Security Leadership · vCISO
Security Governance (vCISO)
CISO-grade security leadership on a monthly retainer.
Board-level direction, oversight and reporting — sized to your company, without a full-time hire.
- Independent and agnostic
- Evidence-driven analysis
- Clear, actionable recommendations
- Senior attention, end to end
The challenge
Security decisions are already being made — by default.
Plenty of companies have security tools and a capable team, but no one senior enough to set direction, weigh risk against the business and answer for it to the board. Without that judgement, spending drifts towards whatever is loudest, real exposure goes unowned, and the board is asked to approve a programme no one can explain. A full-time CISO solves it — at a cost and scarcity many companies cannot justify.
What I do
Direction, oversight and accountability.
The judgement to set priorities, say no to noise, and report risk in terms the board can act on.
How I workSecurity Strategy
A risk-based plan aligned to the business, not a checklist.
Risk Reviews
Regular, evidence-led reviews of exposure and progress.
Board Reporting
Clear reporting that stands up to scrutiny.
Roadmap & Vendors
Keep the programme and its suppliers on track.
Incident Oversight
A steady hand when something goes wrong.
Team Mentoring
Level up the people already in place.
My approach
A steady cadence, sized to your company.
I baseline the environment, set direction, and stay accountable for it.
Explore my method- 01
Baseline
Understand the business, the risk and what already exists.
- 02
Direct
Set strategy, priorities and the reporting cadence.
- 03
Oversee
Review risk, manage roadmap and vendors, report to the board.
- 04
Respond
Provide oversight when incidents occur.
- 05
Renew
Annual renewal, 60 days’ notice, sized to you.
- A single owner for security risk, accountable to the board.
- A risk-based plan that decides what gets done — and what deliberately does not.
- Reporting the board can understand, challenge and act on.
- A steadier hand on suppliers, roadmap and incidents as they arise.
Case study
Security governance (vCISO) for an asset management firm
A vCISO engagement that brought structure and risk-based priorities to an asset management firm, with board reporting that turns security into a business decision.
Read the case study
Work & insights
What I’ve done
GovernanceFrom directive to board plan: decisions you can approve
Turning NIS2 and CRA into something a board can understand, approve and fund: gap assessment, costed roadmap, reporting.9 Dec 2025 · 4 min read
GovernanceThe vCISO: when security leadership on retainer makes sense
Governance, risk-based priorities and board reporting, without a full-time hire.20 Jan 2026 · 4 min read
GovernanceWhat the board should actually ask whoever leads security
A thirty-slide technical report is not oversight. A few right questions, asked regularly, are.10 Mar 2026 · 1 min read
Frequently asked
Questions I get asked.
How is the vCISO engagement structured?
As a monthly retainer, sized to your company, with an agreed cadence of direction, oversight and board reporting. It renews annually and you always know the cost in advance.
Will you replace our existing team?
No. The role is to lead and support the people already in place — setting priorities, mentoring and giving them senior cover — not to displace them.
How much of your time do we get?
Enough to hold the role properly at your scale. I agree the cadence up front, so oversight is regular and predictable rather than present only during a crisis.
Who actually does the work?
The advisor who scopes the engagement holds it. Where a specific problem needs specialist depth, a selected network is brought in — never a hand-off to junior staff.
Ready to start?
Let’s talk about your case.
Every situation is unique. Tell me the context and I’ll help you define the best approach.
Book a consultation