← Consultancy
Virtual CISO

Security leadership, backed by a team that executes

A senior security leader who owns your strategy, reports to your board and answers your customers’ security questions, independent of any tool or vendor.

Board reportingSOC 2 & ISO 27001Security questionnairesVendor-neutral
Your first 90 daysvCISO plan
Week 2 Risk assessmentInterviews and control review Done
Week 6 12-month roadmapAgreed with leadership Done
Week 9 SOC 2 gap assessment14 gaps, owners assigned In progress
Week 12 First board reportRisk, progress, decisions Scheduled
Why it's different

Advice is easy. Delivering it is where most vCISOs stop.

The usual way With Touchpoint
Advisory only: you still need someone to do the work Our engineers can deliver roadmap items under a separate scope if you want
Board reports built from interviews and opinion Board reports built on evidence from your own tools and controls
A roadmap in a slide deck A roadmap of owned, dated work packages, reviewed every month
Hard to reach during an incident Your vCISO leads the business side of an incident alongside your responders
Hours you can’t see being used A monthly summary of what was done, what changed and what’s next
What your vCISO does

Everything a CISO would own

Strategy & roadmap A 12-month security plan tied to your risks, budget and business goals.
Board & investor reporting Quarterly updates in plain language, backed by evidence.
Compliance programmes SOC 2, ISO 27001 and other frameworks, from gap assessment to audit.
Policies & governance Policies written, approved and actually followed.
Customer assurance Security questionnaires and due-diligence calls handled for you.
Incident leadership Business decisions, communication and regulators during a serious incident.
How it works

A clear first 90 days, then steady progress

  1. Month 1 Baseline Interviews, a risk assessment and a review of your current controls and data.
  2. Month 2 Priorities A 12-month roadmap agreed with leadership, with owners and budget.
  3. Month 3 First board report Where you stand, what’s changing and the decisions needed.
  4. Ongoing Deliver Monthly progress on the roadmap, questionnaires and policies.
  5. Quarterly Report Board updates and a refreshed plan as your business changes.
What you get

Leadership you can measure

You always know what your vCISO has done, what has improved and what comes next.

✓ 12-month security roadmapPrioritised, costed and reviewed monthly.
✓ Quarterly board packRisk, progress and decisions needed, on one page.
✓ Risk registerOwned, scored and kept current.
✓ Policy libraryCore policies written and approved.
✓ Questionnaire supportCustomer and supplier assessments completed for you.
✓ Monthly summaryWhat was done, what changed and what’s next.
Engagement options

Scale leadership to where you are

Foundation Compliance-focused For teams preparing for a first certification or customer security reviews.
  • ✓One framework, gap to audit
  • ✓Core policy set
  • ✓Questionnaire support
  • ✓Monthly check-in
Get a fixed quote →
Most chosen Programme leadership For organisations building a full security programme.
  • ✓12-month roadmap and risk register
  • ✓Quarterly board reporting
  • ✓Compliance programme leadership
  • ✓Fortnightly working sessions
Get a fixed quote →
Executive Embedded CISO For fast-growing or regulated organisations that need a CISO in the room.
  • ✓Weekly leadership involvement
  • ✓Board and investor meetings
  • ✓Incident leadership
  • ✓Team and budget planning
Get a fixed quote →
Questions

Before you ask

When do we need a vCISO rather than a full-time CISO?+

When you need senior security leadership but not 40 hours a week of it: typically organisations without a CISO, preparing for certification, funding or rapid growth.

Is the vCISO tied to your products?+

No. The vCISO is vendor-neutral and works with the tools and providers you already have.

Can the vCISO attend board meetings?+

Yes. Board and investor reporting is included from the Programme level.

How is time allocated?+

A set number of days each month, agreed up front, with a monthly summary of how it was used.

Get a security leader without the full-time hire

Tell us where you are and where you need to be. We’ll recommend the right level and agree it up front.

Talk to a vCISO
Other consultancy services Penetration testing→ Cloud security→ Tabletop exercises→ Engineering & implementation→