vCISO · CISO as a Service

Virtual CISO (vCISO): cybersecurity leadership as a service for companies

Hard2bit's virtual CISO takes on the leadership of your cybersecurity part-time: sets the strategy, governs risk, brings order to NIS2, DORA, ENS and ISO 27001 compliance, and reports to management with indicators. You get the judgement of a senior CISO, backed by a full team, without the cost of a full-time hire.

Commitment from
2 days/month
Work plan
90 days · 12 months
Certified to
ENS HIGH · ISO 27001

No obligation · First conversation with the person who will lead the service.

Definition

What is a virtual CISO and what does it do?

A virtual CISO (vCISO), also known as a fractional CISO or CISO as a Service, is an external chief information security officer who performs the role part-time. It is not a consultant who hands over a report and leaves: the vCISO takes on the leadership of the security programme, makes decisions with management and answers for the results.

The work is not primarily technical but about governance: deciding what gets protected first, with what budget, who is accountable for each control and how it is demonstrated to an auditor, a customer or a regulator.

Strategy and roadmap

Turns business objectives into a security programme with priorities, budget and owners.

Governance and board reporting

Security committee, indicators and a report that management understands and can use to decide.

Risk management

A living risk register, an agreed risk appetite and treatment plans that are actually tracked.

Compliance and audits

Leads alignment with NIS2, DORA, ENS or ISO 27001 and fronts the conversation with auditors, customers and regulators.

Third parties and supply chain

Onboarding criteria, contract clauses and monitoring of critical suppliers, SaaS and cloud.

Incident readiness

Response plan, tabletop exercises and coordination with SOC, legal, communications and continuity.

Fit

When a vCISO makes sense, and when it does not

A vCISO works when there are decisions to make and someone willing to make them. If your need is a different one, we will tell you in the first conversation.

It fits if…

  • You need someone to lead security, but a full-time CISO is not yet justified by size or budget.
  • NIS2, DORA, ENS or a strategic customer demands governance, accountable owners and evidence, and nobody in-house holds that mandate.
  • You have an IT team and security vendors, but nobody to prioritise, coordinate and answer to management.
  • Your CISO needs capacity: a support office that absorbs risk, third parties, metrics and documentation.
  • Your CISO has left or is on leave and the function cannot sit vacant while the role is filled.
  • You are facing an audit, due diligence or a funding round and need a defensible programme.

Probably not, if…

  • You need hands, not leadership

    If what is missing is someone to deploy and operate controls, a managed service such as managed SOC or vulnerability management fits better.

  • You only need a one-off snapshot

    For a single assessment, cybersecurity consulting or the regulatory assessment gets you there sooner and with less commitment.

  • Management will not get involved

    A vCISO with no access to decision-makers turns into a report generator. If sponsorship is missing, it is worth securing it before starting.

  • You already justify a full-time in-house CISO

    In large or heavily regulated organisations, the right answer may be your own CISO with a support office. We analyse it in in-house CISO vs vCISO.

Engagement models

Four ways to have an external CISO

The function is the same; what changes is the commitment and who keeps the leadership. You can move from one model to another as the organisation matures.

Fractional vCISO

From 2 days/month

Recurring cybersecurity leadership with a fixed monthly commitment. The vCISO leads the programme, chairs the security committee and reports to management.

  • For companies without their own CISO
  • 90-day and 12-month plan
  • Commitment adjustable every quarter

CISO support office

Tailored commitment

An external team that gives your CISO capacity: risk, third parties, metrics, documentation, audit preparation and action-plan follow-up.

  • Your CISO stays in charge
  • GRC, technical and continuity profiles
  • Extra capacity at peaks: audits, incidents, projects

Interim CISO

3–9 months

Cover for the function during a departure, leave or transition, with an orderly handover to the incoming CISO. The organisation loses neither governance nor pace.

  • On board in days, not months
  • Continuity of committees and commitments
  • Support with recruitment and handover to the new CISO

Framework-bound vCISO

Project duration

Programme leadership during a specific compliance effort —NIS2, DORA, ENS or ISO 27001—, with a planned exit or a move to the fractional model at the end.

  • One clear owner before auditor and regulator
  • Reuses controls across frameworks
  • Coordinated with our GRC team

Getting started

The first 90 days with a vCISO

Value has to show early. This is the usual start-up calendar, with concrete deliverables at each stage.

