Operate

    vCISO

    Senior security leadership on retainer, holding named accountabilities rather than producing advice. Board reporting, risk acceptance, supplier assurance, regulatory interface and incident command — the decisions a CISO makes, without the salary of one.

    Duration

    Minimum six months, typically ongoing

    Built on

    ISO/IEC 27001:2022 · NIS2 · ISO/IEC 27005

    Indicative price

    from €2,500 per month

    Who this is for

    • Managing director or owner

      Needs a CISO's decisions and cannot justify a CISO's salary.

    • CIO

      Is carrying security accountability alongside a full IT remit.

    • Board

      Has become personally accountable under NIS2 and needs someone who can brief them honestly.

    • Growing organisation

      Is between 'the IT manager handles it' and a permanent hire.

    Most organisations need a CISO's decisions, not a CISO's salary

    The work a CISO actually does is less technical than the title suggests. It is deciding which risks the organisation will carry and which it will spend money on. It is standing in front of a board and saying something uncomfortable in language they can act on. It is signing supplier assurance responses that will be held against you. It is taking command when something is on fire. Almost none of it is tooling.

    That work does not scale down neatly. A mid-sized organisation has the same decisions to make as a large one — fewer of them, but the same kind — and no obvious way to buy a fraction of the person who makes them.

    The common failure of fractional security leadership is that it becomes advisory. Someone attends a monthly call, produces a deck, and holds no accountability for anything. That arrangement is comfortable for both sides and changes nothing, because advice without accountability is free to ignore.

    So we do it the other way. The engagement starts with a written mandate: which decisions are ours to make, which we recommend and you decide, and which are always yours. The named accountabilities are explicit. If our vCISO accepts a risk on your behalf, that is recorded with their name against it.

    Six months is the minimum because nothing meaningful lands in less. The first month is understanding the estate and the politics, the second produces a plan, and the value compounds from there.

    How we do it

    1. 01

      Intake and mandate

      2 weeks

      What the organisation needs from the role, what authority comes with it, and what is explicitly out of scope. Written and signed. This conversation prevents most of the ways the arrangement can go wrong.

    2. 02

      Current state

      3–4 weeks

      The estate, the risk position, the obligations, the supplier exposure and the people. Fast, because the point is a plan rather than a report.

    3. 03

      Ninety-day plan

      1 week

      What we will do first, what we will stop doing, and what we need from you. Presented to the board so that the priorities are theirs as well as ours.

    4. 04

      Operating rhythm

      ongoing

      A defined cadence — weekly with IT, monthly with the executive, quarterly with the board — so that security decisions happen on a schedule rather than after an incident.

    5. 05

      Represent

      ongoing

      Board reporting, client and insurer questionnaires, regulator interface, audit sponsorship, and incident command when it is needed.

    6. 06

      Build your successor

      ongoing

      Where the intention is an eventual permanent hire, we define the role, help you recruit it, and hand over deliberately. We would rather end well than be indispensable.

    Named artefacts

    What you receive

    • Written mandate and decision remit, signed
    • Ninety-day security plan, board-approved
    • Risk register with named ownership, and risk acceptances recorded against a person
    • Board reporting pack, produced to a fixed cadence
    • Supplier and client assurance responses
    • Incident command role, with the escalation path defined in advance
    • Annual security plan and budget submission
    • Role definition and handover pack, where a permanent hire is the goal

    What we need from you

    • Real authority within the agreed remit. A vCISO who must seek permission for every decision is a consultant with a different title.
    • Access to the board or executive, not only to IT.
    • Honesty about the politics. Most security problems in a mid-sized organisation are organisational, and we work faster if we are told where the resistance is.
    • A minimum of six months, because the first two are largely orientation.

    What changes

    1. 01Security decisions are made on a cadence, by a named person, and recorded.
    2. 02The board receives an honest picture in language they can act on.
    3. 03Risk acceptances have a name against them rather than being implicit.
    4. 04Client and insurer questionnaires stop being an emergency each time.
    5. 05When you hire permanently, the role is defined and the handover is planned.

    What it costs

    from €2,500 per month

    All prices exclude VAT.

    Questions

    How much time do we actually get?

    The retainer buys a defined number of days a month plus the operating rhythm, and we agree the split at intake. Incident command sits outside the standard allocation and is invoked when needed — we will not leave you unattended during an incident because the month's days are used up.

    Can a vCISO be accountable in the way NIS2 expects?

    NIS2 places accountability on the management body, and that cannot be outsourced to us or to anyone. What we do is make sure the management body is equipped to carry it — the briefings, the evidence, the knowledge requirement — and we hold the operational accountabilities beneath it.

    What happens when we hire a permanent CISO?

    We help define the role, we often help assess candidates, and we hand over with the documentation intact. A number of our engagements end this way and that is a successful outcome, not a lost account.

    Is this the same person every month?

    Yes. A named individual with a named deputy. Rotating the role defeats the purpose, because most of the value is in knowing your organisation.

    Leave with your top three risks documented

    Thirty minutes with a senior practitioner. No slideware, no sales engineer.