Risk Management
Identifying and prioritizing threats based on your business context.
Named vCISO
Powered by ValueMentor
Get the cybersecurity leadership of a Virtual CISO combined with Secusy vCISO Portal, powered by OneCSF. Manage cybersecurity strategy, risks, controls, policies, compliance requirements, evidence, action plans and executive reporting from one place — with an experienced vCISO helping keep the program moving.
Choose how much ownership you want us to take.
vCISO Advisory
You run the program. We guide you.
vCISO Managed
RecommendedWe run the program with you.
vCISO Executive
We act as your outsourced cybersecurity leadership function.
Powered by ValueMentor.
The definition
The objective is not simply to produce documentation. It is to establish and operate a cybersecurity program that management can understand, govern and improve.
Identifying and prioritizing threats based on your business context.
Guiding your team through SOC 2, ISO 27001, and HIPAA audits.
Executive dashboards and board-level security KPIs.
Aligning security investments with long-term business goals.
Traditional vCISO engagements can become a collection of meetings, spreadsheets, presentations and action lists.
Secusy takes a different approach.
Your cybersecurity program is managed through Secusy vCISO Portal, powered by OneCSF, giving your organization a central system for managing:
Your vCISO uses the same platform with your team, creating continuity between meetings and making security progress visible throughout the engagement.
Organizations increasingly need to address multiple cybersecurity and compliance requirements at the same time. You may have customers asking for SOC 2. Management may want ISO 27001. A regulator or business partner may require another cybersecurity framework.
Managing each requirement independently creates unnecessary duplication.
OneCSF is Secusy's approach to managing cybersecurity controls across multiple frameworks through a unified control structure, reducing duplication when several compliance requirements address similar security objectives.
Your vCISO helps identify the controls your organization needs, prioritize gaps, monitor implementation and track evidence through the Secusy platform.
Act once. Comply with many.
Security requirements frequently overlap. A policy, technical control or risk-management activity implemented for one framework may also support requirements in other frameworks. OneCSF helps organize those relationships so you can manage security as a single program rather than running independent compliance projects.
Choose how much ownership you want Secusy to take of your cybersecurity governance program. Pricing is confirmed with you directly before the engagement starts.
You run the program. We guide you.
$1,499/month
Timeline depends on your readiness, scope complexity and team availability.
We run the program with you.
$2,999/month
Timeline depends on your readiness, scope complexity and team availability.
We act as your outsourced cybersecurity leadership function.
$5,999/month
Timeline depends on your readiness, scope complexity and team availability.
| Feature | vCISO Advisory | vCISO Managed | vCISO Executive |
|---|---|---|---|
| Price | $1,499/month | $2,999/month | $5,999/month |
| Best for | Teams that can execute but need security leadership | Companies that want us to actively run the governance program with them | Companies that need an outsourced cybersecurity leadership function |
| Security roadmap | Annual | Actively maintained | Continuously managed |
| Scheduled vCISO meetings | 1/month | 2/month | Weekly |
| Risk register | Customer maintained; vCISO reviewed quarterly | Jointly managed; reviewed monthly | Actively managed |
| OneCSF control tracking | Customer-led | Jointly managed | vCISO-led oversight |
| Evidence tracking | Customer-led | Reviewed monthly | Actively monitored |
| New/revised policies | Templates + guidance | Up to 4/quarter | Up to 8/quarter |
| Compliance program oversight | Advisory | Active oversight | Multi-framework oversight |
| Security KPIs | Quarterly | Monthly | Monthly |
| Executive report | Quarterly | Monthly | Monthly |
| Board/leadership presentation | 1/year | Quarterly | Quarterly/as agreed |
| Vendor security assessments | Guidance | Up to 2/month | Up to 4/month |
| Customer security questionnaires | Guidance | Up to 1/month | Up to 2/month |
| Security architecture review | Advisory | ||
| Security budget/planning | Guidance | ||
| Incident response planning | Review | Develop/review | Develop/manage |
| Tabletop exercise | Add-on | 1/year | 2/year |
| Ad-hoc security advisory | Standard | Priority | Executive priority |
| Minimum engagement | 6 months | 6 months | 6 months |
| Delivery | Remote | Remote | Remote |
| Secusy vCISO Portal | |||
| OneCSF GRC platform | |||
| Named vCISO | |||
| Initial cybersecurity maturity review | |||
| Cybersecurity strategy | |||
| Compliance mapping | |||
| Security policy review | |||
| Vulnerability management oversight | |||
| Security awareness platform |
vCISO Advisory
Custom pricingvCISO Advisory is designed for organizations that already have people capable of executing cybersecurity activities but need experienced security leadership to determine priorities and provide direction.