  1. Weeks 1–2

    Understand the business

    • Kick-off with management and business objectives
    • Map of assets, processes and critical dependencies
    • Rapid maturity and exposure assessment
  2. Month 1

    Put risk in order

    • Risk register and initial treatment plan
    • 90-day roadmap with quick wins
    • Indicators (KPIs and KRIs) and reporting calendar
  3. Months 2–3

    Get the programme running

    • 12-month roadmap with budget, milestones and owners
    • Security committee up and running, with a RACI matrix and change and exception management
    • Essential policies (access, suppliers, incidents, continuity) and Statement of Applicability (SoA) where relevant
    • Third-party management model and incident response plan

Governance

Working cadence and reporting to management

After the first 90 days the service settles into a steady rhythm. Security stops depending on emergencies and gains a calendar, owners and metrics.

Frequency What happens What the organisation gets
Weekly Operational follow-up with IT and vendors Actions unblocked and new risks identified
Monthly Security committee Decisions, priorities and action-plan status
Quarterly Report to management or the board Indicators, risk trend and investment needs
Yearly Strategy and budget review Updated roadmap and objectives for the coming year
On demand Incidents, audits, customers and regulators Expert representation whenever the organisation needs it

Indicators the management report usually includes

They are agreed with management in the first month and kept stable so that progress is comparable. Few, measurable and tied to decisions.

  • Time to close critical vulnerabilities against the agreed SLA
  • MFA and privileged access management (PAM) coverage
  • Critical suppliers assessed and third-party risks open versus mitigated
  • Treatment plan progress and residual risk by area
  • Mean time to detect and to respond to incidents
  • Awareness: training completed and phishing simulation results

Regulatory fit

The vCISO and NIS2, DORA, ENS and ISO 27001

Every framework agrees on the essentials: security needs an accountable owner, a method and evidence. The vCISO meets that requirement and avoids duplicated effort when several apply at once.

NIS2

Article 20 makes management bodies responsible for approving and overseeing risk-management measures. The vCISO gives them the judgement, the programme and the evidence to exercise that responsibility.

NIS2 service →

DORA

Articles 5 and 6 require an ICT risk management framework governed by the management body. The vCISO structures it, maintains it and defends it before the supervisor.

DORA service →

ENS

Spain's Royal Decree 311/2022 requires differentiated roles, including a security officer. The vCISO sets up that role model and leads alignment and its upkeep.

ENS service →

ISO/IEC 27001

The standard (2022 edition, with Amendment 1:2024) calls for leadership, roles and continual improvement. The vCISO acts as ISMS owner before the certification audit and surveillance audits.

ISO/IEC 27001 service →

Formal appointment of the vCISO as the designated security officer is assessed case by case, depending on the framework and the organisation. In every scenario, ultimate accountability rests with the management body.

Experience

Why entrust your security leadership to Hard2bit

We have sat on the audited side

Hard2bit operates certified to Spain's ENS (HIGH category) and ISO 27001, 22301, 20000-1, 9001 and 14001. We run our own management system and defend it every year before accredited auditors.

A vCISO with a team behind them

You are not hiring a lone individual. Behind the vCISO are specialists in GRC, SOC, offensive security, forensics and continuity, called in whenever the programme requires it.

An auditor's judgement

The service is led by an ISO 27001:2022 Lead Auditor (CQI IRCA). We know what an auditor or regulator will ask for because we know the standard from the inside.

Working with regulated companies since 2013

More than a decade supporting organisations in finance, manufacturing, healthcare, technology and the public sector across Spain, Europe and Latin America.

Planning

Commitment and cost of a virtual CISO

The service is sized in days per month or per project, and reviewed every quarter. You start with what you need today and scale up only if the programme calls for it.

Indicative commitment

Essential guidance
2 days/month
SMEs and scale-ups that need governance, a plan and an expert counterpart.
Ongoing leadership
4–6 days/month
Regulated mid-sized companies or those working towards a framework.
Support office · interim
8+ days/month, or per project
Organisations with their own CISO, a vacant function or several frameworks at once.

Essential guidance starts at €1,500 per month (two days a month, VAT not included). From there it is adjusted according to days, commitment and scope, or quoted per project.

