Named vCISO

Powered by ValueMentor

Virtual CISO Services

Get the cybersecurity leadership of a Virtual CISO combined with Secusy vCISO Portal, powered by OneCSF. Manage cybersecurity strategy, risks, controls, policies, compliance requirements, evidence, action plans and executive reporting from one place — with an experienced vCISO helping keep the program moving.

Choose how much ownership you want us to take.

  • vCISO Advisory

    You run the program. We guide you.

  • vCISO Executive

    We act as your outsourced cybersecurity leadership function.

Powered by ValueMentor.

Named vCISOIncluded on every plan
GRC platformOneCSF included on every plan
Minimum engagement6 months
Delivered byValueMentor

The definition

What is a Virtual CISO (vCISO)?

A Virtual CISO, or vCISO, provides cybersecurity leadership to an organization on an outsourced or fractional basis — without the cost of hiring a full-time Chief Information Security Officer. A Secusy vCISO helps set cybersecurity strategy, prioritize risk, oversee controls and compliance activities, and report progress to management, working through the Secusy vCISO Portal and OneCSF rather than a loose collection of meetings and spreadsheets. The service is also referred to as Fractional CISO, Outsourced CISO or CISO as a Service.
The objective is not simply to produce documentation. It is to establish and operate a cybersecurity program that management can understand, govern and improve.
  • Risk Management

    Identifying and prioritizing threats based on your business context.

  • Compliance

    Guiding your team through SOC 2, ISO 27001, and HIPAA audits.

  • Reporting

    Executive dashboards and board-level security KPIs.

  • Strategy

    Aligning security investments with long-term business goals.

More Than a Fractional CISO

Traditional vCISO engagements can become a collection of meetings, spreadsheets, presentations and action lists.

Secusy takes a different approach.

Your cybersecurity program is managed through Secusy vCISO Portal, powered by OneCSF, giving your organization a central system for managing:

Your vCISO uses the same platform with your team, creating continuity between meetings and making security progress visible throughout the engagement.

  • Risk Management
  • OneCSF Control Management
  • Compliance Management
  • Evidence Management
  • Policy Management
  • Action Tracking
  • Security Roadmap
  • Vulnerability Visibility
  • Executive Reporting

One Security Program. Multiple Compliance Requirements.

Organizations increasingly need to address multiple cybersecurity and compliance requirements at the same time. You may have customers asking for SOC 2. Management may want ISO 27001. A regulator or business partner may require another cybersecurity framework.

Managing each requirement independently creates unnecessary duplication.

OneCSF is Secusy's approach to managing cybersecurity controls across multiple frameworks through a unified control structure, reducing duplication when several compliance requirements address similar security objectives.

Your vCISO helps identify the controls your organization needs, prioritize gaps, monitor implementation and track evidence through the Secusy platform.

Act once. Comply with many.

Security requirements frequently overlap. A policy, technical control or risk-management activity implemented for one framework may also support requirements in other frameworks. OneCSF helps organize those relationships so you can manage security as a single program rather than running independent compliance projects.

Compare vCISO plans

Choose how much ownership you want Secusy to take of your cybersecurity governance program. Pricing is confirmed with you directly before the engagement starts.

vCISO Advisory

You run the program. We guide you.

$1,499/month

Package scope
  • Scheduled vCISO meetings1/month
  • Minimum engagement6 months

Timeline depends on your readiness, scope complexity and team availability.

vCISO Executive

We act as your outsourced cybersecurity leadership function.

$5,999/month

Everything in vCISO Managed, plus
  • Scheduled vCISO meetingsWeekly
  • Minimum engagement6 months

Timeline depends on your readiness, scope complexity and team availability.

