For boards · CEOs · CIOs · GCs

Cyber risk, translated into business language

We help leadership teams understand where their real cyber exposure sits, what's worth doing about it, and how to land a credible, budgeted roadmap that satisfies auditors, customers and the board.

01

Boardroom-ready reporting

Risk presented in business terms — likelihood, impact, dollar exposure — not vendor jargon or RAG status theatre.

02

Independent & vendor-agnostic

No product affiliations, no referral fees. You hear the recommendation a CISO would give if they worked for you.

03

Operator credibility

Three decades of in-the-trenches CISO work. Your team gets a peer who has built and broken what you're now building.

The vCISO offering

A senior security partner who sits inside your business

Part-time, fractional, or interim CISO leadership — sized to where your business is today.

01

Seasoned professional

Strategic guidance and leadership on a part-time or fractional basis. Same person across the engagement, not a rotating bench.

02

Advisory arm to your team

Your existing IT and security people leverage cross-industry insight — peer-level coaching, not policing.

03

Tailored security strategy

Risk assessments and a security strategy built for your business, data and growth horizon. Not a copy-paste template.

04

360° view

Industry best practices applied across governance, technology and process — under one accountable program owner.

05

Cost-effective

Top-tier expertise without the loaded cost of a full-time CISO — and a clean exit when you outgrow fractional.

06

Proactive posture

Stay ahead of threat and compliance changes before they become board escalations.

Our approach cycle

Six phases. One accountable program.

Engagements run on a continuous loop — review, quantify, plan, execute, monitor, and hand over.

  1. 01

    360° Review

    Governance, identity, infra & SDLC

  2. 02

    Risk Quantification

    Board-ready NIST · CIS · ISO scores

  3. 03

    Roadmap Planning

    Priorities set by risk appetite

  4. 04

    Solutioning

    Controls deployed & integrated

  5. 05

    Risk Monitoring

    KPIs & KRIs, continuously

  6. 06

    Handover

    With optional ongoing advisory

Scope of work

Twelve responsibilities. One accountable owner.

Everything on your vCISO's clock — from first review to ongoing advisory.

01 360° Review Governance, identity, infrastructure, inventory, SDLC.
02 Gap Assessment Identify gaps in processes and controls. Recommend best practices.
03 Risk Quantification Identify, measure, monitor and report risks against the standard.
04 Security Strategy Customised security and data strategy aligned to business, regulatory and legal needs.
05 Training & Awareness Board, admin and user training. Programs that actually change behaviour.
06 Policy & Insurance Policy frameworks, regulatory readiness, cyber insurance engagement.
07 Budgeting Solution roadmap, vendor selection, and budget envelope per phase.
08 Implementation Deploy and integrate the chosen solutions per priority and timeline.
09 KPI / KRA Design SMART goals — Specific, Measurable, Aligned, Relevant, Time-bound.
10 Controls Monitoring Monitor-mode refinement, automation, noise reduction for actionable alerts.
11 Risk Advisory Governance KRA/KPI monitoring and technical control monitoring.
12 GRC & Audit Regulatory management, continuous control monitoring, audit support.
Timelines

What a program looks like, week by week

Actual timeline depends on your support and resource allocation. Most engagements follow this rhythm.

Phase 1 · 4–12 weeks

Discover & quantify

360° review. Gap assessment. Risk identification and quantification. Security and data strategy.

Phase 2 · 4–28 weeks

Plan & deploy

Budgeting. Solutioning. Policy authoring. Deployment and integration of controls.

Phase 3 · 8–24 weeks

Certify & train

Certification readiness. Cyber insurance engagement. Awareness training. KPI / KRI building.

Phase 4 · Ongoing

Monitor & advise

Risk monitoring. KPI / KRI advisory. Handover to internal team or continued advisory.

FAQ

Common questions from boards & CEOs

How many hours per week does a vCISO commit?

Typically 2 days a week during Phases 1–2 when the program is being designed, scaling down to 1 day a week in Phases 3–4. We size the engagement to your maturity and pace.

Do you replace our internal IT or security team?

No. Our role is advisory and program leadership. We make your existing team more effective, surface the right decisions to the board, and step in as the accountable security leader.

Which frameworks do you score against?

Primarily NIST CSF, CIS Controls, ISO 27001:2022 and C2M2. We also map to PCI-DSS, RBI guidelines, CERT-In directives and ITGC as your regulatory profile demands.

Can you help with cyber insurance?

Yes. We engage directly with your insurance providers and brokers, clarify their questionnaires, and help secure the best possible coverage.

What happens at handover?

Phase 4 is designed to be either a clean handover to your internal team — with documentation, KPIs and run-books — or a continuing risk-monitoring and advisory relationship. Your choice.

How is the engagement priced?

Commercials are tailored to scope, pace and geography. We use a reducing-cost model that's heaviest at program setup and tapers as your team takes ownership. Let's discuss what fits.

Talk to a CISO this week

30 minutes with one of our founders to see whether a fractional CISO is the right shape for your business.