What it depends on

  • Monthly commitment and length of the engagement.
  • Size, spread and technological complexity of the organisation.
  • Applicable frameworks and starting maturity.
  • Representation required: committee, board, auditors, customers or regulator.
  • Need for supporting profiles (GRC, technical, continuity).
Request a proposal

Comparison

vCISO versus in-house CISO

vCISOIn-house CISO
CommitmentPart-time and adjustableFull-time
Time to startDays or a few weeksMonths of recruitment and onboarding
Breadth of experienceSeveral sectors and frameworks, with a team behindDeep within the organisation itself
CostVariable, according to commitmentSalary, employer costs and structure
Best fitSMEs, mid-sized companies, transition or reinforcementLarge organisations and heavily regulated environments

Compared costs, hybrid models and common mistakes in the decision, in the full comparison: in-house CISO vs external vCISO.

Virtual CISO frequently asked questions

What is a virtual CISO (vCISO) and when does it make sense?
A virtual CISO is an external chief information security officer who takes on, part-time, the organisation's security strategy, governance and risk management. It makes sense when you need senior leadership and a measurable programme without yet hiring a full-time CISO.
We are a mid-sized company with no security lead and NIS2 applies to us: is a vCISO right for us?
It is one of the cases where it adds the most value. NIS2 makes management responsible for approving and overseeing risk-management measures; the vCISO provides the expert judgement, structures the programme and produces the evidence. You can first check what applies to you with the regulatory assessment.
How many days a month should we contract?
It depends on maturity and urgency. The usual pattern is a somewhat more intensive start during the first 90 days, followed by a steady commitment of 2 to 6 days a month for committee, follow-up and continual improvement. Commitment is reviewed every quarter.
How much does a virtual CISO service cost?
It depends on the commitment. Essential guidance starts at €1,500 per month for two days a month; from there it is adjusted according to days, applicable frameworks and scope, or quoted per project. In every case it is a fraction of the cost of an equivalent in-house CISO.
Can the vCISO be formally appointed as the designated security officer?
It is assessed case by case, depending on the framework and the organisation. In some scenarios the vCISO takes on the appointment within the scope set out in the contract; in others, the formal officer should be internal, with the vCISO providing direction and support. Ultimate accountability remains with the management body.
We already have a CISO: what does a CISO support office add?
Capacity. The CISO keeps the leadership and the office absorbs the work that eats up their calendar: risk register, third-party assessments, metrics, documentation, audit preparation and action-plan follow-up, with extra reinforcement at peak times.
What is the difference between a vCISO and one-off consulting?
Consulting delivers a diagnosis and recommendations. The vCISO takes on leadership: prioritises, coordinates, measures and is accountable; turns recommendations into execution and into governance decisions sustained over time.
Does the vCISO work with our IT team and SOC, or replace them?
Works with them. The vCISO sets objectives, indicators and service levels, and coordinates vendors —SOC or MDR, incident response, cloud— so that everything answers to a single programme. It does not replace IT or security operations.
What deliverables do we receive, and how often?
In the first 90 days: maturity assessment, risk register, 90-day and 12-month roadmap, indicators and a working security committee. After that, monthly committee minutes, a quarterly report to management and a yearly strategy and budget review.
Does it include NIS2, DORA, ENS or ISO 27001 compliance and the evidence?
It includes compliance governance: what applies, who is accountable, what evidence is needed and how it is maintained. When full documentary implementation or certification readiness is required, we integrate it as a project with our Compliance and GRC team.
What happens if we suffer an incident during the engagement?
The vCISO coordinates the response: activates the plan, organises communication with management, legal and third parties, and assesses notification obligations. Containment and forensics are carried out by the incident response team, yours or Hard2bit's.
Do you provide virtual CISO services in Spain and across Europe?
Yes. The team works from Madrid for organisations across Spain, the rest of Europe and Latin America. The service combines remote work with on-site presence at committees, management sessions and audits when it adds value.
Where does the vCISO sit within Hard2bit's services?
It belongs to the Managed security practice, alongside the managed SOC and vulnerability management, and works hand in hand with Compliance and GRC. It is the leadership layer that gives direction and priority to the other services.

Concepts from our cybersecurity glossary that connect directly with this service.

Cybersecurity leadership, from the first month

Tell us about your situation. In a first conversation with the person who will lead the service we assess fit, engagement model and commitment, and send you a clear proposal.

Written by Adrián González · Reviewed by Thilina Manana, service owner

Last reviewed: