Secure · Cyber & Networks
Virtual CISO
Senior security leadership on a part-time basis: strategy, risk ownership, board reporting and programme direction without a full-time hire.
The challenge
Many organisations carry the risk profile of a large enterprise without the budget or the pipeline to hire a full-time chief information security officer.
Without that leadership, security spending follows the last incident or the loudest vendor, risk decisions are made by default, and the board receives either reassurance or alarm rather than a balanced picture.
A virtual CISO provides experienced direction, a coherent programme and credible reporting, scaled to what your organisation needs.
Our method
How the work is done.
- 01
Baseline
We assess the current security posture, programme, team and spending against NIST CSF to establish where you stand.
- 02
Strategy
A security strategy and multi-year roadmap tied to business priorities and risk appetite.
- 03
Governance
We establish the security committee, risk register, policy framework and reporting cadence.
- 04
Programme direction
Ongoing leadership of security projects, vendor selection, budgets and the internal team.
- 05
Reporting
Regular board and executive reporting on risk, progress and incidents.
- 06
Transition
Where appropriate, we help define the permanent role and support recruitment and handover.
Deliverables
What you receive.
- Security posture baseline against NIST CSF
- Security strategy and roadmap
- Security governance charter and committee terms of reference
- Maintained risk register
- Quarterly board reports
- Security budget and vendor recommendations
- Role profile and handover plan for a permanent CISO
Engagement options
Ways to buy it.
- 0112 months, renewable
Retained leadership
A named security leader for an agreed number of days each month.
- 023 to 9 months
Interim cover
More intensive cover during a vacancy or major programme.
- 034 to 6 weeks
Strategy sprint
A baseline assessment and roadmap, without ongoing leadership.
Standards
Frameworks we work to.
- NIST CSF
- ISO 27001
- CIS Controls
- ISO 31000
Questions
What buyers ask us.
How many days a month does a virtual CISO work?
It is agreed to your needs, typically a few days a month, with more during audits, incidents or major programmes.
Will the virtual CISO attend board meetings?
Yes. Board and committee reporting is a core part of the role.
Does the virtual CISO hold formal accountability?
Accountability for risk stays with your executives. The virtual CISO advises, directs the programme and makes sure decisions are informed and recorded.
What if we have an incident?
Your virtual CISO coordinates the response at leadership level and can bring in our incident response team.
Related services
Often delivered together.
Secure
Governance, risk & compliance
Gap assessments, risk registers, policies and audit readiness against ISO 27001, SOC 2, PCI DSS and NIST CSF, built to be used rather than filed.
Train
Executive cyber briefings
Focused sessions and tabletop exercises that equip boards and leadership teams to govern cyber risk and lead through an incident.
Secure
Incident response
Investigation, containment and recovery when a breach is suspected or confirmed, run to NIST SP 800-61 and documented for regulators and insurers.
Discuss virtual ciso.
A senior engineer reviews every enquiry and replies within one business day.