vCISO · Virtual CISO

A security director by the hour

Our vCISO takes strategic ownership of security in your company. They build the strategy, manage risk and walk you through NIS2, ISO 27001 and DORA, without the cost or the risk of a full-time hire.

  • An experienced CISO without the cost of a full-time hire
  • Strategy, compliance (NIS2, ISO 27001, DORA) and oversight in one place
  • Flexible commitment, from a few days a month to full support
A virtual CISO during a strategy meeting with the board

Who a vCISO is for

When you need the skills and oversight of a CISO, but a full-time hire is too expensive or too early.

Companies in a growth phase

You are scaling faster than you are building security skills, and you need a strategy rather than chaos.

Entities under NIS2 or DORA

You have to demonstrate due care and regulatory compliance, but you have no CISO in house.

Client and tender requirements

Enterprise counterparties expect security maturity and proof that someone owns security oversight.

Companies with no CISO role

A full-time CISO costs 250,000 to 400,000 PLN a year. A vCISO gives you the same oversight for a fraction of that.

Scope of the service

What your vCISO actually does

The full remit of a security director, strategic and operational alike, at a scale matched to what you need.

Security strategy

We build and maintain a cyber strategy matched to your business goals, your risk and your budget.

Risk management

Identifying, assessing and prioritising risk. A risk register and mitigation plan kept up to date.

Compliance and regulation

Preparing for and maintaining compliance with NIS2, ISO 27001, DORA and GDPR. Ready for audits and certification.

Policies and procedures

We write and roll out security policies, procedures and business continuity plans (BCP/DRP).

Overseeing your team and vendors

Coordinating IT, the SOC and external suppliers. Managing supply chain risk.

Incident response

A response plan, leading the team during an incident and reporting to the authorities (for example CSIRT or NIS2).

Building awareness

Training programmes and phishing simulations that raise resilience across the whole organisation.

Reporting to the board

Regular reports and recommendations in business language: risk, compliance status, the metrics that matter.

A security monitoring dashboard

How we work together

We start by understanding your organisation, then run security step by step, with a clear plan and measurable results.

1

Opening assessment

An opening audit: where you stand, what risks and compliance gaps you carry. The result is a map of priorities.

2

Security roadmap

A twelve-month plan with concrete actions, named owners and milestones.

3

Delivery and oversight

We deliver the plan together with your team: policies, controls, processes, suppliers.

4

Upkeep and reporting

Regular reviews, updated risk register, board reports and readiness for audits.

vCISO versus a full-time CISO

The same level of oversight at a much lower cost and risk.

Full-time CISO
PWNONE vCISO
Annual cost
250,000 to 400,000 PLN
from roughly 59,000 PLN
Time to start
3 to 6 months of recruitment
up and running in days
Experience
one person, one background
a team of experts and pentesters
Scaling
a fixed position
a flexible commitment
Compliance (NIS2/ISO/DORA)
depends on the person you hire
included as standard
Engagement models

Clear subscription plans

Pick the level of engagement that matches where your organisation is today.

Essentials

4,900 PLN/ month
up to 2 CISO days a month
  • Opening assessment and risk map
  • Security roadmap
  • A baseline set of policies
  • Monthly review and recommendations
  • Email and ticket support
Choose Essentials
Recommended

Growth

9,900 PLN/ month
up to 5 CISO days a month
  • