Services · Add-on

vCISO

Provides a named cybersecurity officer for board reporting, strategy, budget ownership, risk acceptance, executive escalation, and customer and investor diligence.

Replaces
in-house CISO
Where it sits
Add-on to any tier

Scope

What we own.

Every line is work an engineer carries, reports on monthly, and hands over documented if the retainer ends.
  • Named as the client's cybersecurity officer to their board, customers and investors
  • Quarterly board presentation and Q&A
  • Multi-year cybersecurity strategy and roadmap
  • Cybersecurity budget ownership and justification
  • Formal risk acceptance and sign-off on their behalf
  • Executive-level incident communication and crisis handling
  • Customer cybersecurity reviews and enterprise diligence, attended as their CISO
  • Cyber insurance scoping and renewal negotiation
  • Cybersecurity org design and hiring plan for their eventual internal team
  • Regulator and auditor facing as the accountable person

Boundaries

What this does not cover.

Stated up front so the scope in your proposal matches what actually gets done.
  • The buyer is the CEO or the board, not the CTO.
  • Cybersecurity Program runs the work and reports monthly. The vCISO is named to the board and to customers, owns strategy and budget, and accepts risk. See Cybersecurity Program.

Talk through vCISO.

Bring the systems, the role this has to cover, and the deadline. We come back inside 48 hours with a written scope.