Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Service

vCISO services: security leadership without a full-time hire

A security leader from our team works with you on a recurring basis to set the roadmap, run governance, keep policies current, and report progress to leadership in plain terms.

What we deliver

Virtual CISO advisory: roadmap, governance, policy, metrics, and executive reporting.

References
NIST CSF 2.0CIS Controls v8.1

Who it's for

A good fit for

  • Organizations with growing security obligations and no dedicated security executive
  • IT or engineering leaders who have been handed security and want a senior partner
  • Companies whose customers, insurers, or investors expect evidence of security governance
  • Teams between security leaders that need continuity while they hire

Not the right fit for

  • Organizations that need a full-time, on-site executive or a named corporate officer
  • Teams looking for someone to run day-to-day security operations, monitoring, or help-desk tasks
  • Organizations that mainly need hands-on engineering capacity rather than direction and oversight

Problems it addresses

  • Security work happens, but no one owns the priorities or the order in which things get done.
  • Leadership and the board receive technical updates they can't act on.
  • Policies were written for a past audit and no longer match how the company works.
  • Customer security reviews stall because no one can speak for the program.
  • Tool purchases follow vendor pitches rather than a plan.

Scope

Included

  • A security roadmap tied to business goals, with owners and sequencing
  • Governance: a regular security steering meeting, a decision log, and a risk-acceptance process
  • Policy development and annual review, written to match how your teams actually work
  • Program metrics that show progress and remaining risk, not just activity
  • Executive and board reporting in plain language
  • Support for customer security reviews and questionnaires
  • Input on security tool and service-provider decisions, measured against your roadmap

Not included

  • Day-to-day security operations, monitoring, or alert triage
  • Hands-on administration of your systems or security tools
  • Penetration testing, which is scoped as a separate engagement

Ways to engage

vCISO Advisory

Ongoing guidance for teams that have people doing the work and need experienced direction: setting priorities, reviewing policies and plans, weighing in on decisions, and reporting to leadership.

Price
vCISO Advisory: from $4,000/month; typical $4,000–$6,000/month

vCISO Program Leadership

Deeper involvement for organizations that need someone to lead the program: chairing governance, driving roadmap work across teams, maintaining the policy set, and representing the program in customer and leadership conversations.

Price
vCISO Program Leadership: from $7,500/month; typical $7,500–$12,000/month

Deliverables

  • Security roadmap, reviewed and updated with leadership on an agreed cadence
  • Governance charter, meeting agendas, and decision and risk-acceptance logs
  • A maintained policy set with version history
  • Program metric definitions and periodic leadership reports
  • Board-ready summaries when you need them

How the engagement runs

Every engagement begins with a written scope and proposal.

  1. Discovery

    We learn your business, obligations, current program, and the people involved, and review any recent assessments.

  2. Roadmap

    We agree on priorities and a sequenced plan with owners, and set up governance so decisions are recorded.

  3. Recurring leadership

    We work with your team on a set cadence: running governance meetings, advancing roadmap items, and handling policy and customer-review needs.

  4. Report and adjust

    We report progress and risk to leadership and adjust the roadmap as the business changes.

Standards and methods

  • NIST CSF 2.0, especially the Govern function, as the structure for program governance and reporting
  • CIS Critical Security Controls v8.1 for prioritizing technical safeguards
  • Control mapping to the frameworks you're held to, such as SOC 2, ISO/IEC 27001, the HIPAA Security Rule, PCI DSS, or CMMC

What a vCISO owns and what leadership keeps

A virtual CISO, often called a fractional CISO, brings experienced security leadership without a full-time hire. The split below is one practical way to divide the work; the engagement terms set the exact line for each organization.

Whatever the split, NIST CSF 2.0 puts accountability with organizational leadership: its first outcome for roles and responsibilities (GV.RR-01) is that leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving.

One way to divide security leadership work between a vCISO and the organization's leadership
AreaThe vCISOLeadership
Security roadmapDrafts it, sequences the work, and tracks progressApproves priorities and funding
Risk decisionsFrames the options and recommends a treatmentDecides to reduce, transfer, avoid, or accept each risk
PoliciesDrafts them and keeps them currentApproves them and holds people to them
ReportingPrepares metrics and plain-language updatesUses them to oversee the program and adjust course

Source: NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0 (February 26, 2024)

vCISO work mapped to NIST CSF 2.0 Govern

In NIST CSF 2.0, the Govern Function covers how an organization's cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored.

Much of a vCISO's recurring work lines up with Govern, which makes it a practical structure for reporting on the program to leadership and the board:

  • Organizational Context (GV.OC): understanding the mission, stakeholder expectations, and the legal, regulatory, and contractual requirements behind security decisions
  • Risk Management Strategy (GV.RM): setting risk appetite and risk tolerance statements, and a standard way to rate and document risks
  • Roles, Responsibilities, and Authorities (GV.RR): making accountability explicit and resourcing it
  • Policy (GV.PO): establishing, communicating, and enforcing cybersecurity policy
  • Oversight (GV.OV): using the results of risk management activities to adjust the strategy
  • Cybersecurity Supply Chain Risk Management (GV.SC): managing risk from suppliers and other third parties

Source: NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0 (February 26, 2024)

Prerequisites and your responsibilities

  • An executive sponsor who owns security risk decisions for the organization
  • A primary point of contact on your team for day-to-day coordination
  • A seat in the leadership meetings where security priorities and budget are discussed
  • Internal or contracted staff to carry out the technical work the roadmap calls for

Pricing

  • vCISO Advisory

    From $4,000/month

    Typical scoped range: $4,000 to $6,000/month

    Monthly

  • vCISO Program Leadership

    From $7,500/month

    Typical scoped range: $7,500 to $12,000/month

    Monthly

Non-binding. Final pricing follows a written scope and proposal.

What affects the final price

Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.

Compare published prices for every service

Who stays accountable

Our virtual CISO advises your leadership. Risk decisions and accountability for your security program stay with your organization, and our vCISO doesn't hold a corporate officer role or sign compliance attestations on your behalf.

When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.

Guides

Frequently asked questions

What's the difference between vCISO Advisory and Program Leadership?

Advisory suits teams that already have people doing security work and need experienced direction and review. Program Leadership suits organizations that need someone to actively run the program: chairing governance, coordinating work across teams, and owning the roadmap. Your written proposal sets out the exact scope and cadence.

Is a virtual CISO a replacement for a full-time CISO?

For many growing organizations it's the right step before a full-time hire. You get senior direction now and a documented program that a future hire can inherit. If you later bring in a full-time leader, the roadmap, policies, and decision records give them a clear starting point.

Can the vCISO help with customer security questionnaires?

Yes. Answering questionnaires and joining customer security calls is a common part of the work. Over time we build a library of approved answers and supporting documents so your team can respond faster and more consistently.

How do you work with our IT provider or internal engineers?

We set direction and review outcomes; your staff or managed service provider makes the technical changes. We coordinate with them directly so priorities, evidence, and status stay aligned.

Primary sources

Talk to a practitioner about vCISO support

Share what’s prompting the work and what you need to decide, and we’ll help you judge whether this service is the right fit.

What happens next

  1. Tell us about your environment and what's driving the request.
  2. Talk through goals, constraints, and options with a practitioner.
  3. Review the proposal and decide whether to go ahead.