vCISO & Policy Consulting
Executive-level security leadership and governance, for organizations without a full-time CISO.
What's included
- Fractional / virtual CISO leadership and advisory retainers
- Security policy and procedure development (AUP, IR, access control, data handling, and more; see examples)
- Risk assessments and risk register development
- Framework alignment and CIS Controls implementation guidance
- Vendor/third-party risk review
- Security awareness program design
- Board and executive reporting on cyber risk
How engagements work
vCISO engagements are typically structured as an ongoing monthly retainer: a fixed amount of advisory time, a standing cadence of meetings with leadership, and defined deliverables such as a risk register, policy set, or compliance roadmap. Policy and risk-assessment work can also be scoped as a standalone project.
Good fit if you...
- Need security leadership but aren't ready for a full-time CISO hire
- Have to answer a customer security questionnaire or pursue a compliance framework
- Have no written security policy, or it hasn't been updated in years
- Need someone to translate technical risk into terms your board or leadership can act on
Pursuing a specific certification or attestation? See our dedicated Compliance Consulting page for NIST, CMMC, SOC 2, HIPAA, PCI DSS, and ISO 27001 readiness work.
Policy examples
Every policy engagement starts from a proven template set and is tailored to your organization: your roles, your systems, your regulatory obligations, and the framework you are aligning to. These are the policies, procedures, and forms we most often put together for clients.
People, devices, and data
-
Acceptable Use of Assets Policy Standards for appropriate use of company devices, data, accounts, and network resources by employees, contractors, and third parties
-
Artificial Intelligence Acceptable Use Policy Rules for using AI tools and platforms with company data, including approved services, prohibited inputs, and review requirements
-
Bring Your Own Device (BYOD) Policy Approval, security, and acknowledgment requirements for personally owned mobile devices used for company business
-
Password Policy Length, complexity, rotation, and storage requirements for user accounts, with defined exceptions for system and shared accounts
-
Data Classification and Handling Policy Classification levels and the storage, transmission, sharing, and disposal standards required for each type of data
-
Credit Card and Donation Information Handling Policy Authorized personnel and secure handling, processing, and disposal practices for payment card and donor information
-
Physical Security Policy Access control, visitor handling, after-hours procedures, and protection of facilities, equipment, and personnel
Operations, resilience, and vendors
-
Information Technology Governance Policy An organization-wide security policy mapped to NIST SP 800-53 Rev. 5 and NIST CSF 2.0 control families
-
Business Continuity and IT Incident Response Policy Incident response team, methodology, and recovery commitments for cybersecurity incidents and business disruptions
-
IT Failover and Disaster Recovery Procedure Manual Step-by-step recovery procedures for the loss of a server, application, dataset, or entire datacenter
-
Server Maintenance Window Policy Scheduling, categories, and communication requirements for updates, upgrades, backups, and application maintenance
-
Honeypot and Honeynet Operation Policy Authorization and legal guardrails for operating internet-facing decoy systems for threat intelligence and intrusion detection
-
IT Vendor, Software, or AI Platform Request for Approval An intake form that captures ownership, data flows, and security documentation before a new platform or AI capability is adopted
-
Third-Party Vendor Security Questionnaire A standardized questionnaire for assessing the security practices of vendors and service providers before and during a relationship