a piece of work and leaves. A vCISO holds a standing accountability: the same named person, in your meetings, owning the programme between them. The test is whether anyone is answerable for security when nothing in particular is happening.

How many days a month do we need?

Most organisations of a few hundred people land between two and four days a month once the initial assessment is done, and more during an audit, a funding round or after an incident. We size it after the Baseline assessment rather than guessing at the start.

Do we get a named person or a bench?

A named person. They are in your meetings, they know your estate and they answer your board. There is a team behind them for depth and for cover, but the accountability sits with one individual rather than rotating.

Do we have to use your SOC as well?

No, and the service stands on its own. It is materially better informed where we also run detection and response, because the risk register is then built from what your estate is actually doing rather than from what a workshop reported. We will tell you which version you are buying.

Which frameworks can you work to?

The common ones and most of the uncommon ones: ISO 27001, NIS2, DORA, SOC 2, NIST CSF, CIS, GDPR and the NCSC frameworks among others. Controls are mapped across frameworks rather than assessed separately, so answering one largely answers the next.

Can you answer our customer security questionnaires?

Yes, and for most organisations that is one of the first things that pays for the service. The evidence sits in one current place rather than being reassembled by three people every time a large customer asks.

What happens in an incident?

Your vCISO leads from your side: decisions, stakeholders, disclosure and the write-up afterwards. Where we run your SOC the technical response is already underway, so there is no cold start and no explaining your estate to somebody new at the worst moment.

Where to start

Start with the assessment
then decide if you want us to own it.

Baseline is a fixed engagement with a defined end. It answers the question you actually have, and it tells both of us how many days a month the ongoing service really needs.