Security program design
We build your information security program from the ground up — sized for your business, aligned to your risk appetite, ready to scale as you grow.
Virtual CISO
Fractional security leadership for SMBs across the EU — one certified, accountable owner for the risk that currently sits with you. Active in one to two weeks, not six months.
The gap
NIS2, DORA, GDPR, ISO 27001 — the EU regulatory stack assumes you have someone qualified to run your security program. Auditors, insurers, and enterprise customers all ask the same question: who's accountable here?
A full-time CISO costs €150,000–€300,000 a year in salary alone, before benefits and recruitment. Most SMBs can't justify that headcount — and shouldn't have to. A vCISO closes the gap: the same strategic leadership, scaled to your business and your budget.
What we deliver
We build your information security program from the ground up — sized for your business, aligned to your risk appetite, ready to scale as you grow.
A live risk register that the board actually reads. Threats and treatment plans, prioritised against business impact.
NIS2, DORA, GDPR, ISO 27001, PCI DSS — we own the gap analysis, the roadmap, the remediation, and the audit-readiness work.
A tested IR plan, tabletop exercises, and the leadership your team needs when something goes wrong. Notification timelines under NIS2 and GDPR are tight; we make sure you meet them.
Monthly briefings your CEO and board can act on. Posture, exposure, decisions needed — in plain language, no security theatre.
Internal audits, ISO 27001 certification, customer security assessments. We get you ready, attend the audit, and remediate the findings.
We write the policies your business actually needs, in language people will read — and make sure they're applied, not filed.
Practical training and phishing simulations that move your team from your weakest link to your first line of defence.
We supervise the deployment, configuration, and monitoring of the controls you actually need — not the ones a vendor wants to sell you.
Running your Information Security Management System day-to-day: monitoring effectiveness, maintaining evidence, planning improvements.
Standards are a floor, not a ceiling. We benchmark, identify what's not working, and raise the bar — quarter by quarter.
How we work
25 minutes · free · no commitment
A direct conversation about your business, your current security posture, and which obligations are most pressing. We tell you honestly whether a vCISO engagement is the right fit — or whether something else makes more sense for where you are today.
Week 1–2
A structured review of your current controls, policies, and compliance status. Output: a clear baseline, a prioritised risk register, and a short list of actions worth doing immediately.
Week 3 onwards
Your vCISO develops a tailored security roadmap — aligned to your business goals, regulatory obligations, and budget — then begins building your ISMS, policies, and operating cadence.
Monthly retainer
Risk reviews, policy updates, supplier security, leadership briefings, audit preparation, and continuous compliance monitoring. Scaled up during a sprint, scaled back at steady-state.
What's included
Who this is for
Most of our engagements are with EU-based SMBs of 10–500 employees in regulated sectors or handling sensitive customer data. The signals below tend to come up early in our discovery calls.
Frameworks covered
vs full-time CISO
| Factor | Cyber-Management vCISO | Full-time CISO |
|---|---|---|
| Annual cost | Fraction of a full-time salary; scope sized to your needs | €150,000–€300,000+ in salary alone, before benefits and recruitment |
| Time to start | 1–2 weeks from first conversation | 3–6 months to recruit, onboard, and ramp up |
| Breadth of expertise | Multi-framework, multi-sector practitioner team behind every engagement | Scope limited to the individual hired |
| Flexibility | Scale hours up during a sprint, down at steady-state | Fixed headcount — difficult and costly to adjust |
| EU regulatory coverage | NIS2, DORA, GDPR, ISO 27001, PCI DSS, and more | Varies by individual background |
| Continuity risk | Backed by a team — no single point of failure | High — departure leaves an immediate leadership gap |
| Best suited for | SMBs and scale-ups (10–500 employees) under EU regulation | Large enterprises with full-time security operations |
Case in point
A mid-sized B2B services company in continental Europe — about 80 employees, classified as an important entity under NIS2 — engaged us after their largest customer asked for evidence of NIS2 compliance during a contract renewal.
We started with the discovery call on a Monday and had the security baseline assessment delivered by the following Friday. The gap analysis surfaced 14 priority items; eight could be closed inside their existing tooling, six required investment. Within eleven weeks they had a working risk register, a tested incident response plan, an updated supplier security process, and a board-level cyber report cadence — enough to satisfy the customer and the regulator.
The engagement continued as a monthly retainer. Their auditor flagged zero non-conformities at the next external review.
FAQ