Your internal team manages day-to-day activities through Secusy. Your vCISO reviews progress, challenges decisions, advises management and helps ensure your security program remains aligned with business risks and compliance priorities.
Best for: Organizations with an internal IT, security, compliance or engineering team that can execute the program.
This plan includes
vCISO Managed
Custom pricingvCISO Managed is for organizations that want more than advice. Your vCISO works with your internal teams to actively manage cybersecurity governance using Secusy and OneCSF.
We help maintain the risk program, oversee controls, monitor compliance activities, develop policies, prepare executive reporting and ensure cybersecurity initiatives continue progressing.
Best for: Growing companies that need an experienced security leader to actively help operate their cybersecurity governance program.
This plan includes
vCISO Executive
Custom pricingvCISO Executive is designed for organizations that need someone to operate at the level of a senior cybersecurity leader without hiring a full-time CISO.
Your vCISO takes broader responsibility for coordinating cybersecurity governance across management, IT, engineering, compliance and external security providers. Secusy becomes the operating platform for the program, while your vCISO drives priorities, risk decisions, security planning, governance and executive communication.
Best for: Organizations that need a senior cybersecurity leadership function but do not yet require or want to recruit a full-time CISO.
This plan includes
Your vCISO engagement is delivered through the Secusy platform. Instead of relying on spreadsheets and periodic presentations, you maintain an ongoing view of your cybersecurity program.
Maintain cybersecurity risks, assess their significance, assign actions, identify owners and monitor treatment activities.
Manage cybersecurity controls through OneCSF and map them across applicable frameworks, reducing duplication when multiple compliance requirements address similar security objectives.
Track requirements, gaps, controls, evidence and remediation activities across your applicable cybersecurity frameworks.
Maintain supporting security evidence so compliance activities are not rebuilt from scratch every time a customer, auditor or assessor asks for information.
Track cybersecurity policies and identify when documents need to be created, reviewed or updated.
Assign cybersecurity activities to responsible individuals and monitor outstanding actions.
Maintain visibility into planned cybersecurity initiatives, priorities and progress.
Where relevant Secusy services are enabled, vulnerability information can become part of the broader cybersecurity risk and governance process.
Translate cybersecurity activity into business-level reporting covering risk, compliance, priorities and progress.
Compliance
Security requirements frequently overlap. A policy, technical control or risk-management activity implemented for one framework may also support requirements in other frameworks. OneCSF helps organize those relationships so you can manage security as a single program rather than running independent compliance projects.
Information security management
Trust Services Criteria attestation
Cybersecurity framework
Payment card data protection
Healthcare privacy and security
HITRUST assurance programs
Contractual and questionnaire-driven controls
Additional frameworks as your program requires
Depending on your requirements, your program may include frameworks or standards such as those listed above. The applicable frameworks depend on your business, customers, jurisdiction and contractual obligations. Formal certification, attestation or audit activities are separate where required.
The platform helps establish, manage and oversee your cybersecurity and compliance program. Formal compliance, certification or attestation depends on the applicable framework, your implementation of required controls and, where necessary, assessment by an authorized auditor or assessor.
How it works
Select Advisory, Managed or Executive based on how much responsibility you want Secusy to take.
Tell us about your organization, technology environment, customers, regulatory requirements, security controls and current priorities.
A named vCISO is assigned to lead the engagement and becomes your primary point of contact for cybersecurity leadership and governance.
