What's included

  • Fractional / virtual CISO leadership and advisory retainers
  • Security policy and procedure development (AUP, IR, access control, data handling, and more)
  • Risk assessments and risk register development
  • Framework alignment and CIS Controls implementation guidance
  • Vendor/third-party risk review
  • Security awareness program design
  • Board and executive reporting on cyber risk

How engagements work

vCISO engagements are typically structured as an ongoing monthly retainer: a fixed amount of advisory time, a standing cadence of meetings with leadership, and defined deliverables such as a risk register, policy set, or compliance roadmap. Policy and risk-assessment work can also be scoped as a standalone project.

Good fit if you...

  • Need security leadership but aren't ready for a full-time CISO hire
  • Have to answer a customer security questionnaire or pursue a compliance framework
  • Have no written security policy, or it hasn't been updated in years
  • Need someone to translate technical risk into terms your board or leadership can act on

Pursuing a specific certification or attestation? See our dedicated Compliance Consulting page for NIST, SOC 2, HIPAA, PCI DSS, and ISO 27001 readiness work.

Discuss a vCISO retainer or policy project

Contact Us