Skip to main content

infosecacademy Eğitim Danışmanlık Hizmetleri

vCISO · virtual chief information security officer

Virtual CISO: executive security leadership on a retained basis

For organisations that need the CISO role filled but cannot justify — or cannot recruit — a full-time CISO. A defined cadence, defined deliverables, and a named security leader who reports to your management body. Delivered personally by our founder, with over 25 years in IT and information security.

NIS2 Article 20Board reportingRisk ownershipEssential · Standard · Advanced
In brief

What is a vCISO?

A vCISO — virtual Chief Information Security Officer — is an experienced, externally sourced security leader who sets and runs an organisation’s information security strategy without the organisation employing a full-time CISO. Mid-sized organisations frequently need the function long before they can justify the salary; the role is then absorbed by an IT manager without the mandate, the time or the board access to do it, and the gap only becomes visible during an audit, an incident or a customer security questionnaire.

A real risk picture

A comprehensive discovery and risk assessment replaces assumptions with a prioritised, owned register.

A plan management can read

A 90-day priority action plan with named owners, costs and dates — not a list of recommendations.

Someone accountable

A named security leader who reports to the management body on a defined cadence and answers customer and auditor questions.

Why now

NIS2 made this service considerably more relevant

Compliance is no longer delegable to IT: the management body must approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for failures. Somebody has to prepare those decisions and stand behind them.

Prepare the decisions the board must take

Measures cannot be approved by a management body that has not been given them in a form it can understand and interrogate. The vCISO produces that material.

Maintain the evidence of oversight

Meeting records, reporting packs, decision logs and an active risk register are what a supervisory authority will look for.

Deliver the mandatory training

Article 20(2) requires management body members to follow training. The vCISO delivers it, documents it, and extends it to staff.

Own the reporting chain

The 24-hour early warning and 72-hour notification only work if someone owns the decision to notify, has the contacts, and has tested the process.

Carry the supply chain obligation

Article 21(2)(d) makes supplier security your responsibility. The vCISO runs the assessment programme and drives contract remediation.

Work to the national act

In Slovakia and Romania the engagement runs against Act 69/2018 Coll. with Decree 227/2025 Coll., or GEO 155/2024 and the DNSC deadline sequence — not a generic reading of the directive.

Role coverage

What the role covers

Not a compliance officer. Compliance is the deadline that usually starts the conversation; the value is in having a security executive who also makes architecture, vendor and budget decisions the rest of the year.

  • Security strategy aligned to business objectives
  • Board and management-body reporting
  • Risk register ownership and continuous monitoring
  • Regulatory roadmap and audit readiness
  • Third-party and supply chain risk
  • Incident response leadership and exercises
  • Security budget and vendor decisions
  • Coaching and capability-building for internal teams
Annual packages

Essential, Standard and Advanced

Three levels with a defined scope, deliverables and training calendar. Prices are set against a written scope, not published.

First governance baseline

Essential

For organisations establishing security governance for the first time — typically under 100 staff, no immediate regulatory deadline.

  • Annual security strategy
  • One comprehensive discovery and risk analysis
  • 90-day priority action plan
  • Four management reports a year
  • Core policy set
  • Annual management-body security briefing
  • Two online awareness sessions a year
  • Quarterly email awareness bulletin
Compliance deadline

Standard

For organisations in scope of NIS2, with an active certification programme, or regularly answering customer security questionnaires.

  • Everything in Essential
  • Monthly strategy and management meetings
  • Continuous risk monitoring
  • Two exercises a year — cyber incident and business continuity
  • Compliance advisory — NIS2, GDPR, ISO/IEC 27001
  • Quarterly management-body briefing
  • Four interactive training sessions and two phishing simulations
  • Monthly reporting and security tips bulletin
Regulated supply chain

Advanced

For organisations whose supply chain is part of their regulatory exposure, audited by customers or a group function.

