CISO as a Service

Someone who sets the security priorities, keeps them moving and sits down with the board to explain them, with whatever dedication makes sense for your size.

When it makes sense

When what you need is the judgement, not the headcount

Plenty of organisations need someone directing security long before they can justify a full-time CISO. In the meantime the gap gets covered by whoever has room in their diary that week, almost always from IT and almost always at the expense of something else.

This service fills that seat from outside, with an agreed level of dedication: a few hours a month, a few days, or whatever the moment calls for. It can be the whole role or only the part that isn't covered.

Security has no owner

Tasks are shared out, but nobody answers for the whole and nobody is keeping track of what was left pending last quarter.

The board asks and nobody answers

The committee asks for a picture of the risk and what comes back is a technical report that doesn't answer the question.

There are suppliers and nobody directs them

Several companies touch your security and none of them has the full picture. Coordinating them is a job, and right now nobody is doing it.

What's included

What the role covers

The scope is agreed at the start and reviewed. Not every organisation needs all three from month one.

Governance and risk

The part that holds up everything else and the part that is never urgent until it is.

  • Cybersecurity governance
  • Risk monitoring
  • Definition of the strategy
  • Preparing and running the security committee

Priorities and progress

Getting things done, in the right order and without redoing them.

  • Prioritisation of initiatives
  • Coordination of the projects under way
  • Follow-up on the improvement plans
  • Oversight of suppliers

Communication

Translating in both directions, which is usually what is missing.

  • Reporting to the board
  • Working with IT and the other areas
  • Responding to client security questionnaires
  • Support during audits and external assessments
How I work

How it starts and how it continues

The first two months look different from the rest: you have to understand before you can direct.

  1. Onboarding

    Meeting the board and IT, reviewing what is in place and what is under way, and agreeing which part of the role gets covered.

  2. Baseline

    State of the risk, open initiatives, applicable obligations and suppliers involved. This is the line everything else is measured against.

  3. Rhythm

    Follow-up meetings at the agreed frequency, priorities reviewed and decisions documented. The continuity is the service.

  4. Committee

    Periodic presentation to the board: what has progressed, what risk remains open and what needs deciding. Without unnecessary jargon.

What you get

What you see every month

A retained service is judged by what it leaves in writing, not by the hours it consumes.

  • Current priorities and their reasoning
  • State of the risk, kept up to date
  • Follow-up on the open initiatives
  • Minutes and decisions from the security committee
  • Oversight of the suppliers involved
  • Ongoing availability for whatever comes up

Scope of the serviceThis service covers the direction of security: priorities, governance, follow-up and communication. Day-to-day operation stays with your IT team or your suppliers, and there is no 24×7 on-call or continuous monitoring behind it. Nor does it replace the responsibilities that fall to your organisation's governing body. If any of those pieces needs covering, we look at it and find whoever is right for the job.

Frequently asked questions

What people usually ask before engaging

How many hours a month does it take?

It depends on size, on regulatory pressure and on how much is under way. A small organisation with a stable plan takes considerably less than one in the middle of a NIS2 programme with client audits every couple of months. A level of dedication is agreed at the start and revised when it stops fitting, in either direction.

Is this the same as a vCISO?

Yes, it is the same service under a different name. The market uses external CISO, CISO as a Service and vCISO interchangeably for the same thing: someone performing the security lead role without being on the payroll.

Do you take on the legal responsibility of the post?

The service provides the work, the judgement and the communication, but it does not replace the responsibilities that fall to your organisation's governing body. That split is worth having clear in writing from the start, and it is one of the first things we settle.

Can you talk to our suppliers?

It is part of the service. Coordinating whoever runs your endpoints, whoever runs your cloud and whoever is going to audit you is a good share of the value: they are technical conversations that eat time and where it helps to have someone on your side.

What happens if we end up hiring an internal CISO?

That is the natural end of the service, not a problem. The organisation keeps the governance in place, the risk documented and the plans running, so whoever joins doesn't start from zero. I help with the handover if it is useful.

Do you work remotely?

Yes, that is the usual arrangement, with companies anywhere. Committee meetings or sessions that call for being there in person are agreed separately when it makes sense.

Where to go next

Let's talk

Need someone steering security without adding headcount?

Tell me how security is shared out today, what you are being asked for and what keeps getting left undone each month. Out of that comes the dedication that makes sense, which is often less than people expect.

I reply personally within 24 working hours · No commitment