Virtual CISO

Virtual CISO services for SMBs — security leadership, fractionally.

Fractional security leadership for SMBs across the EU — one certified, accountable owner for the risk that currently sits with you. Active in one to two weeks, not six months.

The gap

An SMB needs a CISO. It can't afford one.

NIS2, DORA, GDPR, ISO 27001 — the EU regulatory stack assumes you have someone qualified to run your security program. Auditors, insurers, and enterprise customers all ask the same question: who's accountable here?

A full-time CISO costs €150,000–€300,000 a year in salary alone, before benefits and recruitment. Most SMBs can't justify that headcount — and shouldn't have to. A vCISO closes the gap: the same strategic leadership, scaled to your business and your budget.

What we deliver

Eleven responsibilities, one accountable owner.

Security program design

We build your information security program from the ground up — sized for your business, aligned to your risk appetite, ready to scale as you grow.

Risk management

A live risk register that the board actually reads. Threats and treatment plans, prioritised against business impact.

Regulatory compliance

NIS2, DORA, GDPR, ISO 27001, PCI DSS — we own the gap analysis, the roadmap, the remediation, and the audit-readiness work.

Incident response

A tested IR plan, tabletop exercises, and the leadership your team needs when something goes wrong. Notification timelines under NIS2 and GDPR are tight; we make sure you meet them.

Board & leadership reporting

Monthly briefings your CEO and board can act on. Posture, exposure, decisions needed — in plain language, no security theatre.

Audit preparation

Internal audits, ISO 27001 certification, customer security assessments. We get you ready, attend the audit, and remediate the findings.

Policy & procedure

We write the policies your business actually needs, in language people will read — and make sure they're applied, not filed.

Security awareness

Practical training and phishing simulations that move your team from your weakest link to your first line of defence.

Security tooling

We supervise the deployment, configuration, and monitoring of the controls you actually need — not the ones a vendor wants to sell you.

ISMS operations

Running your Information Security Management System day-to-day: monitoring effectiveness, maintaining evidence, planning improvements.

Continuous improvement

Standards are a floor, not a ceiling. We benchmark, identify what's not working, and raise the bar — quarter by quarter.

How we work

Four phases. Two weeks to start.

  1. 01

    Discovery call

    25 minutes · free · no commitment

    A direct conversation about your business, your current security posture, and which obligations are most pressing. We tell you honestly whether a vCISO engagement is the right fit — or whether something else makes more sense for where you are today.

  2. 02

    Security baseline assessment

    Week 1–2

    A structured review of your current controls, policies, and compliance status. Output: a clear baseline, a prioritised risk register, and a short list of actions worth doing immediately.

  3. 03

    Roadmap & program build

    Week 3 onwards

    Your vCISO develops a tailored security roadmap — aligned to your business goals, regulatory obligations, and budget — then begins building your ISMS, policies, and operating cadence.

  4. 04

    Ongoing leadership

    Monthly retainer

    Risk reviews, policy updates, supplier security, leadership briefings, audit preparation, and continuous compliance monitoring. Scaled up during a sprint, scaled back at steady-state.

What's included

What the monthly retainer actually covers.

  • A named vCISO as your single accountable security owner.
  • Monthly leadership briefing your CEO and board can act on.
  • A live risk register, reviewed and re-prioritised every month.
  • Policy and procedure updates as your business and the regulations change.
  • Supplier and third-party security reviews on new and renewing contracts.
  • Customer security questionnaires and due-diligence responses, handled for you.
  • Incident response leadership, including regulator notification inside the deadline.
  • Audit preparation and attendance — internal, certification, and customer audits.
  • Regulatory horizon scanning across NIS2, DORA, GDPR, ISO 27001, and PCI DSS.
  • Quarterly benchmarking against your target framework, with a revised roadmap.
  • Evidence and documentation maintained continuously, not rebuilt before each audit.
  • Direct access to your vCISO between scheduled sessions — no ticket queue.

Who this is for

You probably need a vCISO if…

Most of our engagements are with EU-based SMBs of 10–500 employees in regulated sectors or handling sensitive customer data. The signals below tend to come up early in our discovery calls.