Full plan comparison

FeaturevCISO AdvisoryvCISO ManagedvCISO Executive
Price$1,499/month$2,999/month$5,999/month
Best forTeams that can execute but need security leadershipCompanies that want us to actively run the governance program with themCompanies that need an outsourced cybersecurity leadership function
Security roadmapAnnualActively maintainedContinuously managed
Scheduled vCISO meetings1/month2/monthWeekly
Risk registerCustomer maintained; vCISO reviewed quarterlyJointly managed; reviewed monthlyActively managed
OneCSF control trackingCustomer-ledJointly managedvCISO-led oversight
Evidence trackingCustomer-ledReviewed monthlyActively monitored
New/revised policiesTemplates + guidanceUp to 4/quarterUp to 8/quarter
Compliance program oversightAdvisoryActive oversightMulti-framework oversight
Security KPIsQuarterlyMonthlyMonthly
Executive reportQuarterlyMonthlyMonthly
Board/leadership presentation1/yearQuarterlyQuarterly/as agreed
Vendor security assessmentsGuidanceUp to 2/monthUp to 4/month
Customer security questionnairesGuidanceUp to 1/monthUp to 2/month
Security architecture reviewAdvisory
Security budget/planningGuidance
Incident response planningReviewDevelop/reviewDevelop/manage
Tabletop exerciseAdd-on1/year2/year
Ad-hoc security advisoryStandardPriorityExecutive priority
Minimum engagement6 months6 months6 months
DeliveryRemoteRemoteRemote
Secusy vCISO Portal
OneCSF GRC platform
Named vCISO
Initial cybersecurity maturity review
Cybersecurity strategy
Compliance mapping
Security policy review
Vulnerability management oversight
Security awareness platform

vCISO Advisory

Custom pricing

You run the program. We guide you.

vCISO Advisory is designed for organizations that already have people capable of executing cybersecurity activities but need experienced security leadership to determine priorities and provide direction.

Your internal team manages day-to-day activities through Secusy. Your vCISO reviews progress, challenges decisions, advises management and helps ensure your security program remains aligned with business risks and compliance priorities.

Best for: Organizations with an internal IT, security, compliance or engineering team that can execute the program.

This plan includes

  • Named vCISO
  • Secusy vCISO Portal
  • OneCSF GRC platform
  • Initial cybersecurity maturity review
  • Cybersecurity strategy
  • Annual security roadmap
  • Monthly vCISO meeting
  • Quarterly risk review
  • Quarterly security KPIs
  • Quarterly executive reporting
  • Annual board or leadership presentation
  • Policy templates and review
  • Compliance guidance
  • Vendor-risk guidance
  • Customer security-questionnaire guidance
  • Security architecture advisory
  • Vulnerability-management oversight
  • Incident-response-plan review
  • Security awareness platform

vCISO Executive

Custom pricing

Your outsourced cybersecurity leadership function.

vCISO Executive is designed for organizations that need someone to operate at the level of a senior cybersecurity leader without hiring a full-time CISO.

Your vCISO takes broader responsibility for coordinating cybersecurity governance across management, IT, engineering, compliance and external security providers. Secusy becomes the operating platform for the program, while your vCISO drives priorities, risk decisions, security planning, governance and executive communication.

Best for: Organizations that need a senior cybersecurity leadership function but do not yet require or want to recruit a full-time CISO.

This plan includes

  • Everything in Managed, plus:
  • Weekly scheduled vCISO meeting
  • Actively managed cybersecurity risk register
  • vCISO-led oversight of OneCSF controls
  • Continuous roadmap management
  • Active evidence monitoring
  • Multi-framework compliance oversight
  • Up to 8 new or substantially revised policies per quarter
  • Up to 4 vendor security assessments per month
  • Assistance with up to 2 customer security questionnaires per month
  • Quarterly board presentations or additional sessions as agreed
  • Annual cybersecurity budget planning
  • Two incident-response tabletop exercises per year
  • Coordination with relevant security vendors and internal stakeholders
  • Executive-priority cybersecurity advisory

The Secusy vCISO Portal

Your vCISO engagement is delivered through the Secusy platform. Instead of relying on spreadsheets and periodic presentations, you maintain an ongoing view of your cybersecurity program.

  • Risk Management

    Maintain cybersecurity risks, assess their significance, assign actions, identify owners and monitor treatment activities.

  • OneCSF Control Management

    Manage cybersecurity controls through OneCSF and map them across applicable frameworks, reducing duplication when multiple compliance requirements address similar security objectives.

