Advisory
Virtual CISO (vCISO)
Senior security leadership on a retained, part-time basis — for organisations that have outgrown ad-hoc security but cannot yet justify a full-time chief information security officer.
The gap this fills
A regulator, a large customer or a board asks who owns information security. The honest answer is the IT manager, alongside their day job. That arrangement fails on two counts: the IT manager cannot independently challenge the IT function they run, and they rarely have the mandate or the language to engage the board.
A vCISO gives you the seniority and the accountability without the fully loaded cost of a permanent executive hire — typically one to four days a month, with defined deliverables rather than open-ended advice.
What the role covers
- Own the security strategy and the multi-year roadmap, with a budget position the board can approve.
- Chair or attend the security steering committee and report to the board or audit committee.
- Own the information security policy set and drive it through governance.
- Maintain the risk register and bring treatment and acceptance decisions to the right forum.
- Lead regulator and customer engagement on security questions, including inspection responses.
- Oversee incident response readiness and act as the escalation point during a live incident.
- Manage third-party security assurance and vendor risk.
- Direct and prioritise the technical security team without replacing it.
Where a vCISO sits
A note on independence
If we act as your vCISO, we cannot also provide independent audit assurance over the programme we are running. The two engagements are mutually exclusive for the same client. We will say so at proposal stage rather than after you have signed.
How the engagement runs
-
1
Baseline
A short assessment of current posture, obligations and the most urgent exposures, so month one is not spent orienting.
-
2
Roadmap
A prioritised twelve to twenty-four month plan with budget, owners and dependencies mapped.
-
3
Governance setup
Establish the steering forum, reporting cadence and escalation path.
-
4
Execution oversight
Drive the roadmap, unblock the team and hold delivery to account.
-
5
Board reporting
Regular reporting in language the board can act on, with a consistent metric set.
-
6
Review and reset
Reassess quarterly against changing threat, regulation and business priorities.
What you receive
Frequently asked questions
Related services
Related regulatory frameworks
Need an independent view?
Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.
Request a proposal