Your Security Posture, Audit-Ready All Year Round
Stop scrambling every time an insurer, auditor, or tender board asks “prove it.” Our vCISO retainer keeps your risk register current, your reporting board-ready, and your compliance story straight: every month, not once a year.
Get Your Risk Picture Reviewed
Three quick questions, then book a 15-minute discovery call.
Question 1 of 3
Which best describes your situation right now?
The Annual Audit Panic Is a Choice
Most businesses only think about security posture when something forces the issue: a renewal questionnaire, a tender requirement, a board asking pointed questions after a headline breach somewhere else. By then it's reactive, rushed, and expensive.
No one owns it.
Security sits with IT, who are busy keeping the lights on, not tracking risk.
The findings pile up.
Last year's pentest report is still sitting there, half-actioned.
Renewals catch you cold.
Insurance and tender questionnaires ask things nobody's been tracking.
What a vCISO Retainer Actually Gives You
Think of it as outsourcing the “security exec” role: the person who owns your risk picture, keeps it current, and can explain it to your board, your insurer, or your biggest client in plain English.
Advisory
Regular calls with your leadership to review risk and set priorities.
Risk Register
A living record of what’s exposed and what’s being done about it.
Technical Checks
Light-touch validation that things are actually as claimed.
Reporting
Findings translated into something a non-technical exec can act on.
Choose Your Level of Assurance
Pricing scales with how much depth and frequency your business needs, not just headcount.
Essentials
Best for: small businesses buying their first vCISO service
$2,500/month
- 1 x 45-min advisory call/month
- Monthly risk register update
- Simple written summary
- Advisory only: no technical checks
Growth
Best for: mid-market businesses with active compliance obligations
$4,250/month
- 1 x 60-min advisory call/month + email support
- Monthly risk register, reviewed live on call
- 1 light technical check/quarter (config or vuln scan)
- Formatted, exec-readable report
Executive
Best for: board-level oversight, insurance or tender pressure
$6,500/month
- 2 x advisory calls/month + on-call for urgent issues
- Monthly risk register, tracked against framework KPIs
- 1 light technical check/quarter + ad-hoc reviews as needed
- Board-ready pack, presented live on call
Not sure which tier fits? Book a discovery call and we'll recommend one, no obligation.
Where This Fits (and Where It Doesn't)
A vCISO retainer is advisory and oversight, not implementation, and not incident response. We advise and validate; your internal team or MSP does the fixing. If you need a full penetration test or you're dealing with an active incident, those are separate, separately-scoped engagements. Ask us how they fit alongside your retainer.
Real Businesses. Real Outcomes.












Common questions.
How much does a vCISO retainer cost?
Three tiers: Essentials at $2,500/month, Growth at $4,250/month, and Executive at $6,500/month. Pricing scales with call frequency and technical check depth, not headcount. Book a discovery call and we'll recommend the tier that fits.
What's actually included?
Four things every tier includes to some degree: regular advisory calls with your leadership, a living risk register kept current month to month, light-touch technical validation, and reporting translated for non-technical stakeholders like your board or insurer.
Does the retainer include penetration testing or technical checks?
Growth and Executive tiers include one light technical check per quarter (a config review or vulnerability scan). It's light-touch validation, not a substitute for a full penetration test: that's a separate, separately-scoped engagement.
How is this different from a one-off penetration test?
A penetration test is a point-in-time technical assessment. The vCISO retainer is ongoing oversight: advisory, risk tracking, and reporting delivered every month instead of once a year.
Does this cover incident response or implementation work?
No. The retainer is advisory and oversight, not implementation and not incident response. We advise and validate; your internal team or MSP does the fixing. Active incidents and full penetration tests are separately-scoped engagements.
Stop Reacting. Start Reporting.
One discovery call tells you which tier fits and what your first 30 days would look like.
Book a vCISO Discovery Call