Is this you?

  • Security currently belongs to whoever runs IT.
  • Your board, investors or customers want to know who is accountable for security.
  • Your CISO has left and you need continuity while you hire.
  • Your security team needs a leader, not another tool.

What you get

  • A security strategy and roadmap tied to your business objectives
  • Board and executive reporting in plain language
  • Ownership of compliance programs such as CMMC, SOC 2 and NIST CSF
  • Budget planning and vendor decisions
  • Policies, a risk register and an incident response plan, kept current
  • Cyber BAMCIS training so your leaders plan and decide the same way under pressure

How it works

  1. Step 1: Learn

    Understand your business, your risks and the program you have today.

  2. Step 2: Plan

    A near-term plan and a longer roadmap your leadership signs off on.

  3. Step 3: Lead

    Run the program: decisions, reporting and accountability.

  4. Step 4: Hand off

    Transition to a full-time CISO when you are ready, or keep us on.

Every step follows Cyber BAMCIS, our planning method.

Related work

  • State government

    A cyber threat intelligence program

    The program document, operating tracker and leadership briefing for a state government cyber threat intelligence program.

Questions

How much time does a virtual CISO spend with us?

It depends on your environment and your goals. We agree on a cadence up front and adjust it as your needs change.

Will you work with our IT team or managed service provider?

Yes. We set direction and hold the program accountable; your IT team or provider keeps running day-to-day operations.

Can our virtual CISO brief the board?

Yes. Board and executive reporting is part of the role.

Other services

Tell us what’s driving the deadline

One short call is enough to know whether we’re the right fit and what the work would take.