Englishالعربية Soon
Under attack?
vCISO · DPO · ISO as a service

Most organisations need the decisions a CISO makes, not a CISO’s salary.

A senior security leader assigned to your organisation on a defined commitment: owning the strategy, the risk register, the policy set, the regulator relationship and the board conversation, with a team behind them rather than one person’s experience.

Three roles, same principle
vCISO
Security leadership and accountability
DPO
The statutory data protection role
ISO as a service
The management system owned and maintained

The arrangement is a named individual, not a rotating pool. You get the same person in your governance forums and in front of your board, with the wider team available behind them when a specialism is needed.

The role

Nine responsibilities the role actually carries

Which of these are in scope is agreed at the start and written down. A vCISO arrangement without a defined mandate becomes expensive advice nobody has to act on.

01

Strategy and roadmap

A security strategy tied to business objectives and a multi-year roadmap that survives a budget cycle, rather than a list of products.

02

Risk ownership

The risk register maintained, rated and reported. Risk acceptance decisions put to the people with the authority to make them.

03

Policy and governance

The policy set written, approved, communicated and reviewed. Governance forums that actually meet and produce decisions.

04

Regulatory engagement

Requirements interpreted for your licence, evidence maintained continuously, and someone credible in the room when the regulator visits.

05

Board reporting

A quarterly account of posture, incidents, exposure and progress in language a board can act on, not a dashboard screenshot.

06

Programme oversight

Security projects scoped, sequenced and held to their outcomes, including work delivered by third parties.

07

Incident command

A defined role in a live incident: declaring it, directing response, deciding disclosure and owning the post-incident review.

08

Vendor and third-party risk

Supplier due diligence, contractual security terms and ongoing assurance, before procurement signs rather than after.

09

Team development

Your existing engineers mentored and their capability grown, so dependence on the arrangement decreases over time.

When it fits

Six situations where this is the right answer

And one where it is not: if you have the budget, the volume of work and a candidate, hire someone. We will say so.

You have engineers but no strategy

Capable technical staff making architecture and tooling decisions without anyone accountable for the direction they add up to.

A contract or regulator demands a named CISO

Enterprise customers, insurers and supervisors increasingly require a named, qualified individual in the role.

Your last CISO left

The gap between departure and a replacement starting is typically six to nine months, and the risk does not pause.

The role is too big for one person you cannot afford

A full-time hire at the right seniority costs more than the security programme you are trying to fund.

You are preparing for certification or an audit

Certification programmes fail on ownership more often than on controls.

After an incident

Boards that have just been through one want accountability in place before they want tooling.

Engagement models

Four ways to hold the role

Fractional
A defined number of days per month, on an ongoing retainer. The most common arrangement, and the one that suits organisations with a permanent need but not a permanent role.
Interim
Full engagement while you recruit, including running the recruitment brief and handing over to whoever you hire.
Project-based
Scoped to a specific outcome: a certification, a regulatory response, a post-incident programme, and concluded when it is delivered.
Advisory to an internal lead
Your own security manager holds the role, with senior backing behind them for the decisions and the board conversations they have not had before.
First 90 days

What happens before anything is recommended

A vCISO who arrives with a plan on day one has brought somebody else’s.

Weeks 1 to 3

Understand

Business model, regulatory obligations, architecture, existing controls, team capability and what leadership actually worries about.

Weeks 4 to 6

Assess

Current posture measured rather than estimated: risk register built or rebuilt, control gaps identified, and the exposure quantified in terms a board recognises.

Weeks 7 to 10

Plan

A strategy and roadmap sequenced by risk reduction per unit of cost, with the first quarter deliberately achievable.

Weeks 11 to 13

Establish

Governance forums running, reporting cadence set, ownership assigned, and the first board report delivered.

Related role

Data protection officer

Where the law requires a designated DPO, the role can be held under the same arrangement: monitoring compliance, advising on impact assessments, acting as contact point for the regulator and for data subjects, and reporting independently to your board.

Personal data protection →

Related role

ISO as a service

The management system owned and maintained on your behalf: the internal audit cycle run, evidence kept current, surveillance audits attended, and the certificate held rather than rescued each year.

ISO 27001 →

Related

What the role typically commissions first

Risk assessment

The register is the instrument the role governs with. Without it there is nothing to prioritise against.

Internal audit & readiness

An independent view of whether the controls the organisation believes it has actually operate.

Managed SOC

Leadership without detection is advice. Most vCISO roadmaps put monitoring in the first two quarters.

Meet the person, not the proposal.

Tell us the mandate you need covered and we will introduce the individual who would hold it, before anything is agreed.