Skip to content

Advisory

Virtual CISO (vCISO)

Senior security leadership on a retained, part-time basis — for organisations that have outgrown ad-hoc security but cannot yet justify a full-time chief information security officer.

The gap this fills

A regulator, a large customer or a board asks who owns information security. The honest answer is the IT manager, alongside their day job. That arrangement fails on two counts: the IT manager cannot independently challenge the IT function they run, and they rarely have the mandate or the language to engage the board.

A vCISO gives you the seniority and the accountability without the fully loaded cost of a permanent executive hire — typically one to four days a month, with defined deliverables rather than open-ended advice.

What the role covers

  • Own the security strategy and the multi-year roadmap, with a budget position the board can approve.
  • Chair or attend the security steering committee and report to the board or audit committee.
  • Own the information security policy set and drive it through governance.
  • Maintain the risk register and bring treatment and acceptance decisions to the right forum.
  • Lead regulator and customer engagement on security questions, including inspection responses.
  • Oversee incident response readiness and act as the escalation point during a live incident.
  • Manage third-party security assurance and vendor risk.
  • Direct and prioritise the technical security team without replacing it.

Where a vCISO sits

Board / Audit Committee Oversight and challenge Security steering committee Direction, prioritisation, budget vCISO Accountable owner, named and contactable Technical security team Delivery — directed, not replaced
Accountable to the board, directing the technical team rather than replacing it.

A note on independence

If we act as your vCISO, we cannot also provide independent audit assurance over the programme we are running. The two engagements are mutually exclusive for the same client. We will say so at proposal stage rather than after you have signed.

How the engagement runs

  1. 1

    Baseline

    A short assessment of current posture, obligations and the most urgent exposures, so month one is not spent orienting.

  2. 2

    Roadmap

    A prioritised twelve to twenty-four month plan with budget, owners and dependencies mapped.

  3. 3

    Governance setup

    Establish the steering forum, reporting cadence and escalation path.

  4. 4

    Execution oversight

    Drive the roadmap, unblock the team and hold delivery to account.

  5. 5

    Board reporting

    Regular reporting in language the board can act on, with a consistent metric set.

  6. 6

    Review and reset

    Reassess quarterly against changing threat, regulation and business priorities.

What you receive

Security strategy and prioritised roadmap with indicative budget
Board and audit committee reporting pack, issued on an agreed cadence
Maintained information security policy suite
Live risk register with treatment decisions recorded
Incident response plan, escalation matrix and readiness exercises
Named, contactable senior practitioner — not a rotating pool

Frequently asked questions

Most engagements land between one and four days a month, set by the size of the organisation and the intensity of the regulatory calendar. We would rather scope it honestly than sell you a day a month and under-deliver.

Generally yes — regulators care that the accountability exists, is documented, and that the person holding it has the standing to exercise it. What matters is the appointment being formal, the reporting line being to the board or an appropriate committee, and the individual being contactable. We help formalise all three.

That is the intended outcome for most clients. We support the recruitment, hand over the roadmap, risk register and governance artefacts, and taper out over an agreed transition. We have no interest in making the arrangement permanent by making it opaque.

Related services

Related regulatory frameworks

Need an independent view?

Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.

Request a proposal
Top