The challenge behind the engagement.
This service gives you a virtual Chief Information Security Officer (vCISO) without a full-time hire: one named principal who owns security decisions. Onboarding maps your business, data flows, obligations, insurance application, questionnaires, and prior findings, then sets first-year priorities in an executive readout. We run a steady governance rhythm: a written risk appetite, a clear map of who decides what, a policy set with a review calendar, a supplier risk process, and regular leadership reporting. We maintain the risk register in a consistent, portable format, review vendors, answer customer security questionnaires, and prepare the quarterly board briefing. You receive a monthly report and a decision log. Your executives keep legal authority; the charter states what we may decide, draft, and sign.
For organizations whose IT lead carries security on the side, companies between CISOs, and regulated entities whose statutory security officer needs a working deputy. Typical triggers: an enterprise customer sends a security questionnaire nobody owns, an insurance renewal arrives with a control attestation, or a board member asks who owns security.
What we do.
What you can use.
Onboard and write the charter
The first weeks cover your business and data-flow map, policy and tooling inventory, vendor list, compliance obligations, insurance policy and application, open questionnaires, and prior pentest and audit findings. Onboarding closes with an executive readout, a charter naming what the principal may decide, draft, and sign, and the first-year priorities.
Run the governance cadence
Weekly working sessions early, then biweekly or monthly leadership meetings at a rhythm agreed per engagement. Each month the principal updates the risk register, reviews new vendors and exceptions, and revises policies due on the review calendar. The same month’s work answers customer questionnaires from the maintained answer library and closes with a written report on posture, register movement, and compliance status.
Brief the board and keep the record
Each quarter you receive a board deck with KPIs and KRIs (key performance and key risk indicators) measured against your stated risk appetite. Alongside it come a decision log recording every risk acceptance, exception, and vendor approval with its rationale, and an evidence binder for insurers and customers. Every artifact lives in your systems under a named internal owner.
Who it’s for.
When you need it.
- Organizations whose IT lead carries security duties on top of an already full role
- Companies between permanent security leaders that still owe customers and insurers a clear owner
- Regulated entities whose named security officer needs a working deputy running daily decisions
- Growing firms selling into enterprises that demand a documented, accountable security program
- An enterprise prospect sends a lengthy due-diligence questionnaire nobody internally owns
- A cyber insurance renewal arrives asking for control attestations and evidence
- A board member or investor asks who is accountable for security
- The organization signs its first contract carrying real regulatory obligations
What the scope can include.
- 01
Onboarding inventory of policies, tooling, vendors, obligations, insurance documents, and open customer questionnaires
- 02
Governance built out end to end: risk appetite, clear decision ownership, a policy hierarchy, and a leadership oversight loop
- 03
Monthly risk register maintenance in a consistent, portable format with treatment tracking
- 04
Vendor risk reviews and approvals through an agreed supplier risk process
- 05
Customer due-diligence responses drawn from a maintained security questionnaire answer library
- 06
Insurance application review with control evidence and quarterly board briefing preparation
What it typically costs.
One rate: $150/hour.
Priced by the hours you need each month at one flat rate. Pick a size to see the usual range, then we confirm the monthly hours in writing.
Under 50 employees, one location, a few customer or insurer security questions a year
About 8–12 hours a month50–250 employees, one compliance framework or steady customer security reviews, quarterly board updates
About 16–24 hours a month250–1,000 employees, several regulators or frameworks, multiple locations, active board and vendor program
About 30–40 hours a month- How many compliance frameworks, regulators, and insurers you answer to
- Volume of customer security questionnaires and vendor reviews each month
- Meeting cadence (weekly vs. monthly) and whether a board briefing is due each quarter
- How much of the program already exists (policies, risk register, tooling) vs. built from scratch
6–12 month engagements, with the first 1–2 months running heavier for onboarding, the charter, and first-year priorities
Get a fixed quote for your scopeRanges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- A charter and decision-ownership map defining what the principal decides, drafts, and signs, and what stays with executives and counsel
- Twelve-month security strategy and roadmap for the vCISO engagement, with an annual budget request framed by risk
- Monthly written report, quarterly board deck with KPIs and KRIs, and a decision and action log
- Policy set with review calendar, vendor risk register, questionnaire answer library, and insurance evidence binder
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
Who actually shows up each month, and what happens when you are unavailable?
The principal who scoped the engagement attends every session, writes every report, and answers every questionnaire. There is no hand-off to junior staff and no rotating bench. Planned absences are scheduled around your reporting cadence and announced in advance, and the charter names an internal deputy on your side who holds decisions until the next session. Because every artifact lives in your repositories under your naming, nothing is locked in our systems if you pause or end the engagement.
Can you present to our board and handle our public-company security disclosure language?
We prepare and present the quarterly board briefing: security posture, how the risk register has moved, metrics against your risk appetite, and the decisions leadership needs to make. For public companies, we draft the governance and process narrative your regulators expect, but your counsel owns the filing, the materiality call, and any required incident disclosure. The principal is not a company officer and is not the management expertise you formally disclose; that designation is your decision with counsel.
- NIST CSWP 29: The NIST Cybersecurity Framework (CSF) 2.0
- NIST Cybersecurity Framework 2.0: Quick-Start Guide for Creating and Using Organizational Profiles
- NIST SP 800-30 Rev. 1: Guide for Conducting Risk Assessments
- NIST IR 8286 Rev. 1: Integrating Cybersecurity and Enterprise Risk Management (ERM)
- CIS Critical Security Controls Version 8.1
- ISO/IEC 27005:2022 - Guidance on managing information security risks
- Cross-Sector Cybersecurity Performance Goals
