Someone who sets the security priorities, keeps them moving and sits down with the board to explain them, with whatever dedication makes sense for your size.
Plenty of organisations need someone directing security long before they can justify a full-time CISO. In the meantime the gap gets covered by whoever has room in their diary that week, almost always from IT and almost always at the expense of something else.
This service fills that seat from outside, with an agreed level of dedication: a few hours a month, a few days, or whatever the moment calls for. It can be the whole role or only the part that isn't covered.
Tasks are shared out, but nobody answers for the whole and nobody is keeping track of what was left pending last quarter.
The committee asks for a picture of the risk and what comes back is a technical report that doesn't answer the question.
Several companies touch your security and none of them has the full picture. Coordinating them is a job, and right now nobody is doing it.
The scope is agreed at the start and reviewed. Not every organisation needs all three from month one.
The part that holds up everything else and the part that is never urgent until it is.
Getting things done, in the right order and without redoing them.
Translating in both directions, which is usually what is missing.
The first two months look different from the rest: you have to understand before you can direct.
Meeting the board and IT, reviewing what is in place and what is under way, and agreeing which part of the role gets covered.
State of the risk, open initiatives, applicable obligations and suppliers involved. This is the line everything else is measured against.
Follow-up meetings at the agreed frequency, priorities reviewed and decisions documented. The continuity is the service.
Periodic presentation to the board: what has progressed, what risk remains open and what needs deciding. Without unnecessary jargon.
A retained service is judged by what it leaves in writing, not by the hours it consumes.
Scope of the serviceThis service covers the direction of security: priorities, governance, follow-up and communication. Day-to-day operation stays with your IT team or your suppliers, and there is no 24×7 on-call or continuous monitoring behind it. Nor does it replace the responsibilities that fall to your organisation's governing body. If any of those pieces needs covering, we look at it and find whoever is right for the job.
It depends on size, on regulatory pressure and on how much is under way. A small organisation with a stable plan takes considerably less than one in the middle of a NIS2 programme with client audits every couple of months. A level of dedication is agreed at the start and revised when it stops fitting, in either direction.
Yes, it is the same service under a different name. The market uses external CISO, CISO as a Service and vCISO interchangeably for the same thing: someone performing the security lead role without being on the payroll.
The service provides the work, the judgement and the communication, but it does not replace the responsibilities that fall to your organisation's governing body. That split is worth having clear in writing from the start, and it is one of the first things we settle.
It is part of the service. Coordinating whoever runs your endpoints, whoever runs your cloud and whoever is going to audit you is a good share of the value: they are technical conversations that eat time and where it helps to have someone on your side.
That is the natural end of the service, not a problem. The organisation keeps the governance in place, the risk documented and the plans running, so whoever joins doesn't start from zero. I help with the handover if it is useful.
Yes, that is the usual arrangement, with companies anywhere. Committee meetings or sessions that call for being there in person are agreed separately when it makes sense.
Tell me how security is shared out today, what you are being asked for and what keeps getting left undone each month. Out of that comes the dedication that makes sense, which is often less than people expect.
I reply personally within 24 working hours · No commitment