  • Compliance Management

    Track requirements, gaps, controls, evidence and remediation activities across your applicable cybersecurity frameworks.

  • Evidence Management

    Maintain supporting security evidence so compliance activities are not rebuilt from scratch every time a customer, auditor or assessor asks for information.

  • Policy Management

    Track cybersecurity policies and identify when documents need to be created, reviewed or updated.

  • Action Tracking

    Assign cybersecurity activities to responsible individuals and monitor outstanding actions.

  • Security Roadmap

    Maintain visibility into planned cybersecurity initiatives, priorities and progress.

  • Vulnerability Visibility

    Where relevant Secusy services are enabled, vulnerability information can become part of the broader cybersecurity risk and governance process.

  • Executive Reporting

    Translate cybersecurity activity into business-level reporting covering risk, compliance, priorities and progress.

Compliance

Manage multiple frameworks with OneCSF.

Security requirements frequently overlap. A policy, technical control or risk-management activity implemented for one framework may also support requirements in other frameworks. OneCSF helps organize those relationships so you can manage security as a single program rather than running independent compliance projects.

  • ISO/IEC 27001

    Information security management

  • SOC 2

    Trust Services Criteria attestation

  • NIST Cybersecurity Framework

    Cybersecurity framework

  • PCI DSS

    Payment card data protection

  • HIPAA-related security requirements

    Healthcare privacy and security

  • HITRUST e1 / i1

    HITRUST assurance programs

  • Customer security requirements

    Contractual and questionnaire-driven controls

  • Other applicable cybersecurity and regulatory frameworks

    Additional frameworks as your program requires

Depending on your requirements, your program may include frameworks or standards such as those listed above. The applicable frameworks depend on your business, customers, jurisdiction and contractual obligations. Formal certification, attestation or audit activities are separate where required.

The platform helps establish, manage and oversee your cybersecurity and compliance program. Formal compliance, certification or attestation depends on the applicable framework, your implementation of required controls and, where necessary, assessment by an authorized auditor or assessor.

How it works

How the vCISO Service Works

  1. Step 1

    Choose Your Plan

    Select Advisory, Managed or Executive based on how much responsibility you want Secusy to take.

  2. Step 2

    Complete Digital Onboarding

    Tell us about your organization, technology environment, customers, regulatory requirements, security controls and current priorities.

  3. Step 3

    Meet Your Named vCISO

    A named vCISO is assigned to lead the engagement and becomes your primary point of contact for cybersecurity leadership and governance.

  4. Step 4

    Establish Your Secusy Workspace

    Your cybersecurity program is organized within the Secusy vCISO Portal and OneCSF. Relevant risks, controls, frameworks, actions and evidence are brought into the operating environment.

  5. Step 5

    Assess Your Current Position

    We review your security maturity, risks, compliance requirements, current controls and existing cybersecurity initiatives.

  6. Step 6

    Build Your Cybersecurity Roadmap

    Your vCISO establishes priorities based on business risk, customer requirements, compliance obligations and your current security maturity.

  7. Step 7

    Run the Program

    Risks, controls, compliance activities, policies, vulnerabilities, actions and reporting are managed through Secusy based on the service level you selected.

  8. Step 8

    Measure and Improve

    Your vCISO continuously reviews progress and helps adjust priorities as the organization, threat environment and business requirements change.

Who Is This For?

  • Startups and Scale-ups

    Build a credible cybersecurity program while preparing to sell to larger customers.

  • SaaS Companies

    Manage customer security requirements, SOC 2, ISO 27001 and broader security governance without building a large internal team.

  • Mid-Market Organizations

    Establish structured cybersecurity governance and management reporting.

  • Regulated Businesses

    Coordinate multiple security and compliance requirements through one cybersecurity program.

  • Companies Preparing for ISO 27001 or SOC 2

    Establish governance, risk management, policies, controls and management oversight before or alongside a formal certification or attestation project.

  • Organizations Without Dedicated Cybersecurity Leadership

    Give management an experienced cybersecurity leader who can coordinate security activities across internal and external teams.

Cybersecurity Leadership Backed by ValueMentor

Your named vCISO does not work in isolation.

