Managed Services

Security leadership without the hiring problem.

A capable CISO in India costs upwards of ₹50 lakh a year, takes six months to hire, and most organisations that need one do not need them full time. They need them a few days a month, consistently, for years.

Monthly posture 78 posture Critical 2 High 6 Medium 14 Low 23 Reviewed with a named practitioner each month
NamedSenior practitioner
MonthlyFixed subscription
ContinuousVulnerability management
BoardReady reporting

The gap between "somebody in IT" and a full-time CISO

Most mid-sized organisations sit in an awkward position. Security has become a real obligation — customers audit them, regulators expect documented controls, insurers ask questions — but the volume of work does not justify a full-time senior hire, and the person currently holding it is an infrastructure lead who inherited security along with the backup rota.

That arrangement fails in a specific way. The technical work gets done, more or less. What does not happen is the part that requires seniority: deciding what not to do, saying no to a project that introduces unacceptable risk, presenting a coherent position to a board, and holding a multi-year programme together across changing priorities. Those are the parts that need someone who has done it before.

A virtual CISO engagement provides exactly that, at a defined number of days a month. Not a helpdesk, not an anonymous pool — a named senior practitioner who learns your organisation, owns the security roadmap, attends the meetings that matter and is accountable for the programme. Alongside it, we run the operational work continuously: vulnerability management, compliance monitoring and reporting, on the platform, so the strategic time is spent on decisions rather than on assembling status.

Coverage

What the service includes

Assembled to fit. Most clients take vCISO plus continuous vulnerability management, and add compliance operations when a certification is in play.

Virtual CISO

A named senior practitioner at an agreed number of days per month: strategy, roadmap, architecture decisions, board and audit-committee reporting, and being the person accountable when something goes wrong.

Continuous vulnerability management

Scanning, triage, prioritisation and chasing to closure — including the chasing, which is the part that actually determines whether anything gets fixed.

Attack surface monitoring

Continuous external discovery with same-day alerting on new exposure, run as a managed service rather than a dashboard you have to remember to open.

Compliance operations

Control monitoring, evidence collection, internal audit scheduling and surveillance-audit readiness maintained continuously.

Third-party risk

Vendor assessment, questionnaire handling and ongoing monitoring of the suppliers who are part of your attack surface whether or not you assess them.

Security questionnaire response

Your customers’ security reviews answered by us, which for a growing SaaS business quietly consumes an enormous amount of engineering time.

Incident response retainer

A defined response commitment, agreed escalation paths and a team who already knows your environment before the day it matters.

Executive and board reporting

A monthly pack in business language, with the trend lines a board needs to see rather than a count of tickets.

Approach

How the engagement works

Monthly subscription, three-month minimum, reviewed quarterly. Scaled up or down as your position changes.

  1. 01 · Assess

    Two to three weeks establishing where you actually are — technical posture, obligations, team capability and what leadership is worried about.

  2. 02 · Plan

    A prioritised twelve-month roadmap with costs and owners, agreed with leadership so the programme has a mandate rather than an opinion.

  3. 03 · Operate

    Continuous vulnerability management, monitoring and compliance operations, running on the platform from day one.

  4. 04 · Lead

    Scheduled vCISO days each month: architecture and project reviews, decisions, supplier conversations and internal escalation.

  5. 05 · Report

    A monthly pack for leadership and a quarterly review against the roadmap, with the programme adjusted where reality has moved.

  6. 06 · Respond

    When something happens, you call a team that already knows your environment, your suppliers and your escalation path.

Run against recognised standards

  • ISO 27001Programme structure
  • NIST CSFMaturity measurement
  • CIS ControlsPrioritised technical baseline

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

A named practitioner

The same person every month, who knows your environment and can be reached without a ticket.

Twelve-month security roadmap

Costed, prioritised and reviewed quarterly against what actually happened.

Monthly leadership pack

Posture, trend, incidents, progress and decisions required — written for a board, not for an engineer.

Live posture dashboard

SemperWise One™ access for your team, so status is available without asking anyone.

Audit and customer support

We handle security questionnaires and sit in audits so your engineers can keep building.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • Security is somebody’s second job and it is not going well.
  • You need a CISO for board and customer credibility but not for forty hours a week.
  • You are certified and cannot sustain the programme between audits.
  • Enterprise security questionnaires are consuming your engineering team.
  • You have tooling nobody has time to operate.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

Managed Security & vCISO — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

What does a virtual CISO actually do?

The senior work that a security programme needs and that technical staff cannot do from their position: setting strategy, deciding what not to spend money on, making architecture and risk decisions, presenting to boards and audit committees, handling regulators and enterprise customers, and holding a multi-year programme on course. It is a leadership role delivered part-time, not an outsourced engineer.

How many days a month do we need?

Two to four days a month suits most organisations between 50 and 500 people in a steady state. During a certification programme or immediately after an incident it is usually higher for a period. We would rather start at the right level and adjust than sell you a large retainer you do not use — the quarterly review exists to have that conversation honestly.

Is it the same person every month?

Yes. A named senior practitioner is assigned and stays with the account, with a second person briefed for continuity during leave. The entire value of the model rests on someone who knows your organisation well enough to make judgement calls, which is impossible from a rotating pool.

Can you work with our existing IT team or MSP?

Yes, and that is the normal arrangement. We do not replace your IT function or your managed service provider — we set the direction, define the requirements and verify that what was supposed to happen actually happened. Most clients find the verification layer is what was missing: the work was being done, but nobody independent was checking the outcome.

What is the minimum commitment?

Three months, then monthly. Three months is roughly the point at which the assessment and roadmap are complete and the operational work is running, so a shorter engagement would mean paying for the setup and leaving before the value arrives.

Do you provide 24/7 monitoring?

We provide continuous automated monitoring with same-day alerting on critical findings, and an incident response retainer with a defined response commitment. We are honest that we are not a 24/7 staffed SOC — where a client genuinely needs round-the-clock human eyes, we help select and manage a specialist provider and act as the client-side technical authority over them, which is usually a better arrangement than buying it from the same firm that reports on it.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.