Security Advisory and vCISO Services

At some point most growing organisations reach the same position. Security has become important enough to need someone senior owning it, and not yet important enough to justify a full time chief information security officer at the salary one commands.

So it goes to the head of IT, who is already running the estate. Or the chief technology officer, who is already running engineering. Or a founder, who is already running everything. It gets attention when a customer asks or something breaks, and no attention in between.

A virtual CISO fills that gap. You get senior security leadership for a defined number of days each month, at a fraction of what the equivalent hire would cost, without a recruitment process that takes six months and frequently fails.

Advisory & vCISO

What a vCISO actually does

The term gets used loosely, so here is the substance of the role.

Owns the security strategy. A written plan covering where you are, where you need to be, what it will cost and in what order it happens. Reviewed and updated as the business changes rather than written once and filed.

Manages risk properly. A risk register that reflects your actual business rather than a generic threat list, reviewed on a schedule, with decisions recorded. Boards increasingly ask to see this, and so do auditors, insurers and acquirers.

Represents security to leadership. Board and executive reporting translated out of technical language into commercial terms. This is often the single most valuable part of the role, because most security functions fail at the point of asking for budget rather than the point of doing the work.

Handles customer and regulator security questions. Attending customer security reviews, responding to due diligence, dealing with regulators and insurers. Having a named security leader on the call changes how those conversations go, particularly in enterprise sales.

Directs technical work. Setting priorities for internal teams and managing external providers including testing, monitoring and compliance work. Making sure the money you spend on security is spent on the things that matter most to you.

Runs incident readiness. Response plans that have been tested rather than written. Tabletop exercises with the leadership team, because the people who will make decisions during an incident should not be encountering the plan for the first time during one.

How the engagement works

We agree a monthly commitment, commonly between two and eight days depending on your size and what is happening. Regular cadence, a standing meeting rhythm, and availability between sessions rather than a consultant who disappears for a month at a time.

The first ninety days follow a consistent shape. Assess the current position properly. Produce a prioritised roadmap. Deliver a small number of visible improvements quickly, because credibility inside the organisation matters and a roadmap alone does not build it.

A good vCISO engagement should reduce over time. As your programme matures, or as you hire internally, the commitment drops. We would rather hand over a working function than remain permanently necessary, and we will tell you when you have reached the point of hiring someone full time.

Cyber risk assessment

A structured assessment of what could realistically go wrong in your organisation, how likely each scenario is, what it would cost you, and which controls would reduce it most per pound spent.

We work to recognised methodology such as ISO 27005 or the NIST risk management framework, then translate the output into language a board can act on. A risk register nobody outside the security team can read has failed at its main purpose.

The output tends to surprise people. The risks that keep security teams awake are often not the risks that would actually damage the business most, and seeing the two compared side by side changes how budget gets allocated.

Security awareness training

Most awareness training is bought to satisfy a compliance requirement and delivered as an annual video that staff click through while doing something else. It changes nothing, which everybody involved quietly knows.

Training that works is short, frequent, relevant to the specific roles being trained, and measured against behaviour rather than completion rates. Finance staff face different attacks to engineers. Executives are targeted differently again.

We combine training with phishing simulation so improvement can be measured against click rates and reporting rates over time. The metric that matters most is not how few people click. It is how quickly people report, because in a real incident that number determines how much time your responders have.

AI security and governance

Two related problems arriving in most organisations at once.

AI security. If you are building products that use large language models, you have introduced an attack surface that traditional testing does not cover. Prompt injection, insecure output handling, training data exposure, excessive agency granted to automated systems and supply chain risk in models and plugins. We assess against the OWASP Top 10 for LLM applications.

AI governance. If your staff are using AI tools, and they are, you need to know what data is going into them and under what terms. The EU AI Act introduces obligations on a phased timeline, and ISO 42001 provides a management system standard for organisations that need to demonstrate governance. We help you establish acceptable use, inventory what is actually in use, assess risk and build the documentation that customers and regulators are beginning to request.

Merger and acquisition security due diligence

Acquiring a company means acquiring its security debt, its breach history and its regulatory exposure. Technical due diligence frequently covers architecture and code quality while treating security as a checkbox.

We assess the target's security posture, compliance position, incident history and the integration risk of connecting their environment to yours. Findings that affect valuation are worth knowing before completion rather than after.

Who this is for

Companies growing past the point where security can stay informal, usually somewhere between fifty and five hundred staff. Businesses whose customers are asking who is responsible for security and expecting a name. Organisations preparing for funding, acquisition or entry into a regulated market. Companies with an internal security hire who needs senior support rather than replacement. Businesses that have had an incident and now need to build something structured rather than reacting again.

Frequently asked questions

How does a vCISO differ from a security consultant?

A consultant delivers a project and leaves. A vCISO holds ongoing responsibility for your security programme, attends your meetings, knows your business and remains accountable between engagements.

How many days per month do we need?

Most organisations start between two and four days monthly. Companies going through certification, an acquisition or the aftermath of an incident typically need more initially and less afterwards.

Can a vCISO work with our existing IT team?

Yes, and that is the normal arrangement. The role provides direction and ownership. Your team continues to deliver. Many engagements exist specifically to give a capable internal team the senior backing they have been missing.

Will this help us pass customer security reviews?

Considerably. Having a named security leader who can attend a customer review, answer questions directly and speak to your programme with authority changes the outcome of those conversations more than any document does.

What happens when we hire internally?

We hand over, and we help you recruit if useful. Some clients keep a reduced advisory arrangement afterwards so their new hire has someone senior to consult. Others end the engagement entirely, which is a reasonable outcome and one we plan for from the start.

Is this a long term contract?

Engagements are typically agreed in twelve month terms with a review point at three months, though we are happy to start with a shorter initial period if you would rather see the work before committing.

Get senior security leadership without the hire

Book a call to talk through where your security programme currently sits and what a vCISO engagement would cover.