Virtual CISO (vCISO)

Security leadership for your business, without a full-time executive hire

A virtual CISO (vCISO) gives you an experienced security leader on a part-time, ongoing basis, who knows your environment, sets direction, and stays accountable for the program over time.

Overview

What a vCISO does for your business

A Chief Information Security Officer (CISO) owns an organization's security program: deciding what to protect, setting policy, managing risk, and answering to leadership, auditors and insurers when questions come up. Most small and mid-sized businesses need that leadership but don't need, or can't justify, a full-time executive.

A virtual CISO (vCISO) fills that role on a part-time, ongoing basis. Dominant-IT's vCISO service gives you an experienced security leader who knows your environment, sets direction, and stays accountable for the program over time.

Who it's for

Leadership for businesses with or without an IT team

Businesses without a security lead

Security decisions fall to the owner, the office manager or whoever handles IT, and nobody owns the overall program.

Businesses with an existing IT team

Your internal staff or IT provider handles day-to-day operations; the vCISO adds strategy, governance and oversight alongside them.

What's included

A security program, run by a security leader

Security program and roadmap

An assessment of where your security stands today and a prioritized plan for where it should go, with the reasoning, cost and business impact of each step explained in plain terms.

Policies

Written security policies that reflect how your business actually operates: acceptable use, access control, incident response, data handling and the other policies auditors, insurers and customers ask to see.

Risk assessments

Identifying the risks that matter most to your business, how likely and costly they are, and what to do about them.

Compliance oversight

Guidance and oversight for the frameworks your business answers to. We work with HIPAA, PCI DSS, SOC 2 readiness and NIST 800-53. A vCISO helps you build and maintain the program; compliance remains a shared responsibility that also depends on your people and processes.

Vendor risk

Evaluating the security of the vendors and service providers who handle your data or have access to your systems.

Board and insurance reporting

Clear reporting on your security posture for owners, boards and cyber insurance carriers, including help with insurance security questionnaires.

Incident response leadership

When something goes wrong, your vCISO leads the response: coordinating containment, communication and recovery. Dominant-IT can handle incident response from start to finish, and for larger organizations works alongside the incident response vendors assigned by a cyber insurance carrier.

Who you'll work with

Your vCISO holds the following certifications

Training includes SANS FOR500 (digital forensics and incident response) and SANS SEC411, with SANS SEC530 (defensible security architecture) in progress.

  • Certified Information Systems Security Professional (CISSP)
  • Microsoft Certified Systems Engineer (MCSE)
  • Microsoft Certified IT Professional: Enterprise Administrator
  • Azure Security Engineer Associate
  • Red Hat Certified System Administrator (RHCSA)
  • CompTIA A+

Pricing

How it's priced

vCISO services are provided on a monthly retainer. The scope and retainer are set with each client, based on the size of your organization, your compliance requirements and how involved you want your vCISO to be.

FAQ

vCISO frequently asked questions

What is a vCISO?
A virtual Chief Information Security Officer: an experienced security leader who runs your security program on a part-time, ongoing basis instead of as a full-time employee.
Do we need a vCISO if we already have IT support?
IT support keeps systems running. A vCISO decides what your security program should be, sets policy, manages risk and reports to leadership. Many businesses use both, and the vCISO works alongside your existing IT team or provider.
Can a vCISO help with HIPAA or PCI DSS?
Yes. A vCISO provides compliance oversight, policies and risk assessments for frameworks such as HIPAA, PCI DSS, SOC 2 readiness and NIST 800-53. Compliance still depends on your policies, people and processes.
How much does a vCISO cost?
Dominant-IT's vCISO service is a monthly retainer, scoped with each client based on size, compliance needs and level of involvement.
Can a vCISO help with cyber insurance?
Yes. Your vCISO can report on your security posture to insurers and help with the security questionnaires carriers require.

Talk to us about vCISO services

Tell us about your business, the frameworks you answer to, and who handles security today. We'll talk through whether a vCISO makes sense for you and what the engagement would look like. Or email contact@dominant-it.com.