Virtual CISO
A named senior practitioner at an agreed number of days per month: strategy, roadmap, architecture decisions, board and audit-committee reporting, and being the person accountable when something goes wrong.
Managed Services
A capable CISO in India costs upwards of ₹50 lakh a year, takes six months to hire, and most organisations that need one do not need them full time. They need them a few days a month, consistently, for years.
Most mid-sized organisations sit in an awkward position. Security has become a real obligation — customers audit them, regulators expect documented controls, insurers ask questions — but the volume of work does not justify a full-time senior hire, and the person currently holding it is an infrastructure lead who inherited security along with the backup rota.
That arrangement fails in a specific way. The technical work gets done, more or less. What does not happen is the part that requires seniority: deciding what not to do, saying no to a project that introduces unacceptable risk, presenting a coherent position to a board, and holding a multi-year programme together across changing priorities. Those are the parts that need someone who has done it before.
A virtual CISO engagement provides exactly that, at a defined number of days a month. Not a helpdesk, not an anonymous pool — a named senior practitioner who learns your organisation, owns the security roadmap, attends the meetings that matter and is accountable for the programme. Alongside it, we run the operational work continuously: vulnerability management, compliance monitoring and reporting, on the platform, so the strategic time is spent on decisions rather than on assembling status.
Coverage
Assembled to fit. Most clients take vCISO plus continuous vulnerability management, and add compliance operations when a certification is in play.
A named senior practitioner at an agreed number of days per month: strategy, roadmap, architecture decisions, board and audit-committee reporting, and being the person accountable when something goes wrong.
Scanning, triage, prioritisation and chasing to closure — including the chasing, which is the part that actually determines whether anything gets fixed.
Continuous external discovery with same-day alerting on new exposure, run as a managed service rather than a dashboard you have to remember to open.
Control monitoring, evidence collection, internal audit scheduling and surveillance-audit readiness maintained continuously.
Vendor assessment, questionnaire handling and ongoing monitoring of the suppliers who are part of your attack surface whether or not you assess them.
Your customers’ security reviews answered by us, which for a growing SaaS business quietly consumes an enormous amount of engineering time.
A defined response commitment, agreed escalation paths and a team who already knows your environment before the day it matters.
A monthly pack in business language, with the trend lines a board needs to see rather than a count of tickets.
Approach
Monthly subscription, three-month minimum, reviewed quarterly. Scaled up or down as your position changes.
Two to three weeks establishing where you actually are — technical posture, obligations, team capability and what leadership is worried about.
A prioritised twelve-month roadmap with costs and owners, agreed with leadership so the programme has a mandate rather than an opinion.
Continuous vulnerability management, monitoring and compliance operations, running on the platform from day one.
Scheduled vCISO days each month: architecture and project reviews, decisions, supplier conversations and internal escalation.
A monthly pack for leadership and a quarterly review against the roadmap, with the programme adjusted where reality has moved.
When something happens, you call a team that already knows your environment, your suppliers and your escalation path.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
The same person every month, who knows your environment and can be reached without a ticket.
Costed, prioritised and reviewed quarterly against what actually happened.
Posture, trend, incidents, progress and decisions required — written for a board, not for an engineer.
SemperWise One™ access for your team, so status is available without asking anyone.
We handle security questionnaires and sit in audits so your engineers can keep building.
Is this for you?
If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.
Book a scoping callHow we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
The senior work that a security programme needs and that technical staff cannot do from their position: setting strategy, deciding what not to spend money on, making architecture and risk decisions, presenting to boards and audit committees, handling regulators and enterprise customers, and holding a multi-year programme on course. It is a leadership role delivered part-time, not an outsourced engineer.
Two to four days a month suits most organisations between 50 and 500 people in a steady state. During a certification programme or immediately after an incident it is usually higher for a period. We would rather start at the right level and adjust than sell you a large retainer you do not use — the quarterly review exists to have that conversation honestly.
Yes. A named senior practitioner is assigned and stays with the account, with a second person briefed for continuity during leave. The entire value of the model rests on someone who knows your organisation well enough to make judgement calls, which is impossible from a rotating pool.
Yes, and that is the normal arrangement. We do not replace your IT function or your managed service provider — we set the direction, define the requirements and verify that what was supposed to happen actually happened. Most clients find the verification layer is what was missing: the work was being done, but nobody independent was checking the outcome.
Three months, then monthly. Three months is roughly the point at which the assessment and roadmap are complete and the operational work is running, so a shorter engagement would mean paying for the setup and leaving before the value arrives.
We provide continuous automated monitoring with same-day alerting on critical findings, and an incident response retainer with a defined response commitment. We are honest that we are not a 24/7 staffed SOC — where a client genuinely needs round-the-clock human eyes, we help select and manage a specialist provider and act as the client-side technical authority over them, which is usually a better arrangement than buying it from the same firm that reports on it.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.