Law 25 — run your compliance in our platform, 1 month free

Security leadership, without the hire

A defined number of days per month from someone who has built security programmes, reports to your board, and owns the roadmap.

The challenge

A full-time CISO costs more than most SMEs can justify, but the work still needs an owner with authority and experience.

Scope — included and not included
Included
  • Security roadmap ownership
  • Board and executive reporting
  • Policy governance
  • Vendor and third party security review
  • Incident escalation authority
  • Audit and client questionnaire support
Not included
  • Hands-on technical implementation
  • Being available outside agreed days without a retainer uplift
  • Legal or HR responsibilities
  • Signing off risks on your behalf
How it works
01
Assess and set the roadmap

Where you are, where you need to be, who owns what by when.

02
Operate monthly

The agreed days, spent on the roadmap and whatever the month brings.

03
Report to the board

Progress, risk and asks — in business language.

04
Review quarterly

Roadmap and days adjusted to reality.

What you receive
  • Security roadmap with owners and dates
  • Monthly progress report
  • Board-ready reporting pack
  • Vendor review record
  • Availability for client security questionnaires
What we need from you
  • ·Executive access
  • ·Authority to set direction
  • ·A named internal counterpart
  • ·Agreed days per month
Timeline and engagement

Ongoing retainer, minimum six months. Days per month agreed up front; unused days handled per the contract.

Standards, methods and tooling
ISO 27001NIST CSFLaw 25Portal hosted in Canada
Frequently asked questions

Give the roadmap an owner

A defined number of days, a named person, board-level reporting.