Managed Security

Virtual CISO (vCISO) services from your fractional security team

Security ended up on the CTO's desk. A customer's questionnaire, an auditor's evidence list and a board question all point at the same person, and that person also owns the product roadmap. You may already pay for a GRC platform that shows what is missing and cannot fix it. Who owns the security program, and who does the work?

From USD $2,500 a month, scope-dependent.

Ali Aleali

Ali Aleali, CISSP, CCSP

Co-Founder & Principal Consultant

Former security architect for Bank of Canada and Payments Canada. CISSP, CCSP. Leads every engagement.

Connect on LinkedIn

When a fractional security team is the right call, and when it is not

If we are not a fit, we say so on the strategy call.

What you get

One senior lead who owns the program and answers for it, backed by analysts, GRC platform admins and framework specialists.

icon-8

A named senior security lead

One person holds the vCISO seat, joins your leadership cadence and answers to your board, auditors and customers.

icon-7

Architecture review and threat modeling first

The opening 4 to 6 weeks cover security architecture review, data flow and network diagrams, inventory discovery, user interviews and threat modeling.

icon-9

Controls built against your systems

Policies and controls matched to your real workflows, with evidence capture designed in rather than assembled before an audit.

icon-6

Your GRC platform, operated

We run Vanta, Drata, Secureframe, Scrut, Sprinto and others day to day. The platform stays yours.

icon-5

Frameworks mapped onto one program

SOC 2, ISO 27001, ISO 42001, ISO 27701, CMMC, CPCSC, HIPAA, PIPEDA, Law 25, GDPR and HITRUST from the same evidence.

icon-4

The operating rhythm

Weekly checkpoints with control owners, monthly leadership review, quarterly roadmap planning, audit liaison and customer questionnaire response.

Also available on the same engagement

Added to the program when the environment or a customer requires it, under the same lead.

icon-2

Incident response retainer

A named team on call, a tested plan and a coordinator who has handled breaches under regulator and customer scrutiny.

icon-1

Tabletop exercises

Leadership and engineering walk through a realistic incident together. Gaps in decisions, contacts and evidence show up before a real one.

icon-3

Active security monitoring and response (MDR) (coming soon)

Detection and response operated on your existing stack, reported into the same monthly review.

How it works

Assess, Build, Operate. A continuous loop rather than a project with an end date.

01

Assess

Security architecture review, data flow analysis, threat modeling and a capability assessment across the program. Output: a prioritized roadmap.

02

Build

Policies matched to real workflows, controls tied to real systems, evidence pipelines configured in your GRC platform. Output: the Security Program Manual.

03

Operate

Weekly, monthly and quarterly cadence, audits managed through fieldwork, questionnaires answered, new frameworks mapped as deals require them.

Artifacts you hold at the end of the first quarter

Every engagement produces the same set, built from your systems rather than a template. They survive staff turnover and stand up to an auditor or a buyer's security team.

  • Security Program Manual

  • Security Posture Report

  • Security architecture review

  • Data flow and network diagrams

  • Threat model and remediation roadmap

  • Capability assessment scores

  • Policies and control set

  • Evidence pipelines in your GRC platform

  • Questionnaire answer library

  • Vendor risk register

What changes in the first 90 days

The program gets an owner, a manual and a rhythm. Your engineers go back to the roadmap.

Frequently asked questions

Most fractional CISO firms have made "vCISO" a synonym for "we run your SOC 2." We start with security architecture review, data-flow analysis, and threat modeling, then build the program around your actual environment. Frameworks map onto the program when needed. Companies hire us when they want the security to actually work, not just the badge to clear the deal.

In practice, none. "Fractional CISO" emphasizes part-time senior leadership; "vCISO" emphasizes remote or outsourced delivery. We use "fractional security team" because the seat involves more than one person, a senior operator backed by analysts, GRC platform admins, and framework specialists.

The math typically flips somewhere between 250 and 500 employees, or earlier when a board, regulator, or major customer specifically requires a named full-time CISO. Below that, a fractional team delivers the same program quality without the $300K+ all-in cost and the six-to-nine-month executive search.

The platform surfaces what's missing. We operate it, configure controls to match your environment, drive remediation owners, manage evidence, respond to alerts. We run Vanta, Drata, Secureframe, Scrut, Sprinto, Cocoon, and Mycroft.io. No platform yet? We'll help you pick the right one first.

Both. We don't issue the audit report, that's the auditor's role, and the independence boundary matters. We prepare your environment, manage the auditor relationship through fieldwork, coordinate evidence requests, and remediate findings. We work alongside Prescient Assurance, MHM, and others.

Transition planning is part of the engagement. We document the program, hand over institutional knowledge, and stay on for a defined transition window so the new CISO inherits a running program, not a recovery project. About a third of long-running engagements end this way.

They are not substitutes, so the honest comparison is what each one leaves you holding. A GRC platform runs USD $20,000 to $60,000 a year and surfaces what is missing. It does not decide what to fix first, configure controls against your actual systems, chase the owners, or answer an auditor. Someone still operates it. A fractional security team starts at USD $2,500 a month and includes that operator, and we run Vanta, Drata, Secureframe, Scrut, Sprinto, Cocoon and Mycroft.io, so the platform stays yours either way. If you already have a security operator on staff, buy the platform alone. If you do not, the platform is a line item with a person-shaped hole behind it.

By building one program and mapping it, rather than running one project per framework. Controls are implemented against your real systems once, and each framework becomes a lens over the same evidence. SOC 2 and ISO 27001 overlap heavily, so the second certification is mostly mapping rather than new work. ISO 42001 is where a fractional team earns the most, because it extends the management system you already have with AI-specific risk and impact assessment, data governance, model lifecycle and human oversight, so most of the effort is deciding which of your AI uses are in scope rather than starting again. We operate SOC 2, ISO 27001, ISO 42001, ISO 27701, CMMC, CPCSC, HIPAA, PIPEDA, Quebec Law 25, GDPR and HITRUST from a single program.

Four things, and price is not the first. One, who holds the seat, and whether you meet that person before you sign, because a named senior operator and an account manager are different products. Two, whether the engagement opens with architecture review, data flow analysis and threat modeling or with a policy pack, because that decides whether you get a security program or a document set. Three, what happens after the audit, because a provider scoped to readiness leaves at the point the program needs operating. Four, whether the provider will tell you something you do not want to hear during fieldwork. Ask each one what they would flag to an auditor that would slow your certification down, and see who gives you a straight answer.

Strengthen your security program before the next deal asks

Book a 30-minute strategy call. We cover your environment, your current posture and whether a fractional security team fits.

From the blog: vCISO and security programs

vCISO Services for Mid-Market SaaS: How to Evaluate Fractional Security Leadership in 2026

vCISO services give a mid-market SaaS company senior security leadership on a fractional basis: someone who owns the security program, drives SOC 2 ...

Top 8 vCISO Services for Mid-Market SaaS in 2026

The right vCISO service for a mid-market SaaS company is the one that owns and runs the security program end to end, on a fractional basis, the way a ...

The Real Cost of DIY Compliance vs. Hiring a Consultant

On paper, DIY compliance looks straightforward. Subscribe to a GRC platform, follow the control library, collect evidence, engage an auditor. The ...