A security director by the hour
Our vCISO takes strategic ownership of security in your company. They build the strategy, manage risk and walk you through NIS2, ISO 27001 and DORA, without the cost or the risk of a full-time hire.
- An experienced CISO without the cost of a full-time hire
- Strategy, compliance (NIS2, ISO 27001, DORA) and oversight in one place
- Flexible commitment, from a few days a month to full support

Who a vCISO is for
When you need the skills and oversight of a CISO, but a full-time hire is too expensive or too early.
Companies in a growth phase
You are scaling faster than you are building security skills, and you need a strategy rather than chaos.
Entities under NIS2 or DORA
You have to demonstrate due care and regulatory compliance, but you have no CISO in house.
Client and tender requirements
Enterprise counterparties expect security maturity and proof that someone owns security oversight.
Companies with no CISO role
A full-time CISO costs 250,000 to 400,000 PLN a year. A vCISO gives you the same oversight for a fraction of that.
What your vCISO actually does
The full remit of a security director, strategic and operational alike, at a scale matched to what you need.
Security strategy
We build and maintain a cyber strategy matched to your business goals, your risk and your budget.
Risk management
Identifying, assessing and prioritising risk. A risk register and mitigation plan kept up to date.
Compliance and regulation
Preparing for and maintaining compliance with NIS2, ISO 27001, DORA and GDPR. Ready for audits and certification.
Policies and procedures
We write and roll out security policies, procedures and business continuity plans (BCP/DRP).
Overseeing your team and vendors
Coordinating IT, the SOC and external suppliers. Managing supply chain risk.
Incident response
A response plan, leading the team during an incident and reporting to the authorities (for example CSIRT or NIS2).
Building awareness
Training programmes and phishing simulations that raise resilience across the whole organisation.
Reporting to the board
Regular reports and recommendations in business language: risk, compliance status, the metrics that matter.

How we work together
We start by understanding your organisation, then run security step by step, with a clear plan and measurable results.
Opening assessment
An opening audit: where you stand, what risks and compliance gaps you carry. The result is a map of priorities.
Security roadmap
A twelve-month plan with concrete actions, named owners and milestones.
Delivery and oversight
We deliver the plan together with your team: policies, controls, processes, suppliers.
Upkeep and reporting
Regular reviews, updated risk register, board reports and readiness for audits.
vCISO versus a full-time CISO
The same level of oversight at a much lower cost and risk.
Clear subscription plans
Pick the level of engagement that matches where your organisation is today.
Essentials
- Opening assessment and risk map
- Security roadmap
- A baseline set of policies
- Monthly review and recommendations
- Email and ticket support
Growth
- Everything in Essentials
- Preparation for ISO 27001 and NIS2
- Vendor risk management
- Oversight of rollouts and the SOC
- Quarterly board reports
- Incident response plan
Enterprise
- Everything in Growth
- A dedicated vCISO leading the work
- Full support for audits and certification
- Leading your team during an incident
- Attendance at board meetings
- SLA and availability on demand
Prices are net, on a monthly contract with a notice period. Can be combined with PWNONE penetration tests and audits.