CISO-for-hire
Principal-level security leadership as a seat inside your organisation, without a full-time hire.
What we deliver
- Board and leadership cadence
Monthly reporting, risk decisions, and follow-up in the language the board already reads.
- Security strategy and roadmap
A roadmap with owners, costs, and sequencing, not a wish list.
- Programme oversight on ISO 27001, NIS2, and DORA
Owner of your compliance programme, from control work to auditor conversations.
- Vendor and contract scrutiny
Security review of new suppliers, tender requirements, and renewals of existing contracts.
- Build or buy capacity calls
Concrete recommendations on when to hire internally, buy a service, or defer the decision.
- Incident escalation owner
Your own security lead on the bridge while CrowdStrike Falcon Complete runs the response.
How we deliver this service
- In a role at the customer
A dedicated vCISO seat with a fixed cadence, typically a few days per month over twelve months.
- As part of a service
Included in the Secured by FM CyberSecurity bundle for small and medium-sized businesses.
- In a project
Interim CISO during a transition, an acquisition, or until a permanent hire is in place.
Recent insights on CISO-for-hire
- ISO 27001 work as part of a security subscription
Secured by FM CyberSecurity combines security operations, advice and ISO 27001 preparation. Here is what to clarify when buying that work as a subscription.
- What CISSP certification means when picking a cybersecurity consultant
CISSP is a broad security credential with experience requirements. Verify it, then assess the person's fit for your specific systems and assignment.
- Publishing a website without a public admin login
A static website can keep publishing separate from visitor traffic. Git, a build pipeline and a controlled publishing service each have a distinct role.