Virtual CISO / vCISO
Ongoing CISO support to maintain ISO 27001
Achieving certification proves that your Information Security Management System met the standard at the time of assessment. Maintaining it requires continued ownership, evidence, risk management, review and improvement.
ISO Security provides an experienced virtual CISO who can oversee this work without the cost or commitment of employing a full-time Chief Information Security Officer.
Scope of the role
Governance, risk and compliance — not outsourced IT
This service is deliberately focused. It covers information security governance, risk management, compliance and the operation of your ISMS through the certification cycle.
It is not outsourced IT support, a security operations centre or a managed detection and response service. Where those capabilities are needed, we help you specify them and hold suppliers to account — but we do not pretend to be them.
Fit
Who needs ongoing CISO support?
- Certified organisations without an internal ISMS owner
- Growing businesses whose security responsibilities have outgrown informal processes
- Businesses preparing for surveillance or recertification audits
- Organisations receiving complex customer security questionnaires
- Leadership teams that need clearer information-security reporting
Inclusions
What the service can include
- Named senior security adviser
- ISMS programme ownership
- Risk-register review
- Policy review and version control
- Security objectives and action tracking
- Control-effectiveness review
- Internal audit coordination
- Management review preparation
- Surveillance-audit preparation
- Recertification support
- Corrective-action management
- Supplier-risk oversight
- Customer security questionnaire support
- Board and senior-management reporting
- Advice following organisational, supplier or technology changes
How it works
A four-stage engagement model
- 01
Review the existing ISMS
We assess the current system against ISO/IEC 27001:2022 and against your own documented commitments, identifying where evidence, ownership or review activity has drifted.
- 02
Agree responsibilities and priorities
We set out clearly what the vCISO owns, what remains with your team, your IT provider and other suppliers, and which issues are addressed first.
- 03
Establish a regular governance rhythm
A predictable cycle of risk reviews, policy reviews, action tracking, internal audit activity and management reporting, at a cadence that suits the organisation.
- 04
Maintain evidence and audit readiness
Records are kept current as work happens, so surveillance and recertification audits become a review of business as usual rather than a project in themselves.
Boundaries
What a virtual CISO does not replace
- Your IT provider or internal IT team, who implement and run technical controls
- Your legal adviser, on contracts, regulatory interpretation and liability
- A Data Protection Officer, where one is required under data protection law
- Your penetration-testing or vulnerability-assessment provider
- The independent certification body that audits and certifies your ISMS
- Management accountability, which always remains with your leadership team
FAQs
Virtual CISO FAQs
Need someone to own your ISMS?
Tell us about your current ISMS, your certification status and where the gaps are. We will explain how ongoing CISO support would work in your organisation.
Or email info@isosecurity.co.uk