vCISO and security programme
Security stops being a series of projects and starts being a programme at the point where someone senior owns it continuously. Most organizations reach that point long before they can justify an executive salary for it, and spend the intervening years with security owned by whoever last had time.
The short version: a named senior owner, on a defined cadence
The role provides continuity of judgement. Not a report that arrives and then ages, but a person who was in the last conversation, knows why the decision was taken, and is in the next one. That continuity is most of the value, and it is the part a series of one-off assessments cannot produce.
A defined cadence rather than a fraction of a headcount: a standing slot each week or fortnight, a longer monthly working session, and quarterly reporting, with the volume agreed in writing before the engagement starts. Where an engagement needs capability this practice does not hold directly, vetted specialists are brought in for that project and named in the scope. How the role differs from a full-time executive and from a managed provider is set out in vCISO versus CISO versus MSSP.
What the role covers
Strategy and roadmap
A twelve to eighteen month sequence with the reasoning attached: what is being done, in what order, why that order, and what is deliberately being left undone this year. The last of those is what makes a roadmap credible.
Risk register
A working register rather than a spreadsheet nobody opens: each risk with an owner, a current treatment, an agreed appetite, and a review date. Risks that are accepted are recorded as accepted, by name, with an expiry — a permanent unowned acceptance is how a register turns into decoration. The wider risk practice, from appetite to board indicators, is set out under cyber risk management and governance.
Policy set
Written to be followed, sized to the organization, and mapped to whichever framework your customers or regulators care about. A policy that describes practices nobody performs is worse than no policy, because it becomes evidence against you.
Running the programme
Chairing the cadence, keeping the roadmap current, preparing the reporting, reviewing significant changes before they ship, and handling the security questions that arrive from customers, insurers and partners.
Security programme and maturity assessment
This is the assessment that starts most engagements, and it is also bought on its own. It is a review and a gap analysis — not an examination performed by an independent body, and the page is precise about that because several comparable firms are not.
It covers current state against a named framework, a target state appropriate to your size and sector rather than to an ideal, a gap register, and a sequenced roadmap with effort and dependency estimates. Effort and dependency matter more than they sound: a roadmap that ignores which item blocks which is a list, and lists do not survive contact with a delivery plan.
Which framework?
Usually the NIST Cybersecurity Framework, whose 2.0 revision organizes outcomes into six functions — govern, identify, protect, detect, respond and recover — and is readable by a board without translation. Where a customer contract or a regulator points at a different framework, that one is used instead; the framework is a structure for the conversation, not the product. Readiness against the frameworks buyers demand is covered under compliance and privacy.
Re-measure
The same assessment is repeated at six or twelve months against the same criteria. Without a re-measure, a roadmap is unfalsifiable: nobody can say whether the year of work moved anything. With one, the programme becomes answerable to something other than activity.
Board and customer reporting
A board paper that runs to forty slides gets skimmed; one that runs to a page gets read and argued with, which is the point. Reporting produced here is built around a small number of things a director can actually decide on: what changed since last time, what the top risks are and who owns them, what the roadmap is buying this quarter, and what is not being funded and what that means.
Customer-facing reporting is the other half. Enterprise buyers send questionnaires, and the organizations that answer them quickly are the ones whose evidence is already assembled rather than reconstructed each time. That assembled form is described in the evidence pack.
When a vCISO is the wrong answer
Three cases come up often enough to state plainly. If what you need is a specific piece of work — a design review, a test, a readiness project — buy that piece of work; a retainer wrapped around it costs more and delivers the same thing more slowly. If the organization has no capacity to implement anything, a programme owner produces a backlog and frustration, and the money is better spent on implementation. And if you already have a competent security lead, what is usually missing is a second opinion on the plan, not a second owner of it.
Where the shape of the system is the question rather than the shape of the programme, start with security architecture and threat modelling. Where the pressing question is what your suppliers or an acquisition target expose you to, start with third-party risk and cyber due diligence.
How the engagement is structured
Engagements run on a fixed cadence for a fixed term, most often six or twelve months, with a written statement of what is included, what the reporting rhythm is, and how additional project work is handled when it arises. The engagement is quoted in writing before it starts, and the scope names the deliverables rather than describing an availability.
The first eight weeks are usually the maturity assessment, the risk register and the roadmap, because everything after that depends on them being written down.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
How much time does a vCISO actually spend?
Time bought without a cadence tends to be consumed by whatever is loudest that week, which is exactly the pattern the role exists to break.
Do you take accountability, or advise?
Accountability for security risk stays with the organization and its officers, because it cannot be contracted out; the role supplies the judgement, the plan and the reporting, and names the decisions that are yours to take.
Where a customer contract or an insurer asks for a named security contact, the engagement can supply one and the scope records exactly what that designation does and does not mean.
At what size should we hire a full-time CISO?
The usual triggers for a full-time hire are a regulatory obligation, a security function large enough to need daily management, or customers who contractually require a named executive — headcount alone is a poor signal. A common pattern is a fractional role through the growth phase and a handover to a permanent hire, with the roadmap, register and policy set transferring as documents the new hire inherits rather than reinvents.
Can you also answer our customers’ security questionnaires?
Yes. Customer security questionnaires are answered from the same evidence the programme already produces, which is what keeps the answers consistent from one questionnaire to the next.
Where a questionnaire asks for something the organization does not have, the honest answer goes on the form and the gap goes on the roadmap. Questionnaires answered aspirationally become contractual representations, which is a much more expensive problem later.
Give security a named owner and a cadence
Describe the organization, what is driving the need, and who owns security today. The reply says what a cadence would look like and what the first eight weeks would produce — see also all security services.