Home / Services / Virtual CISO (vCISO)
vCISO

Security leadership, without a full-time executive hire.

Fractional CISO support for companies that need real security leadership: strategy, board reporting, incident readiness and governance ownership, before they're ready for a full-time executive.

Fractional LeadershipStrategy to board reporting
Framework-agnostic
UK · US · EU-based
Who it's for

Who this is for

Companies that have outgrown ad hoc security ownership but cannot yet justify a full time security executive. Usually that means somewhere between thirty and two hundred and fifty people, with enterprise customers asking harder questions, a compliance programme underway, and a CTO who is currently absorbing security leadership alongside a full engineering remit. It also suits companies between permanent hires who need continuity rather than a gap.

What's included

Scope, in plain terms.

VC-01 Scope

Security Strategy & Roadmap

A prioritised security roadmap tied to your business goals: funding round, enterprise sales targets, or a specific compliance deadline.

VC-02 Scope

Board & Investor Reporting

Security updates written for a board or investor audience: risk posture, incident summary, roadmap progress, without the jargon.

VC-03 Scope

Policy & Governance Review

Ongoing review of your security policy set, so documentation doesn't quietly go stale or drift out of line with how your controls actually operate.

VC-04 Scope

Incident Response Leadership

A named, experienced lead on call if a real incident happens, not a generic hotline.

VC-05 Deliverable

Monthly Cadence

Regular working sessions with your engineering and leadership teams, sized to your actual risk profile rather than a fixed retainer template.

VC-06 Fit

Framework-Agnostic

Support across ISO 27001, SOC 2, GDPR and customer-specific security requirements from one point of accountability.

What a vCISO does that a consultant does not

Project consulting delivers a defined output and ends. A vCISO carries ongoing accountability for a function. The distinction shows up in the unglamorous parts: someone has to decide whether the risk of a particular architecture change is acceptable, answer the security section of an enterprise contract, brief the board before a funding round, and be reachable when something goes wrong at an inconvenient hour.

In practice the role spans strategy, governance, and incident readiness. Strategy means a prioritised roadmap tied to what the business is actually trying to do, whether that is closing enterprise deals, entering a regulated market, or preparing for diligence. Governance means the policy set stays current and someone reviews it against how the organisation genuinely operates. Incident readiness means a plan that has been tested rather than written.

How the engagement is usually structured

Most vCISO arrangements run on a monthly cadence sized to the organisation's risk profile rather than a fixed retainer applied uniformly. A company preparing for its first SOC 2 while closing large enterprise deals needs more time than one maintaining a stable, already certified environment.

The cadence typically includes a regular working session with engineering, a leadership or board touchpoint at an appropriate interval, and availability between sessions for the questions that do not wait. Where a compliance programme is running in parallel, vCISO work is coordinated with it so the two do not duplicate effort or, worse, contradict each other in front of an auditor.

We are deliberately honest about sizing. Selling more hours than a company needs is easy and short sighted, and an engagement that is too large gets cancelled rather than renewed.

The independence boundary in a vCISO engagement

A vCISO who helps shape your control environment cannot also be the independent party who certifies or attests to it. This is the same principle described in our independence statement and it applies here just as clearly.

Practically, this means a vCISO engagement runs alongside certification and examination work performed by others, not instead of it. Where we also perform your ISO 27001 internal audit, we structure the work so the audit remains independent of the areas the vCISO has directly shaped. If that becomes impossible in a given cycle, we will tell you and recommend the audit sits elsewhere that year.

Engagement process

How the work actually happens.

01

Security posture review

We assess your current state, existing tooling and any live compliance deadlines before proposing a scope of work.

02

Roadmap & priorities

A prioritised, resourced roadmap, what needs fixing before your next funding round or enterprise deal, and what can wait.

03

Embedded cadence

Regular touchpoints with engineering, leadership and (where relevant) your board, at a frequency matched to your risk profile.

04

Framework alignment

vCISO work is coordinated with any active ISO 27001, SOC 2 or pentest engagements so nothing is duplicated or contradicted across workstreams.

05

Incident readiness

An incident response plan you've actually rehearsed, with a named lead available if something real happens.