Your cybersecurity program is organized within the Secusy vCISO Portal and OneCSF. Relevant risks, controls, frameworks, actions and evidence are brought into the operating environment.
We review your security maturity, risks, compliance requirements, current controls and existing cybersecurity initiatives.
Your vCISO establishes priorities based on business risk, customer requirements, compliance obligations and your current security maturity.
Risks, controls, compliance activities, policies, vulnerabilities, actions and reporting are managed through Secusy based on the service level you selected.
Your vCISO continuously reviews progress and helps adjust priorities as the organization, threat environment and business requirements change.
Build a credible cybersecurity program while preparing to sell to larger customers.
Manage customer security requirements, SOC 2, ISO 27001 and broader security governance without building a large internal team.
Establish structured cybersecurity governance and management reporting.
Coordinate multiple security and compliance requirements through one cybersecurity program.
Establish governance, risk management, policies, controls and management oversight before or alongside a formal certification or attestation project.
Give management an experienced cybersecurity leader who can coordinate security activities across internal and external teams.
Your named vCISO does not work in isolation.
Secusy is powered by ValueMentor, giving the vCISO access to broader cybersecurity expertise when specialist knowledge is required.
Your vCISO remains responsible for coordinating the security program while specialist services can be added where necessary.
Included
Every Secusy vCISO customer receives the following. The frequency and level of hands-on management depend on the selected plan.
Every plan includes
Your role
Cybersecurity governance requires participation from your organization. You should nominate:
You should nominate
Scope boundaries
The Secusy vCISO service is designed as a defined cybersecurity leadership and governance subscription. Each subscription covers one legal entity. Services are delivered remotely. All plans have a six-month minimum engagement. The vCISO service covers cybersecurity governance, strategy, risk management, oversight, reporting and the defined activities included in the selected plan. It does not include unlimited operational cybersecurity execution. Separate services may be required for:
Your team should provide reasonable access to information required to understand the environment, including existing cybersecurity policies, security architecture, risk information, compliance requirements, previous audit or assessment findings, vulnerability reports, security tools, business priorities and relevant customer requirements. Your internal teams remain responsible for implementing technical and operational activities unless those services are separately included or purchased. Your vCISO can help identify and coordinate these requirements.
You already have people who can execute cybersecurity work and need an experienced security leader to provide direction, reviews and governance.
You run it. We guide you.
You want Secusy to actively help maintain your risk, compliance and governance program and keep cybersecurity activities moving.
We run it with you.
You need someone to operate as your outsourced cybersecurity leader and coordinate the broader cybersecurity program.
We act as your cybersecurity leadership function.
Traditional vCISO engagements can become a collection of meetings, spreadsheets, presentations and action lists. Secusy takes a different approach.
Included on every plan
OneCSF included on every plan
Security requirements frequently overlap. A policy, technical control or risk-management activity implemented for one framework may also support requirements in other frameworks. OneCSF helps organize those relationships so you can manage security as a single program rather than running independent compliance projects.
ValueMentor
OneCSF is Secusy's approach to managing cybersecurity controls across multiple frameworks through a unified control structure, reducing duplication when several compliance requirements address similar security objectives.
6 months
Build and prepare your ISMS for certification.
Learn morePrepare for SOC 2 and complete your Type 1 CPA examination.
Learn moreDemonstrate the ongoing operation of your controls through a Type 2 examination.
Learn moreCREST-approved penetration testing for web applications.
Learn moreBuild and assess foundational cybersecurity controls through the HITRUST e1 assessment.
Learn moreAddress a broader set of cybersecurity controls with a HITRUST i1 assessment.
Learn moreQuestions
Get the technology, structure and leadership needed to manage cybersecurity continuously.
Custom pricing
You run the program. We guide you.
Custom pricing
We run the cybersecurity governance program with you.
Custom pricing
Your outsourced cybersecurity leadership function.
6-month minimum • Remote delivery • One legal entity
Secusy vCISO Portal, powered by OneCSF
Powered by ValueMentor.