Capability 01
Virtual CISO Program
Ongoing executive-level cyber leadership, without the cost or commitment of a full-time CISO. One senior advisor owns your risk picture, reports it to your board or leadership, and keeps the security roadmap moving.
When to engage
A security leader just left, and the roadmap left with them.
A major customer's security questionnaire is holding up a deal, and you can't answer it with confidence.
Your regulator expects a named person accountable for security, reporting to your leadership, and right now you don't have one.
Your board or an investor is asking for a security roadmap and risk reporting.
You're raising, selling, or taking on an investor, and their diligence team is asking hard questions about your security posture.
How it works
It begins with a baseline: a senior advisor spends the first couple of months learning your business, your systems, and where you're exposed, then turns that into a roadmap your board or leadership can sign off on. After that it's an ongoing relationship. The same person owns your risk picture month to month, reports it in plain terms your leadership can act on, and keeps the roadmap moving instead of letting it stall. The specific projects plug in under that leadership when the roadmap calls for them: a risk assessment, a policy build, an incident-response plan. Each is also available on its own if a one-time need is all you have.
What you receive
- Your top risks identified, quantified, and kept current as things change
- A policy and procedure set kept current and mapped to what your regulator or auditor expects
- A security roadmap that keeps moving, with owners and milestones
- Risk reporting your board and leadership can act on
- Vendor and third-party risk, reviewed and tracked over time
- An incident response plan kept ready, not just written once
- We carry your security program through your audit or exam, and speak the examiner's language
Timeframe
An ongoing engagement, billed monthly. Most clients begin with a 60–90 day baseline assessment.
How the engagement is structured
Most engagements begin in the Advisory or Embedded tier and move up as the security program grows.
Advisory
A defensible answer to 'who owns security?'
~8 hrs / month
- Cadence
- Quarterly risk review and a board summary
- Scope
- Security strategy, policy guidance, and an annual roadmap
- Compliance
- Framework gap assessment
Embedded
A security program actively run and reported.
~16–20 hrs / month
- Cadence
- Monthly leadership sync and board reporting
- Scope
- Advisory scope, plus incident response planning and vendor risk management
- Compliance
- Active audit preparation support
Executive
A program owned end to end, through audit.
~40 hrs / month
- Cadence
- Weekly, on-site as needed
- Scope
- Embedded security leadership across the organization
- Compliance
- Full program ownership through audit
Who does the work
Your vCISO is one named senior advisor who has held the CISO or CTO seat and answered to a board, not a rotating bench of analysts. You get the same person each month, someone who has built and defended a security program and can do it again for you.