Fractional CISO support for companies that need real security leadership: strategy, board reporting, incident readiness and governance ownership, before they're ready for a full-time executive.
Companies that have outgrown ad hoc security ownership but cannot yet justify a full time security executive. Usually that means somewhere between thirty and two hundred and fifty people, with enterprise customers asking harder questions, a compliance programme underway, and a CTO who is currently absorbing security leadership alongside a full engineering remit. It also suits companies between permanent hires who need continuity rather than a gap.
A prioritised security roadmap tied to your business goals: funding round, enterprise sales targets, or a specific compliance deadline.
Security updates written for a board or investor audience: risk posture, incident summary, roadmap progress, without the jargon.
Ongoing review of your security policy set, so documentation doesn't quietly go stale or drift out of line with how your controls actually operate.
A named, experienced lead on call if a real incident happens, not a generic hotline.
Regular working sessions with your engineering and leadership teams, sized to your actual risk profile rather than a fixed retainer template.
Support across ISO 27001, SOC 2, GDPR and customer-specific security requirements from one point of accountability.
Project consulting delivers a defined output and ends. A vCISO carries ongoing accountability for a function. The distinction shows up in the unglamorous parts: someone has to decide whether the risk of a particular architecture change is acceptable, answer the security section of an enterprise contract, brief the board before a funding round, and be reachable when something goes wrong at an inconvenient hour.
In practice the role spans strategy, governance, and incident readiness. Strategy means a prioritised roadmap tied to what the business is actually trying to do, whether that is closing enterprise deals, entering a regulated market, or preparing for diligence. Governance means the policy set stays current and someone reviews it against how the organisation genuinely operates. Incident readiness means a plan that has been tested rather than written.
Most vCISO arrangements run on a monthly cadence sized to the organisation's risk profile rather than a fixed retainer applied uniformly. A company preparing for its first SOC 2 while closing large enterprise deals needs more time than one maintaining a stable, already certified environment.
The cadence typically includes a regular working session with engineering, a leadership or board touchpoint at an appropriate interval, and availability between sessions for the questions that do not wait. Where a compliance programme is running in parallel, vCISO work is coordinated with it so the two do not duplicate effort or, worse, contradict each other in front of an auditor.
We are deliberately honest about sizing. Selling more hours than a company needs is easy and short sighted, and an engagement that is too large gets cancelled rather than renewed.
A vCISO who helps shape your control environment cannot also be the independent party who certifies or attests to it. This is the same principle described in our independence statement and it applies here just as clearly.
Practically, this means a vCISO engagement runs alongside certification and examination work performed by others, not instead of it. Where we also perform your ISO 27001 internal audit, we structure the work so the audit remains independent of the areas the vCISO has directly shaped. If that becomes impossible in a given cycle, we will tell you and recommend the audit sits elsewhere that year.
We assess your current state, existing tooling and any live compliance deadlines before proposing a scope of work.
A prioritised, resourced roadmap, what needs fixing before your next funding round or enterprise deal, and what can wait.
Regular touchpoints with engineering, leadership and (where relevant) your board, at a frequency matched to your risk profile.
vCISO work is coordinated with any active ISO 27001, SOC 2 or pentest engagements so nothing is duplicated or contradicted across workstreams.
An incident response plan you've actually rehearsed, with a named lead available if something real happens.
On the opening posture review, you get one round to address what we raised. We re-check those items and reissue the assessment reflecting your corrected position.
Where a vCISO engagement includes a discrete assessment, such as the opening security posture review, the same principle applies. You get one round to address what we raised, we re-check those items, and the final version of the assessment reflects your corrected position. Beyond that, remediation tracking is continuous by nature, since the engagement is ongoing rather than a single deliverable.
The role only pays for itself if it carries real decision making authority. A nominal appointment with no mandate is visible to auditors and customers alike.
A roadmap nobody has time to execute creates a documented list of known unaddressed risks, which is worse than not having written it down.
Security leadership introduced after architecture decisions are made can only object, not shape. Involve them early or accept limited value.
They cannot, for the same independence reasons that apply across everything we do.
Engagements begin with a security posture review over the first two to three weeks, producing a prioritised roadmap. From there the work settles into its ongoing cadence. Meaningful improvement in audit readiness typically becomes visible within a quarter; cultural change, where engineering teams own their controls without prompting, generally takes two to three quarters. Companies expecting a transformed security posture within a month are usually better served by a defined project engagement instead.
We're consultants. We'll get your controls in shape and get you ready for the audit, but we don't hand out ISO 27001 certificates or sign SOC 2 reports, because the rules quite rightly don't let the firm that prepared you be the firm that passes you. That job goes to an independent certification body or CPA firm, and we'll help you find a good one. More on where exactly that line sits in our independence statement.
Those services are scoped, time-boxed programmes toward a specific certification or examination. VCISO is ongoing security leadership (strategy, governance and incident readiness) that often runs alongside or after a certification programme.
It varies by company stage and risk profile. We scope this honestly rather than selling a fixed retainer that doesn't match your actual need.
No. The same independence principle applies here. A vCISO who helped design your controls cannot also be the independent party that certifies or attests to them. See our independence statement.
Yes, this is a common part of the engagement, translating technical risk into language a board or investor audience can act on.
Often, yes, particularly once you're facing enterprise security questionnaires or your first SOC 2/ISO 27001 requirement but aren't ready for a full-time hire.
A consultant delivers a defined project and leaves. A vCISO holds ongoing accountability for the security function, including decisions, board communication and incident leadership between projects.
It varies with company stage and risk profile, which is why we scope it after a posture review rather than quoting a standard package. We would rather size it correctly than sell hours that go unused.
Yes, and this is common. What matters is that the role carries genuine authority, because auditors will ask what decisions the person actually makes.
You get a named, experienced lead rather than a ticket queue. We help you run the response, manage customer and regulatory communication, and complete a post incident review that feeds back into the roadmap.
No. The vCISO provides leadership and governance; certification and examination work still sits with independent bodies. Where the two overlap, we coordinate so effort is not duplicated.
One remediation cycle is included as standard in every engagement. You get one round to apply fixes to what we raised, we re-check those specific findings, and the final report reflects your corrected state rather than the position we found at the start. What sits outside that is our engineers implementing the fixes on your behalf, rather than verifying yours, and any further rounds beyond the first. Both are quoted separately and transparently before any work starts.
Tell us your target date and current state. We'll come back with a fixed-scope proposal within two business days.
Book a discovery call