[ VIRTUAL CISO ]

Virtual CISO

Companies between 50 and 500 people need a CISO function but rarely need a full-time hire. Our vCISO retainer gives you strategic security leadership, compliance roadmap ownership, and board-ready reporting — without the €200k+ salary line.

What’s included

The CISO role, served as a retainer

Senior security leadership without the full-time cost. We act as your CISO — in board meetings, in vendor reviews, in incident escalations, in compliance audits.

Security Roadmap

Annual security strategy aligned with your business objectives. Quarterly reviews, monthly adjustments. Roadmap that survives auditor scrutiny.

Risk Register Ownership

Living risk register maintained on your behalf. Severity-ranked, mitigation-tracked, treatment-justified. Ready for any ISO 27001 or SOC 2 audit.

Incident Response Leadership

When something happens, you call us. Tabletop exercises quarterly. Real incident playbooks. Coordinated response when it matters.

Policy & Compliance

Information security policy suite, acceptable use, vendor management, data classification — authored and maintained on a documented review cadence.

Board-Ready Reporting

Monthly security report for the leadership team and quarterly briefing for the board. Plain-English, executive-ready, no jargon dump.

Vendor & Procurement Review

Security review of new vendor contracts, DPAs, data-sharing arrangements. We sign off on the security questionnaires your sales prospects send you, too.

Pen testing without a strategy is just findings on a PDF

The vCISO retainer pairs naturally with our penetration testing service: pen testing identifies the technical vulnerabilities, the vCISO retainer owns turning them into a prioritised remediation programme, governance, and audit evidence. Most clients run both as one engagement.

Bundled pricing: vCISO + monthly pen testing scans from €3,500/month total — cheaper than either alone and significantly cheaper than the €15k+/month all-in-one MDR services.

Why us

Built around the things other agencies get wrong

Every promise on this block is grounded in something we kept hearing customers complain about elsewhere. We picked the opposite as our default.

Continuous, not project-then-abandon

Agent-managed workflows handle the daily and weekly work. You see results in plain language every week — not "we’ll check in at the end of the quarter."

One senior strategist, no rotation

Your engagement is owned by one senior person from day one. No bait-and-switch to a junior team after the contract is signed. No reassignments every few months.

Transparent pricing, no lock-in

Every price is on our pricing page. Month-to-month after the initial term. 30-day cancellation. No renewal surprises, no "inflation adjustment," no exit interview.

You own everything we produce

Code, data, playbooks, architecture decisions — all documented and handed over. We’re here to make ourselves useful, not indispensable.

READY · AWAITING INPUT

CISO-level guidance, retainer-priced

From €3,000/month. Tell us about your business and your compliance goals — we’ll come back with a tailored scope.

Contact us →    Penetration Testing →

AGENT-CHAT
System: Sichere Verbindung hergestellt. Warte auf Eingabe...