Essential
$7,600/mo
10 hours / month
Strategy calls, risk register, policy reviews, and a compliance roadmap.
Small–mid companies starting their program.
Fractional leadership
CISO-level expertise on a flexible retainer. We build and mature your security program, guide compliance, and report to leadership — at a fraction of a $250k+ salary.
Book a vCISO assessmentWhat you get
Monthly advisory sessions and quarterly executive-ready updates your leadership can act on.
Risk registers, policy development, and roadmaps for SOC 2, ISO 27001, and PIPEDA.
We deploy and tune Eramba as your GRC hub — controls, audits, assets, and compliance tracking in one place.
Third-party risk programs, IR planning, and tabletop exercises when you need them.
AWS Well-Architected reviews, Zero Trust direction, and team mentoring as you grow.
We help you navigate policy applications, coverage gaps, and insurer questionnaires — so you qualify and stay covered.
Advisory & consulting
Need depth in a specific domain? We take on targeted advisory and consulting gigs alongside — or independent of — a vCISO engagement.
GRC platform
Open-source Eramba gives SMEs enterprise-grade GRC without six-figure licensing. We handle installation, framework mapping, control libraries, and workflows so your team can run audits and track remediation — not wrestle with spreadsheets.
Ideal fit
Former CISOs and security leaders with 15+ years in finance, healthcare, and energy. Fixed monthly fees, 3-month minimum, scale up or down as your program matures.
Engagement tiers
Billed in advance · 3-month minimum
$7,600/mo
10 hours / month
Strategy calls, risk register, policy reviews, and a compliance roadmap.
Small–mid companies starting their program.
$14,000/mo
20 hours / month
Full vCISO leadership, board reporting, vendor risk, and IR planning.
Growing SaaS, fintech, and tech-forward SMEs.
$23,600+/mo
40 hours / month
Embedded leadership, SOC 2 / ISO support, mentoring, and pentest coordination.
Larger or regulated organizations.
Add-ons: security awareness training, tabletops, cloud security reviews, and blended implementation retainers.
Book a free assessment — we'll give you an honest fit check, even if we're not the right match.