Security & Compliance
vCISO retainer
Part-time security leadership for companies that need the function but not the salary.
Who it is for
Scale-ups and mid-market.
Everything below is in the scope document, written and priced before anything starts. If something you need is not on this list, say so and it goes in the quote — or we tell you it does not belong in this engagement.
- Security roadmap owned and reported against
- Customer security questionnaires and audits handled
- Incident response readiness and tabletop exercises
- Vendor security review before you sign
- Board-level reporting in language the board can act on
Also in Security & Compliance
ISO 27001 implementationThe information-security certification European RFPs treat as table stakes.12–16 weeksSOC 2 readinessFor material US enterprise deals. Roughly 70–80% of the controls overlap with ISO 27001.9–14 months including observationDPDP Act complianceIndia's Digital Personal Data Protection Act, applied to systems you already run.3–8 weeksGDPR & data-protection advisoryFor EU customers and EU data, including the transfer mechanism question.3–8 weeks
Next step
Thirty minutes on whether this is the right engagement.
If a different service on this list fits better, or if you do not need us at all, that is what the call will conclude.