Advisory
Virtual CISO (vCISO)
Board-level security leadership, on tap — without a full-time executive salary.
Good security leadership shouldn’t be reserved for organisations big enough to hire it full-time. A virtual CISO (vCISO) gives your organisation access to an experienced Chief Information Security Officer for a fraction of the cost of a full-time hire. Ours is led by Stephen Phillips, whose 20+ years in the field include a previous role as CISO at Westpac NZ.
It’s the right fit for organisations that need credible security leadership and board-ready reporting, but aren’t at the size where a full-time CISO makes sense.
What’s involved
Inside Virtual CISO (vCISO)
- Security strategy and roadmap aligned to your risk and budget
- Board and leadership reporting in plain language
- Risk appetite definition and monitoring
- Framework alignment — NIST CSF 2.0, ISO/IEC 27001, NZISM
- Vendor, insurer and audit support
- Incident oversight and readiness
Why it matters
The difference it makes
Boards and directors are increasingly expected to understand and own cyber risk. A vCISO gives you the seniority and structure to do that credibly — without carrying an executive salary.
FAQ
Common questions
What does a vCISO actually do?
A vCISO sets security strategy, defines your risk appetite, reports to the board, aligns you to the right frameworks, and provides senior oversight during audits, vendor reviews and incidents — the CISO function, delivered part-time.
How is a vCISO different from our IT provider?
IT providers keep systems running. A vCISO owns security strategy and governance — the leadership layer above day-to-day IT, focused on risk, assurance and board accountability.
Is a vCISO worth it for a 30-person organisation?
Often, yes — especially if you hold sensitive data, have compliance obligations, or your board is asking about cyber risk. You get senior expertise scaled to your size and budget.
Related pages
Let’s talk
Every good plan starts with a conversation, and there’s no obligation in having one.