Virtual CISO

Security leadership by the month, instead of by the salary.

Most companies of 11 to 50 people need a CISO's decisions without needing a CISO's headcount. Framework selection, risk register, audit preparation and board reporting, included from the entry plan up.

30 minutes. We tell you what we would change first, and you keep the notes.

Why the role gets shared

The job is real. The full time salary usually is not.

At your size the security leadership work is genuine and it is also intermittent. There are weeks where it is a standing agenda item and weeks where it is nothing. Hiring a full time executive for that pattern means paying for availability you do not use, and most owners look at the number once and quietly decide to carry the risk instead.

Carrying the risk works until somebody external asks you to demonstrate you are managing it. That request rarely arrives gently. It is a customer questionnaire with a deadline, an insurer at renewal, or an auditor with a scope already written. At that point the missing thing is not software. It is the person who was supposed to have decided what standard you work to.

Sharing the role solves the arithmetic without pretending the work is optional. You get the decisions, the documents and the continuity, at a fraction of a salary, from someone who is already inside your environment rather than being introduced to it during the emergency.

What you get

What the engagement produces

Security leadership is easy to sell vaguely. This is the concrete list, so you can hold us to it.

  • A risk register that names owners and dates, not categories
  • Framework selection, so you work toward one standard rather than four
  • Policy set written to be operated, not filed
  • Audit and questionnaire preparation before the deadline, not during
  • Vendor and supply chain review
  • Incident response plan that has been walked through
  • Security roadmap tied to the technology budget
  • Reporting a board or an owner can act on

On our own compliance position: EzziTrust LLC operates to SOC 2 aligned controls and its own Type II audit is in progress.

Questions about the role

Straight answers

What is a virtual CISO?

A Chief Information Security Officer is the person accountable for how an organisation manages security risk: which standard you work to, what gets fixed first, what the board is told, and what happens during an incident. A virtual CISO is that role bought by the month rather than by the salary. For a company of twenty to fifty people the work is real but it is not a full time job, and hiring for it at market rate is rarely justifiable. Sharing the role is the honest answer to that arithmetic.

When does a company actually need one?

Usually one of four things has happened. A large customer has sent a security questionnaire you cannot answer. An insurer has started asking for attestations at renewal. You are pursuing a certification such as SOC 2 and have discovered it is an operational programme rather than a document. Or you have had an incident and the board has asked who owns this. If none of those has happened yet, the honest answer is that you probably have time.

What does a vCISO actually produce?

Documents and decisions, mostly, which sounds unsatisfying until the audit arrives. A risk register with named owners. A chosen framework, so effort compounds instead of scattering. Policies written to be followed rather than filed. An incident response plan someone has walked through before it was needed. And reporting that lets an owner decide where the next dollar of security budget goes, which is the part that is genuinely hard to buy any other way.

How is this different from hiring a consultant for a project?

A consultant delivers an assessment and leaves. That is useful once, and the finding list usually ages badly because nobody owns the remediation. The vCISO model is continuous: the same person carries the risk register forward, watches whether the fixes actually happened, and is present the following quarter when the priorities have moved. The value is in the continuity rather than the initial assessment.

Is vCISO consulting included, or is it an extra line?

It is included, from Cybersecurity & Compliance at $72 per user per month upward. That surprises people, because security leadership is usually sold as a separate retainer. It sits inside the plan because compliance evidence is easier to produce when the person defining the standard and the team operating the controls are the same organisation.

Will a vCISO replace our IT team?

No, and the distinction matters. IT keeps the systems running. A CISO decides what risk the business is willing to carry and proves it is being managed. Those are different jobs, and combining them puts the same person in charge of both doing the work and judging whether the work was sufficient. When a client already has an IT person we run co-managed. They keep supporting your people while we take cybersecurity and compliance, and our team covers nights, weekends and anything they cannot get to.

Got a security questionnaire you cannot answer?

Send it over. We will tell you what it is really asking for and how far you are from being able to answer it honestly.