Security leadership, without the hire
A defined number of days per month from someone who has built security programmes, reports to your board, and owns the roadmap.
The challenge
A full-time CISO costs more than most SMEs can justify, but the work still needs an owner with authority and experience.
Scope — included and not included
Included
- Security roadmap ownership
- Board and executive reporting
- Policy governance
- Vendor and third party security review
- Incident escalation authority
- Audit and client questionnaire support
Not included
- Hands-on technical implementation
- Being available outside agreed days without a retainer uplift
- Legal or HR responsibilities
- Signing off risks on your behalf
How it works
01
Assess and set the roadmap
Where you are, where you need to be, who owns what by when.
02
Operate monthly
The agreed days, spent on the roadmap and whatever the month brings.
03
Report to the board
Progress, risk and asks — in business language.
04
Review quarterly
Roadmap and days adjusted to reality.
What you receive
- →Security roadmap with owners and dates
- →Monthly progress report
- →Board-ready reporting pack
- →Vendor review record
- →Availability for client security questionnaires
What we need from you
- ·Executive access
- ·Authority to set direction
- ·A named internal counterpart
- ·Agreed days per month
Timeline and engagement
Ongoing retainer, minimum six months. Days per month agreed up front; unused days handled per the contract.
Standards, methods and tooling
ISO 27001NIST CSFLaw 25Portal hosted in Canada
Frequently asked questions