vCISO

You already have a CISO’s workload. You just don’t have the CISO.

The questionnaire from a prime. The risk nobody wants to accept in writing. The insurer’s renewal form. The board asking whether you’re covered. Those questions arrive whether or not anyone’s job is to answer them — and right now they land on you, or on whoever runs IT.

A named practitioner who knows your environment, your contracts, and your customers — on a monthly retainer, with the managed security stack included per seat.

The problem

The decisions don’t wait for you to hire someone.

A full-time CISO is a quarter-million-dollar commitment, and at your size there isn’t enough work to justify one — but there’s far too much to leave unowned. So it gets absorbed by people who already have jobs, in the gaps between their real ones.

It lands on IT, or on you

Your IT lead is good at keeping things running. That’s a different skill from deciding what risk the business will accept — and it isn’t fair to either of you.

Nobody owns the answer

A prime sends a 200-line questionnaire. Whoever has time fills it in, nobody checks whether it’s true, and it becomes a commitment you didn’t know you made.

Risk gets accepted by default

Decisions made by not deciding are still decisions — they just have no rationale behind them when someone asks why, and no record that anyone weighed the tradeoff.

What’s missing isn’t hours. It’s a named person with the authority and the judgment to decide — and to stand behind the decision when a prime, an auditor, or an insurer asks how you got there.

What they own

The desk everything lands on.

Not advice you then have to act on. Ownership — the decisions get made, written down, and defended, and you find out about them in a monthly report instead of in an audit.

Direction and risk

Where you’re going, what you’ll accept, and what you’ll spend to close the gap.

Security strategy and roadmap Risk register Risk acceptance with rationale Budget prioritization

Program and documentation

The written record that makes your posture defensible when someone comes to check.

Policy ownership Control and scope decisions Third-party and vendor risk Incident command

Speaking for you

Being the person in the room when someone external needs an answer they can rely on.

Prime questionnaires Customer security reviews Insurance renewals Board reporting

One line we don’t cross. Your senior official signs your affirmation — that responsibility sits with your company and can’t be outsourced to us or anyone else. What we do is make sure that when they sign, the evidence behind it actually holds, and that they understand exactly what they’re attesting to.

How it works

A person, on a retainer, who actually shows up.

Tiered monthly, sized to how much of this you need. The managed security stack is included per seat, so you’re not buying leadership and tooling as two separate arguments.

A named practitioner, not a queue

The same person every month, who learns your contracts and your environment. You have their calendar and their number — escalation isn’t a form you fill in.

A running cadence

Regular working sessions plus a monthly report. Reviews, risk assessments, training, and affirmations sit on a calendar someone else is watching — so nothing arrives as a surprise.

The security stack, per seat

EDR, monitoring, awareness training, and vulnerability management come with the retainer. Leadership without tooling is just opinions, and tooling without leadership is shelfware.

Decisions in writing

Every risk accepted, every scope call, every exception — recorded with the reasoning at the time. That record is what turns a judgment call into a defensible one two years later.

Someone who answers externally

Questionnaires, customer security reviews, insurer renewals, and assessor walkthroughs handled by the person who actually knows the answers — not routed back to you.

Reporting your board can read

Where you stand, what changed, what it cost, and what’s next — in language a non-technical owner or board can act on without a translator.

Is this you?

Right for some companies. Wrong for others.

A vCISO fits when the decisions have outgrown the person currently making them — typically somewhere between 10 and 200 people, with contracts that carry real security obligations and no one whose actual job this is.

  • A prime is pushing requirements you can’t confidently answer
  • Security questions are landing on your IT lead, or on you
  • You need decisions defended, not just tasks completed
  • An assessment, renewal, or affirmation is coming

When it isn’t the right call. If you already have a security leader, you don’t need us in that seat — you may just want the practices underneath. And if what you actually need is one specific thing done, a scoped engagement will cost you less than a retainer. We’ll say so.

Start here

See what having one would change.

Start with a scoping session. Bring the questions currently sitting unanswered — the questionnaire, the renewal, the risk nobody wants to sign off — and we’ll show you how they’d get handled. Including whether a retainer is more than you need. No obligation.

Veteran-founded · Cyber AB RPA-led · Government contractors only