  • You process, store, or transmit sensitive personal or financial data.
  • You fall under NIS2, DORA, GDPR, ISO 27001, or PCI DSS — and someone needs to actually own that.
  • Customers, partners, or insurers are asking pointed questions about your security posture.
  • You've had a security incident or near-miss in the past 24 months.
  • Your IT team runs operations well but has no formal security governance experience.
  • You're pursuing an ISO 27001 (or similar) certification and need expert leadership through the audit.
  • Your board can't clearly articulate your current cyber risk exposure — and that's starting to feel uncomfortable.
  • You are scaling fast and informal security practices are creating compliance gaps.

vs full-time CISO

Same accountability. Different cost structure.

FactorCyber-Management vCISOFull-time CISO
Annual costFraction of a full-time salary; scope sized to your needs€150,000–€300,000+ in salary alone, before benefits and recruitment
Time to start1–2 weeks from first conversation3–6 months to recruit, onboard, and ramp up
Breadth of expertiseMulti-framework, multi-sector practitioner team behind every engagementScope limited to the individual hired
FlexibilityScale hours up during a sprint, down at steady-stateFixed headcount — difficult and costly to adjust
EU regulatory coverageNIS2, DORA, GDPR, ISO 27001, PCI DSS, and moreVaries by individual background
Continuity riskBacked by a team — no single point of failureHigh — departure leaves an immediate leadership gap
Best suited forSMBs and scale-ups (10–500 employees) under EU regulationLarge enterprises with full-time security operations

Case in point

A regulated SMB, an 11-week NIS2 readiness sprint.

A mid-sized B2B services company in continental Europe — about 80 employees, classified as an important entity under NIS2 — engaged us after their largest customer asked for evidence of NIS2 compliance during a contract renewal.

We started with the discovery call on a Monday and had the security baseline assessment delivered by the following Friday. The gap analysis surfaced 14 priority items; eight could be closed inside their existing tooling, six required investment. Within eleven weeks they had a working risk register, a tested incident response plan, an updated supplier security process, and a board-level cyber report cadence — enough to satisfy the customer and the regulator.

The engagement continued as a monthly retainer. Their auditor flagged zero non-conformities at the next external review.

FAQ

Common questions.

How is a vCISO different from a security consultant?
A consultant delivers a defined project then steps back. A vCISO takes ongoing accountability for your entire security program — strategy, risk, team leadership, board reporting, and compliance. Think head of security, not project contractor. The two are complementary: a vCISO often commissions consultants for specific work (penetration testing, forensics, certification audits) and owns the integration of their findings.
How quickly can you actually start?
One to two weeks from the discovery call. We scope the engagement on the call, agree the contract within a few days, and begin the baseline assessment in week one. Compare that to a full-time hire: three to six months to recruit, negotiate, and onboard before any work begins.
Do you replace our IT team?
No — we work alongside your existing IT and engineering teams. A vCISO sets security strategy, owns governance, manages risk, and reports to leadership. Your IT team continues running operations, with the vCISO providing the security context they often don't have time to build themselves.
Can a vCISO take us through ISO 27001 certification?
Yes — this is one of the most common outcomes of our engagements. Our practitioners hold PECB ISO/IEC 27001 Lead Auditor accreditation. We design your ISMS, run your internal audit, prepare you for the external certification audit, and stay engaged through the surveillance audits afterwards.
What happens if we have a security incident during the engagement?
Your vCISO leads the response: containment, regulator notification, customer communication, forensics coordination, and recovery. Under NIS2 and GDPR the notification windows are tight (24-72 hours depending on the incident) — having an experienced security executive at the helm from minute one is the difference between a managed incident and a crisis.
How is the engagement priced?
Two components, both fixed: a one-time onboarding fee covering the discovery call, security baseline assessment, and roadmap & program build (phases 01-03), and a monthly retainer for ongoing leadership (phase 04). No surprise bills, no hourly tracking. Both numbers are scoped to your organisation's size, complexity, and regulatory exposure, and shared transparently in the proposal after the discovery call — so you know exactly what you're committing to before you sign.
Can we move to a full-time CISO later?
Yes — and many of our clients do, as they grow into a full-time CISO role. We can help you define the role, write the job description, and brief candidates during the hire. The work the vCISO has done — your ISMS, policies, processes, risk register — transfers cleanly to the incoming CISO.
Do you work with our region or sector?
We serve businesses across France & DOM, Belgium, Luxembourg, Switzerland, and the broader EU — bilingually in English and French, remotely and on-site as needed. Most of our engagements are in regulated sectors (finance, healthcare, industrial, professional services) or with SMBs handling significant volumes of personal or commercial data.