
Case Study · Asset management
Security governance (vCISO) for an asset management firm
- Ongoingfractional engagement
- 4/yearboard reporting cadence
- 3 monthsfirst roadmap cycle
The challenge
An asset management firm had reached a size where security could no longer be handled informally, yet did not yet justify a full-time CISO. Decisions were made case by case, without an overall view of risk or an interlocutor who spoke the board’s language.
The board perceived security as a technical cost that was hard to assess. There was no way to connect spend and initiatives to actual business risk, or to answer questions from institutional clients and regulators about the firm’s posture with confidence.
My approach
I took on the vCISO role on a fractional basis, starting from a read of risk calibrated to the firm’s business model: client data, operational continuity, provider relationships, and obligations toward investors and authorities. From there I defined a roadmap with a few clear priorities, ordered by risk rather than by technology fashion.
I established a governance rhythm: periodic board reporting that translates security status into business-risk terms, with understandable indicators and decisions to be made. Security became a recurring, structured agenda item rather than an occasional emergency.
Day to day I acted as the reference point for technology choices, provider relationships, and the due diligence requests of institutional clients, bringing continuity and consistency without the cost of a full-time hire.
The result is a security function proportionate to the firm’s size: decisions made deliberately, an informed board, and a defensible posture in front of clients and regulators.
Related
You might also like
GovernanceFrom directive to board plan: decisions you can approve
Turning NIS2 and CRA into something a board can understand, approve and fund: gap assessment, costed roadmap, reporting.9 Dec 2025 · 4 min read
GovernanceThe vCISO: when security leadership on retainer makes sense
Governance, risk-based priorities and board reporting, without a full-time hire.20 Jan 2026 · 4 min read
GovernanceWhat the board should actually ask whoever leads security
A thirty-slide technical report is not oversight. A few right questions, asked regularly, are.10 Mar 2026 · 1 min read