Virtual CISO · Operating since 2002
A virtual CISO is not a cheaper CISO. It is a different shape of the same function: somebody accountable for the security programme, who attends the board meeting, owns the risk register and signs off the architecture — but who does so for an agreed number of days a month rather than as a permanent hire.
Board reporting · risk ownership · policy · audit and regulator liaison
The function
What the role actually covers
Security leadership is mostly decisions, and decisions need somebody whose name is against them.
Risk ownership
A maintained risk register with named owners and review dates, rather than a spreadsheet produced for the last audit and not opened since.
Board and management reporting
Security reported in language the board can act on — exposure, trend and decisions required, not alert counts.
Policy that survives contact
Policies written to be followed and auditable, sized to your organisation rather than copied from a template built for a bank.
Architecture sign-off
Somebody senior reviewing designs before they are built, which is dramatically cheaper than reviewing them after.
Vendor and audit liaison
Handling security questionnaires, customer due diligence and auditor requests so they stop landing on your engineers.
Incident decision-making
The person who decides whether to disconnect, notify or escalate. Those calls need to be made by someone with authority and prior experience of making them.
The trade
Why the economics work
The gap is the part most organisations cannot justify.
A full-time security executive is a substantial fixed cost with a long hiring cycle and a long notice period. For an organisation of a few hundred people the work is real but it is not full-time work — and hiring for it means either overpaying for idle capacity or, more commonly, not hiring at all and leaving the function unowned.
The honest limitation: a vCISO is not present. Somebody in-house still has to run day-to-day operations. The engagement works when it is paired with either your own team or a managed service — it does not replace both.
Honest limits
When a vCISO is the wrong answer
This is not the right engagement for everyone, and it is cheaper to establish that now than four months in.
| If this is you | A vCISO will not fix it | What would |
|---|---|---|
| Nobody to execute | Direction without delivery capacity produces a well-documented backlog and no change. | Managed services first, leadership second |
| One specific project | A defined piece of work with an end date does not need a standing accountability. | Scoped consulting — an audit or an implementation |
| A regulator deadline next month | Programme leadership pays off over quarters, not weeks. | Targeted compliance remediation |
| Executive sponsorship absent | Security leadership without a mandate is advice nobody has to take. This is the most common cause of a disappointing engagement. | Fix the mandate first, or do not start |
Scroll the table sideways on a narrow screen.
We would rather turn down an engagement than take one that was structurally unable to succeed.
Related
Related work
These sit alongside this engagement more often than not:
Managed security services
Day-to-day security operations run on your behalf, which is what leadership and compliance work both depend on.
Questions
Virtual CISO (vCISO) Services India, answered
What is a virtual CISO?
A senior security leader engaged part-time and accountable for your security programme — risk, policy, architecture decisions and board reporting — for an agreed number of days each month rather than as a permanent employee.
How is a vCISO different from a consultant?
A consultant delivers a piece of work and leaves. A vCISO holds a standing accountability: the risk register stays theirs between visits, and they are the person who answers when the board asks how exposed you are.
Do we still need an internal security team?
You need somebody to execute. A vCISO sets direction, makes the decisions and owns the reporting, but the day-to-day operations still have to happen — either in-house or through a managed service.
How much vCISO time does an organisation need?
It depends on regulatory load and change rate far more than on headcount. An organisation in a stable environment with no regulator may need a couple of days a month; one mid-way through a compliance programme or a migration needs considerably more. We would rather scope it after a conversation than quote a number blind.
Can a vCISO help with an audit or certification?
Yes, on the preparation side — control design, evidence, remediation and dealing with the auditor’s questions. The audit or certification itself is signed by an accredited body, not by us, and any provider claiming otherwise is worth a second look.
Who would we actually be working with?
Sanjay Seth leads these engagements. He has worked in networking and security since 1993 and founded P J Networks in 2002; the firm holds ISO/IEC 27001:2022. You are not handed to a delivery pool.
Next step
Talk to someone who has done this before
Tell us where you are and we will tell you what the work actually involves. If you do not need us, we will say so.