Secusy is powered by ValueMentor, giving the vCISO access to broader cybersecurity expertise when specialist knowledge is required.

Your vCISO remains responsible for coordinating the security program while specialist services can be added where necessary.

  • Governance, risk and compliance
  • Penetration testing
  • Vulnerability management
  • Cloud security
  • Security architecture
  • Managed detection and response
  • Cybersecurity assurance
  • Compliance assessments

Included

What You Receive

Every Secusy vCISO customer receives the following. The frequency and level of hands-on management depend on the selected plan.

Every plan includes

  • A named vCISO
  • Secusy vCISO Portal access
  • OneCSF GRC capabilities
  • Initial cybersecurity maturity review
  • Cybersecurity strategy
  • Security roadmap
  • Risk-management oversight
  • Policy support
  • Compliance guidance
  • Security metrics
  • Executive reporting
  • Vulnerability-management oversight
  • Incident-preparedness support
  • Security-awareness capabilities

Your role

What We Need From You

Cybersecurity governance requires participation from your organization. You should nominate:

You should nominate

  • An executive sponsor
  • Relevant IT or engineering contacts
  • Compliance or legal contacts where applicable
  • Business owners for important risks and controls

Scope boundaries

Clear Scope. No Hidden Unlimited Consulting.

The Secusy vCISO service is designed as a defined cybersecurity leadership and governance subscription. Each subscription covers one legal entity. Services are delivered remotely. All plans have a six-month minimum engagement. The vCISO service covers cybersecurity governance, strategy, risk management, oversight, reporting and the defined activities included in the selected plan. It does not include unlimited operational cybersecurity execution. Separate services may be required for:

  • Penetration testing
  • Vulnerability scanning
  • Security engineering
  • Cloud-security implementation
  • SOC and MDR
  • Digital forensics
  • Active incident response
  • Certification audits
  • Formal attestations
  • ISO 27001 implementation projects
  • SOC 2 implementation or CPA examination
  • PCI DSS assessments
  • HITRUST assessments
  • Other specialist security engagements

Your team should provide reasonable access to information required to understand the environment, including existing cybersecurity policies, security architecture, risk information, compliance requirements, previous audit or assessment findings, vulnerability reports, security tools, business priorities and relevant customer requirements. Your internal teams remain responsible for implementing technical and operational activities unless those services are separately included or purchased. Your vCISO can help identify and coordinate these requirements.

vCISO Advisory vs Managed vs Executive

  • Choose Advisory if:

    You already have people who can execute cybersecurity work and need an experienced security leader to provide direction, reviews and governance.

    You run it. We guide you.

  • Choose Managed if:

    You want Secusy to actively help maintain your risk, compliance and governance program and keep cybersecurity activities moving.

    We run it with you.

  • Choose Executive if:

    You need someone to operate as your outsourced cybersecurity leader and coordinate the broader cybersecurity program.

    We act as your cybersecurity leadership function.

Why Secusy + ValueMentor?

Traditional vCISO engagements can become a collection of meetings, spreadsheets, presentations and action lists. Secusy takes a different approach.

Named vCISO

Included on every plan

GRC platform

OneCSF included on every plan

Act once. Comply with many.

Security requirements frequently overlap. A policy, technical control or risk-management activity implemented for one framework may also support requirements in other frameworks. OneCSF helps organize those relationships so you can manage security as a single program rather than running independent compliance projects.

Delivered by

ValueMentor

OneCSF

OneCSF is Secusy's approach to managing cybersecurity controls across multiple frameworks through a unified control structure, reducing duplication when several compliance requirements address similar security objectives.

Minimum engagement

6 months

Questions

Frequently asked questions

Start Running Cybersecurity as a Business Program

Get the technology, structure and leadership needed to manage cybersecurity continuously.

vCISO Advisory

Custom pricing

You run the program. We guide you.

vCISO Executive

Custom pricing

Your outsourced cybersecurity leadership function.

6-month minimum • Remote delivery • One legal entity

Secusy vCISO Portal, powered by OneCSF

Powered by ValueMentor.