06

Remediation round and re-check

On the opening posture review, you get one round to address what we raised. We re-check those items and reissue the assessment reflecting your corrected position.

Included as standard

One remediation cycle is built into every engagement

Where a vCISO engagement includes a discrete assessment, such as the opening security posture review, the same principle applies. You get one round to address what we raised, we re-check those items, and the final version of the assessment reflects your corrected position. Beyond that, remediation tracking is continuous by nature, since the engagement is ongoing rather than a single deliverable.

What goes wrong

Common mistakes we are asked to fix.

Hiring a vCISO to tick a customer questionnaire box

The role only pays for itself if it carries real decision making authority. A nominal appointment with no mandate is visible to auditors and customers alike.

Buying strategy with no delivery capacity

A roadmap nobody has time to execute creates a documented list of known unaddressed risks, which is worse than not having written it down.

Leaving the vCISO outside engineering decisions

Security leadership introduced after architecture decisions are made can only object, not shape. Involve them early or accept limited value.

Assuming the vCISO can sign your audit

They cannot, for the same independence reasons that apply across everything we do.

Timelines

Timing and what to expect

Engagements begin with a security posture review over the first two to three weeks, producing a prioritised roadmap. From there the work settles into its ongoing cadence. Meaningful improvement in audit readiness typically becomes visible within a quarter; cultural change, where engineering teams own their controls without prompting, generally takes two to three quarters. Companies expecting a transformed security posture within a month are usually better served by a defined project engagement instead.

One thing worth being clear about

We're consultants. We'll get your controls in shape and get you ready for the audit, but we don't hand out ISO 27001 certificates or sign SOC 2 reports, because the rules quite rightly don't let the firm that prepared you be the firm that passes you. That job goes to an independent certification body or CPA firm, and we'll help you find a good one. More on where exactly that line sits in our independence statement.

Common questions

Frequently asked questions

How is this different from your ISO 27001 or SOC 2 preparation services?

Those services are scoped, time-boxed programmes toward a specific certification or examination. VCISO is ongoing security leadership (strategy, governance and incident readiness) that often runs alongside or after a certification programme.

How many hours a month is typical?

It varies by company stage and risk profile. We scope this honestly rather than selling a fixed retainer that doesn't match your actual need.

Can a vCISO sign our SOC 2 report or ISO 27001 certificate?

No. The same independence principle applies here. A vCISO who helped design your controls cannot also be the independent party that certifies or attests to them. See our independence statement.

Do you work directly with our board or investors?

Yes, this is a common part of the engagement, translating technical risk into language a board or investor audience can act on.

Is this a good fit for an early-stage startup?

Often, yes, particularly once you're facing enterprise security questionnaires or your first SOC 2/ISO 27001 requirement but aren't ready for a full-time hire.

How is a vCISO different from a security consultant?

A consultant delivers a defined project and leaves. A vCISO holds ongoing accountability for the security function, including decisions, board communication and incident leadership between projects.

How many days a month is typical?

It varies with company stage and risk profile, which is why we scope it after a posture review rather than quoting a standard package. We would rather size it correctly than sell hours that go unused.

Can a vCISO be named to customers and auditors?

Yes, and this is common. What matters is that the role carries genuine authority, because auditors will ask what decisions the person actually makes.

What happens if we have a security incident?

You get a named, experienced lead rather than a ticket queue. We help you run the response, manage customer and regulatory communication, and complete a post incident review that feeds back into the roadmap.

Does a vCISO replace our need for compliance work?

No. The vCISO provides leadership and governance; certification and examination work still sits with independent bodies. Where the two overlap, we coordinate so effort is not duplicated.

Is remediation included, or is that charged separately?

One remediation cycle is included as standard in every engagement. You get one round to apply fixes to what we raised, we re-check those specific findings, and the final report reflects your corrected state rather than the position we found at the start. What sits outside that is our engineers implementing the fixes on your behalf, rather than verifying yours, and any further rounds beyond the first. Both are quoted separately and transparently before any work starts.

Related services

Often scoped alongside this.

Ready to scope this?

Tell us your target date and current state. We'll come back with a fixed-scope proposal within two business days.

Book a discovery call