Photo: kate.sade / Unsplash

Case Study · Asset management

Security governance (vCISO) for an asset management firm

  • vCISO
  • Governance
  • Board reporting
  • Ongoingfractional engagement
  • 4/yearboard reporting cadence
  • 3 monthsfirst roadmap cycle

The challenge

An asset management firm had reached a size where security could no longer be handled informally, yet did not yet justify a full-time CISO. Decisions were made case by case, without an overall view of risk or an interlocutor who spoke the board’s language.

The board perceived security as a technical cost that was hard to assess. There was no way to connect spend and initiatives to actual business risk, or to answer questions from institutional clients and regulators about the firm’s posture with confidence.

My approach

I took on the vCISO role on a fractional basis, starting from a read of risk calibrated to the firm’s business model: client data, operational continuity, provider relationships, and obligations toward investors and authorities. From there I defined a roadmap with a few clear priorities, ordered by risk rather than by technology fashion.

I established a governance rhythm: periodic board reporting that translates security status into business-risk terms, with understandable indicators and decisions to be made. Security became a recurring, structured agenda item rather than an occasional emergency.

Day to day I acted as the reference point for technology choices, provider relationships, and the due diligence requests of institutional clients, bringing continuity and consistency without the cost of a full-time hire.

The result is a security function proportionate to the firm’s size: decisions made deliberately, an informed board, and a defensible posture in front of clients and regulators.

A similar situation?

Start with a confidential briefing.

Book a consultation