Solutions /  The situation

It landed on the CTO. He did not ask for it, and he is not wrong to resent it.

There is no CISO. Security ended up with whoever was technical enough to be handed the questionnaire, usually the CTO or VP R&D, who now spends his week on vendor reviews and access spreadsheets instead of the product. He is competent enough to do it badly and busy enough to do it never, and the whole thing is held together by his memory.

Get your free exposure assessment

The pressure is external and it is compounding: customer questionnaires, ISO 27001 in contracts, Amendment 13 requiring named officers, insurers asking who is responsible. Every one of those wants an owner. A full-time CISO is expensive and hard to hire for a 100-person company, so the role stays informal and the work stays undone.

What it is costing you

  • Your best engineer's calendar is being consumed by work he is not trained for and does not want.
  • Nothing is continuous: policies are written for an audit, then abandoned; access reviews happen when someone remembers.
  • When a customer asks "who is responsible for security," there is no name to give, and the deal review notices.
  • It is all in one person's head. When he leaves, so does the entire security program.

What we do

01

We put a name in the role

An experienced CISO, part-time and external, who owns security in your company: attends the customer call, signs off the questionnaire, sits in the board update, and is the person your buyer can be introduced to.

02

The recurring work comes off engineering

Access reviews, vendor reviews, policy maintenance, risk register, awareness training, incident readiness. These belong to a function, not to a founder's spare evening.

03

We give you a program, not a project

A roadmap tied to what your sales pipeline needs next (the questionnaire, then the certificate, then the regulator) rather than a generic maturity model.

04

We run it continuously

The ROC keeps controls, evidence and obligations live between audits, so when the next customer asks, the answer already exists and is already true.

How long it takes. The owner exists from week one. A functioning program, the recurring work running on a schedule and producing evidence, takes about a quarter to establish.

What does a virtual CISO actually do?

A virtual CISO owns the security function without being a full-time hire: sets the security roadmap, owns policies and the risk register, runs access and vendor reviews, answers customer security questionnaires and joins customer security calls, prepares and manages certification audits (ISO 27001, SOC 2), runs incident readiness, and reports to management or the board. The distinguishing feature is ownership: a named person accountable for the work, not an advisor who leaves recommendations behind.

When does a company need a CISO?

The trigger is almost never internal. It is the first enterprise customer questionnaire, the first contract demanding ISO 27001 or SOC 2, a regulatory obligation such as Amendment 13 requiring a named officer, or a cyber insurance application asking who is responsible. At that point the company needs an owner, not necessarily an employee. Most companies in the 50-500 range cannot justify a full-time CISO salary but cannot function without the role.

Can our CTO just be the CISO?

He can hold the title, and many do. The failure mode is predictable: security work is recurring and unglamorous (access reviews, vendor reviews, evidence collection), and it loses every scheduling conflict with shipping product. The result is a program that is real before an audit and dormant afterwards, held entirely in one person's head. It also creates a conflict of interest, since the person building the system is the person certifying it is secure.

Find out how far you have drifted.

A free exposure assessment. We connect to what you already have, and show you what your dashboards are not showing you.

No obligation. Results in 10 business days.