Cyber Security Audit & Review
Virtual CISO (vCISO)
Fractional security leadership: strategy, board reporting and programme ownership.
Every engagement includes manual validation, a two audience report and free re-testing.
Get a scoped quote+91 96682 00222What this actually is
Plenty of organisations need security leadership but not a full-time executive salary. What they actually need is someone who can sit in a board meeting, own the risk register, answer the auditor and tell the engineering team which three things matter this quarter.
Our vCISO engagement gives you a named senior practitioner on an agreed cadence. They run your security programme, not a slide deck about it.
Because they sit inside Threatsys, they can also pull in testers, auditors and incident responders when the work needs it, without you managing three vendors.
What we go after
- Security strategy and multi-year roadmap
- Risk register ownership and board reporting
- Policy framework and governance structure
- Regulatory and audit liaison
- Vendor and third-party risk oversight
- Incident response readiness and tabletop exercises
- Security budget planning and business cases
How we run it
- 01
Understand the business
What you do, what would genuinely hurt if it stopped, and how much risk your board will carry.
- 02
Assess
People, process and technology together, because attackers do not respect the boundary between them.
- 03
Benchmark and rank
Where you sit against your peers and your regulator, with findings ranked by real exposure.
- 04
Roadmap
A sequenced plan with costs attached, so the business case writes itself.
What you receive
- Security strategy and roadmap
- Maintained risk register with owners and dates
- Board and audit committee reporting pack
- Policy framework fit for your regulator
- Quarterly programme review
Who needs this
Growing companies whose customers now ask security questions they cannot answer, and regulated entities that must name an accountable security officer.
How long it takes
Ongoing, typically two to eight days a month depending on the size of the programme.
Standards this satisfies
- ISO 27001
- NIST CSF
- RBI
- SEBI CSCRF
- DPDP Act
Why it matters
There is a gap between knowing you have a security problem and knowing which one to solve first. Advisory work exists to close that gap: an independent view of where the risk actually sits, expressed in terms a board can act on and a budget can be built around.
The other reason is availability. Most organisations do not need a full time security leader, but they do need someone to ask before making a decision rather than after. The cost of the wrong architecture choice, or the wrong vendor, dwarfs the cost of the conversation that would have prevented it.
Choose how you want this delivered
Most of the price difference between quotes comes down to this one choice, and it is rarely explained. Pick one to see what it covers, what it suits and what it costs you.
A defined number of days a month with a named advisor who keeps context between conversations. This is what most organisations actually need: not a large project, but someone to ask before making a decision rather than after.
Choose this when
- Decisions arriving faster than you can hire for
- You need continuity rather than another report
- Board or committee reporting on a regular cycle
Effort and cost
Monthly, with a defined day allocation. Far cheaper than a hire and available immediately.
Scope it yourself, before you call anyone
Answer a few questions and you get an indicative number, the working behind it and what your answers tell us. It runs in your browser, so nothing you type reaches us.
Which framework are you going for?
What we look for, and keep finding
These are the classes of problem this work exists to surface. Not every engagement finds all of them, but these are the ones that turn up often enough to be worth naming.
Capability that does not match the risk
Heavy investment in one area and nothing in another, usually reflecting what a previous incident or a previous hire cared about rather than where the current exposure sits.
No owner for the important things
Ask who owns third party risk, or identity, and the answer is a committee. Controls without a named owner degrade quietly and predictably.
Reporting that does not support a decision
Dashboards full of counts that never answer the question a board actually asks, which is whether we are more or less exposed than last quarter and what it would cost to change that.
Unmanaged supplier concentration
Several critical services resting on one provider, with no assessment of what happens if it becomes unavailable or compromised.
Plans that have never been tested
Incident response and continuity documents that read well and have never been rehearsed. The first rehearsal always finds something, which is the point of having one.
Who runs your engagement
A practitioner, not a presentation
Advisory work is led by someone who has run security operations rather than only advised on them. The test we apply to our own recommendations is whether the person making them has had to live with a decision like it.
Questions we get asked
Is this the same person every month?
Yes. A named practitioner with a named backup. Continuity is most of the value, and rotating consultants through the role defeats the purpose.
Can a vCISO sign off compliance for our regulator?
They can hold the accountable role where the framework permits an outsourced officer, and they will prepare and present the evidence. Where the regulator requires an employee, we work alongside your nominated person instead.
Often scoped alongside
- Cybersecurity Posture & Maturity AssessmentBenchmarked maturity scoring with a costed, sequenced remediation roadmap.Read more
- STQC Audit & GIGW ComplianceSTQC cyber security audit and GIGW certification for government digital services.Read more
- Dark Web MonitoringContinuous monitoring for leaked credentials, data and brand exposure.Read more
- Root Cause AnalysisPost-incident forensics that establishes what actually happened and why.Read more
Ready to scope your virtual ciso (vciso)?
Thirty minutes with a senior engineer, and you leave with a written scope and indicative effort.