  • Everything in Standard
  • Supplier security audits
  • Supplier contract security annex review
  • Annual full policy-set refresh
  • Third-party compliance audit support
  • Management-body briefing quarterly and on demand
  • Six training sessions and four phishing simulations
  • Monthly awareness campaigns; annual compliance report
Package comparison

Choosing the right level

vCISO package comparison
FeatureEssentialStandardAdvanced
Annual security strategy✓✓✓
Risk assessment and 90-day plan✓✓✓
Policy setCoreStandardFull, refreshed annually
Management reporting4 / year12 / year12 / year + monthly meeting
Management-body briefing (Art. 20)AnnualQuarterlyQuarterly + on demand
Compliance advisory—✓✓
Exercises (incident / continuity)—2 / year4 / year
Supplier security audits——✓
Third-party audit support——✓
Training and awareness2 sessions + quarterly bulletin4 sessions + 2 phishing + monthly bulletin6 sessions + 4 phishing + monthly campaigns

Commercial logic

Published market data puts a retained vCISO meaningfully below the fully-loaded cost of a permanent CISO for organisations of this size — with the added advantage that the engagement scales up or down without a hiring or redundancy cycle.

We do not publish prices. You receive a recommended package with the reasoning and a written scope before any commercial figure.

Engagement shapes

  • Annual retainer — the default; fixed monthly or quarterly commitment with a defined notice period
  • Project-based — leadership through a defined programme, such as a certification cycle or a regulatory deadline
  • Hourly — for organisations that want to start small and scale
How an engagement starts

From introductory call to steady state

  1. Introductory call

    Thirty to forty-five minutes: sector, size, regulatory exposure, what already exists internally, and what triggered the conversation.

  2. Package recommendation and written scope

    A recommended level with the reasoning, a meeting and reporting calendar, and a deliverable list — before any commercial figure.

  3. Contract and onboarding

    Annual agreement with a defined notice period. NDA in place before any client material is exchanged.

  4. Discovery and risk assessment

    The first substantive deliverable, normally completed within the first six weeks.

  5. 90-day plan and first management report

    Prioritised actions with owners, costs and dates, presented to the management body.

  6. Steady state

    Monitoring, reporting, training, exercises and advisory against the agreed calendar.

What we will tell you honestly

  • If a package is more than you need, we will recommend the smaller one.
  • If part of the work is better done by your own team with our oversight, we will structure it that way.
  • Self-sufficiency of your internal team is an explicit objective, not continued dependency.
Frequently asked questions

vCISO questions we are asked

What is a vCISO?

A virtual Chief Information Security Officer is an experienced, externally sourced security leader who sets and runs an organisation’s information security strategy on a retained basis, without the organisation employing a full-time CISO. The role covers strategy, board reporting, risk ownership, compliance roadmap, incident leadership and supplier risk.

How does a vCISO help with NIS2 Article 20?

Article 20 requires the management body to approve the cybersecurity risk-management measures, oversee their implementation and follow training. The vCISO prepares those decisions in a form the board can interrogate, maintains the evidence of oversight — meeting records, reporting packs, decision logs, an active risk register — and delivers and documents the mandatory training.

Is a vCISO cheaper than a permanent CISO?

For mid-sized organisations, published market data puts a retained vCISO meaningfully below the fully-loaded cost of a permanent CISO, and the engagement scales up or down without a hiring or redundancy cycle. We do not publish prices; a proposal follows a written scope with a recommended package.

Which package should we choose?

Essential suits organisations with no formal security governance and no immediate regulatory deadline. Standard suits organisations in scope of NIS2, working towards certification or regularly answering customer security questionnaires. Advanced suits organisations whose supply chain is part of their regulatory exposure. If a package is more than you need, we will recommend the smaller one.

Is the vCISO on site?

Remote by default, and on site for the risk assessment, exercises, training and board meetings. The service is delivered in English or Turkish, with a defined meeting and reporting calendar agreed at the start.

Let us start with a scoping conversation

Thirty to forty-five minutes is usually enough to establish scope, a realistic timeline, and whether we are the right people for the work.