The moment usually arrives as an attachment.
A large customer sends a security questionnaire. Two hundred questions, a deadline, and a deal attached. Someone forwards it to engineering. Engineering has never seen most of these terms. The deal slips a quarter.
Or it arrives as a list — from an auditor, a consultant, an insurer — of forty things you should be doing. All reasonable. None prioritised. It's been sitting in a folder since March.
A vCISO exists for both: someone senior enough to decide what gets done this quarter, and to put their name on the answer.
What the Engagement Covers
Security roadmap and prioritisation. A programme scoped to your actual risk, budget and stage, sequenced so the next two quarters are specific rather than aspirational.
Policies and documentation. The policy set your auditors and customers require, written to how you operate rather than lifted from a template.
Security questionnaires and due diligence. We complete them. Directly, accurately, on your deadline, without your engineers losing a week — and we flag which honest "no" answers are worth converting before the next questionnaire lands.
Third-party and vendor risk. A working process for evaluating vendors before they get access, and reviewing the ones who already have it.
Incident response readiness. A plan that names people rather than roles, and tabletop exercises to find out whether it survives contact with a real Tuesday.
Tool rationalisation. Most companies at this stage pay for overlapping tools while missing basics. We fix the ratio before asking for budget.
Leadership and board reporting. Security expressed as business risk, in language your board will act on.
How It Works
Fractional and ongoing — a set number of days per month on retainer. You get a named person who knows your environment, joins the meetings that need them, and is reachable when something happens. Not a rotating pool, not a portal, not a ticket queue.
When You Don't Need This
If you're eight people, pre-revenue, with no customer data and no enterprise pipeline, you don't need a vCISO. You need MFA everywhere, a password manager, backups you've actually tested, and someone patching things. That's a conversation, not a retainer, and we'll say so on the call rather than selling you a programme.
This makes sense when you're handling sensitive data, selling to companies that audit their suppliers, operating under a regulatory framework, or growing faster than your controls.
Who Leads This Work
[Practitioner block — see the end of this document.]
Questions We Get Asked
How is this different from hiring a security consultant?
Continuity and accountability. A consultant delivers a project and leaves. A vCISO owns the outcome across quarters, sits in your leadership meetings, and is the name on the security section of your contracts.
Can you act as our security contact with customers?
For questionnaires and due diligence, yes. Contractual and legal signing authority stays with you.
What's the minimum commitment?
Quarters, not months. Meaningful change doesn't happen in four weeks and we'd rather not take the money for pretending otherwise.
Ready to take the first step?



