What is the typical engagement size?
Most clients start at 2 to 4 days per month, scaling to 6 to 8 days during regulator submissions, incidents or M&A activity.
Extended answers to the questions buyers, boards and procurement teams ask before commissioning Virtual CISO (vCISO).
Delivered by an ISO/IEC 27001, 27701 & 9001 certified organisation
Most clients start at 2 to 4 days per month, scaling to 6 to 8 days during regulator submissions, incidents or M&A activity.
Yes — vCISO retainers include on-call escalation for major incidents and breach response.
A consultant delivers a project. A vCISO holds the CISO accountability — owns the strategy, board narrative, regulator relationship and incident command across an open-ended retainer.
A named senior practitioner with 15+ years of CISO or Head-of-Security experience in your sector. Same person every month — no rotating account team.
Yes. Several clients have converted vCISOs into permanent hires after 9 to 18 months. We support the transition with no buy-out fee.
No — the vCISO leads and orchestrates your existing team (or MSSP). They provide leadership, governance and external credibility, not hands-on engineering.
Yes — preparation, attendance and follow-up across the quarterly audit committee, board risk committee and ad-hoc cyber forums.
Days flex up monthly. We have moved clients from 2 days/month to a full-time interim CISO during regulator events, M&A and major incidents.
Every engagement is led by a partner or principal with at least 12 years in managed services and supported by certified consultants (CISA, CISM, CISSP, CIPP/E, ISO 27001 Lead Auditor, ISO 42001 Lead Implementer, OSCP, CREST). You meet the actual delivery team before contracts are signed.
All client data stays within the regions you authorise. NDAs are signed before scoping calls, and we offer fully on-premise delivery for sensitive engagements. For UAE and KSA clients, evidence remains in-country by default.
Yes. We routinely collaborate with EY, Deloitte, KPMG, PwC, BDO and Grant Thornton as your implementation partner while they retain audit independence. Roles are agreed upfront in writing to preserve auditor independence rules.
Yes — our Managed Compliance Service operates the programme on a monthly subscription, covering control monitoring, evidence collection, internal audit and recertification across every framework in scope.
Success criteria are agreed in the engagement charter — typically a passed certification or regulator submission, an audit-ready evidence repository, trained control owners and a 12-month continuous-improvement plan.