A client contract requires ISO 27001.
Law 25 applies to you and nobody owns it.
You need security leadership but cannot justify a hire.
You have never tested whether your continuity plan works.
ISO 27001
Fixed scopeFrom gap analysis to certification audit, with an ISMS that actually operates.
Law 25
Fixed scopeGap analysis, the required policies and registers, and a breach procedure that works.
Virtual CISO
RetainerDefined days per month of security leadership that reports to your board.
Risk assessment
Fixed scopeAn ISO 27005 assessment that produces a treatment plan executives will fund.
Continuity & tabletop
Fixed scopeContinuity and recovery plans, then a rehearsal that tests whether they survive.
The risk assessment drives the ISMS, the ISMS needs the evidence our offensive and defensive tracks generate, and the vCISO keeps it operating after certification.
Fixed scope for defined deliverables, retainer for ongoing leadership. From 2 weeks to 12 months.