Service
Risk assessments
Where you stand against NIST CSF 2.0 and CIS Controls
Service
A security leader from our team works with you on a recurring basis to set the roadmap, run governance, keep policies current, and report progress to leadership in plain terms.
What we deliver
Virtual CISO advisory: roadmap, governance, policy, metrics, and executive reporting.
Ongoing guidance for teams that have people doing the work and need experienced direction: setting priorities, reviewing policies and plans, weighing in on decisions, and reporting to leadership.
Deeper involvement for organizations that need someone to lead the program: chairing governance, driving roadmap work across teams, maintaining the policy set, and representing the program in customer and leadership conversations.
Every engagement begins with a written scope and proposal.
We learn your business, obligations, current program, and the people involved, and review any recent assessments.
We agree on priorities and a sequenced plan with owners, and set up governance so decisions are recorded.
We work with your team on a set cadence: running governance meetings, advancing roadmap items, and handling policy and customer-review needs.
We report progress and risk to leadership and adjust the roadmap as the business changes.
A virtual CISO, often called a fractional CISO, brings experienced security leadership without a full-time hire. The split below is one practical way to divide the work; the engagement terms set the exact line for each organization.
Whatever the split, NIST CSF 2.0 puts accountability with organizational leadership: its first outcome for roles and responsibilities (GV.RR-01) is that leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving.
| Area | The vCISO | Leadership |
|---|---|---|
| Security roadmap | Drafts it, sequences the work, and tracks progress | Approves priorities and funding |
| Risk decisions | Frames the options and recommends a treatment | Decides to reduce, transfer, avoid, or accept each risk |
| Policies | Drafts them and keeps them current | Approves them and holds people to them |
| Reporting | Prepares metrics and plain-language updates | Uses them to oversee the program and adjust course |
Source: NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0 (February 26, 2024)
Read the full guide: What a vCISO does, and when to hire a full-time CISO
In NIST CSF 2.0, the Govern Function covers how an organization's cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored.
Much of a vCISO's recurring work lines up with Govern, which makes it a practical structure for reporting on the program to leadership and the board:
Source: NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0 (February 26, 2024)
From $4,000/month
Typical scoped range: $4,000 to $6,000/month
Monthly
From $7,500/month
Typical scoped range: $7,500 to $12,000/month
Monthly
Non-binding. Final pricing follows a written scope and proposal.
Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.
Our virtual CISO advises your leadership. Risk decisions and accountability for your security program stay with your organization, and our vCISO doesn't hold a corporate officer role or sign compliance attestations on your behalf.
When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.
Advisory suits teams that already have people doing security work and need experienced direction and review. Program Leadership suits organizations that need someone to actively run the program: chairing governance, coordinating work across teams, and owning the roadmap. Your written proposal sets out the exact scope and cadence.
For many growing organizations it's the right step before a full-time hire. You get senior direction now and a documented program that a future hire can inherit. If you later bring in a full-time leader, the roadmap, policies, and decision records give them a clear starting point.
Yes. Answering questionnaires and joining customer security calls is a common part of the work. Over time we build a library of approved answers and supporting documents so your team can respond faster and more consistently.
We set direction and review outcomes; your staff or managed service provider makes the technical changes. We coordinate with them directly so priorities, evidence, and status stay aligned.
Share what’s prompting the work and what you need to decide, and we’ll help you judge whether this service is the right fit.