Security Leadership & Program / FOCUSED SERVICE

vCISO & Fractional Security Leadership

Virtual CISO services provide fractional cybersecurity leadership for risk management, vendor reviews, customer due diligence, and board reporting.

WHAT THIS SERVICE ADDRESSES

The challenge behind the engagement.

This service gives you a virtual Chief Information Security Officer (vCISO) without a full-time hire: one named principal who owns security decisions. Onboarding maps your business, data flows, obligations, insurance application, questionnaires, and prior findings, then sets first-year priorities in an executive readout. We run a steady governance rhythm: a written risk appetite, a clear map of who decides what, a policy set with a review calendar, a supplier risk process, and regular leadership reporting. We maintain the risk register in a consistent, portable format, review vendors, answer customer security questionnaires, and prepare the quarterly board briefing. You receive a monthly report and a decision log. Your executives keep legal authority; the charter states what we may decide, draft, and sign.

WHEN THIS IS THE RIGHT FIT

For organizations whose IT lead carries security on the side, companies between CISOs, and regulated entities whose statutory security officer needs a working deputy. Typical triggers: an enterprise customer sends a security questionnaire nobody owns, an insurance renewal arrives with a control attestation, or a board member asks who owns security.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Onboard and write the charter

The first weeks cover your business and data-flow map, policy and tooling inventory, vendor list, compliance obligations, insurance policy and application, open questionnaires, and prior pentest and audit findings. Onboarding closes with an executive readout, a charter naming what the principal may decide, draft, and sign, and the first-year priorities.

Run the governance cadence

Weekly working sessions early, then biweekly or monthly leadership meetings at a rhythm agreed per engagement. Each month the principal updates the risk register, reviews new vendors and exceptions, and revises policies due on the review calendar. The same month’s work answers customer questionnaires from the maintained answer library and closes with a written report on posture, register movement, and compliance status.

Brief the board and keep the record

Each quarter you receive a board deck with KPIs and KRIs (key performance and key risk indicators) measured against your stated risk appetite. Alongside it come a decision log recording every risk acceptance, exception, and vendor approval with its rationale, and an evidence binder for insurers and customers. Every artifact lives in your systems under a named internal owner.

IS THIS THE RIGHT ENGAGEMENT?

Who it’s for.
When you need it.

BEST SUITED FOR
  • Organizations whose IT lead carries security duties on top of an already full role
  • Companies between permanent security leaders that still owe customers and insurers a clear owner
  • Regulated entities whose named security officer needs a working deputy running daily decisions
  • Growing firms selling into enterprises that demand a documented, accountable security program
WHEN IT’S TIME TO ENGAGE
  • An enterprise prospect sends a lengthy due-diligence questionnaire nobody internally owns
  • A cyber insurance renewal arrives asking for control attestations and evidence
  • A board member or investor asks who is accountable for security
  • The organization signs its first contract carrying real regulatory obligations
AGREED AROUND YOUR ENVIRONMENT

What the scope can include.

  • Onboarding inventory of policies, tooling, vendors, obligations, insurance documents, and open customer questionnaires

  • Governance built out end to end: risk appetite, clear decision ownership, a policy hierarchy, and a leadership oversight loop

  • Monthly risk register maintenance in a consistent, portable format with treatment tracking

  • Vendor risk reviews and approvals through an agreed supplier risk process

  • Customer due-diligence responses drawn from a maintained security questionnaire answer library

  • Insurance application review with control evidence and quarterly board briefing preparation

TRANSPARENT PRICING

What it typically costs.
One rate: $150/hour.

Priced by the hours you need each month at one flat rate. Pick a size to see the usual range, then we confirm the monthly hours in writing.

Small
$1,200–$1,800/mo

Under 50 employees, one location, a few customer or insurer security questions a year

About 8–12 hours a month
Mid-size
$2,400–$3,600/mo

50–250 employees, one compliance framework or steady customer security reviews, quarterly board updates

About 16–24 hours a month
Large
$4,500–$6,000/mo

250–1,000 employees, several regulators or frameworks, multiple locations, active board and vendor program

About 30–40 hours a month
WHAT MOVES THE PRICE
  • How many compliance frameworks, regulators, and insurers you answer to
  • Volume of customer security questionnaires and vendor reviews each month
  • Meeting cadence (weekly vs. monthly) and whether a board briefing is due each quarter
  • How much of the program already exists (policies, risk register, tooling) vs. built from scratch
TYPICAL COMMITMENT

6–12 month engagements, with the first 1–2 months running heavier for onboarding, the charter, and first-year priorities

Get a fixed quote for your scope

Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.

TANGIBLE DELIVERABLES

What you take forward.

  • A charter and decision-ownership map defining what the principal decides, drafts, and signs, and what stays with executives and counsel
  • Twelve-month security strategy and roadmap for the vCISO engagement, with an annual budget request framed by risk
  • Monthly written report, quarterly board deck with KPIs and KRIs, and a decision and action log
  • Policy set with review calendar, vendor risk register, questionnaire answer library, and insurance evidence binder

Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.

SERVICE-SPECIFIC QUESTIONS

Before we get started.

Who actually shows up each month, and what happens when you are unavailable?

The principal who scoped the engagement attends every session, writes every report, and answers every questionnaire. There is no hand-off to junior staff and no rotating bench. Planned absences are scheduled around your reporting cadence and announced in advance, and the charter names an internal deputy on your side who holds decisions until the next session. Because every artifact lives in your repositories under your naming, nothing is locked in our systems if you pause or end the engagement.

Can you present to our board and handle our public-company security disclosure language?

We prepare and present the quarterly board briefing: security posture, how the risk register has moved, metrics against your risk appetite, and the decisions leadership needs to make. For public companies, we draft the governance and process narrative your regulators expect, but your counsel owns the filing, the materiality call, and any required incident disclosure. The principal is not a company officer and is not the management expertise you formally disclose; that designation is your decision with counsel.

REFERENCE POINTS
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security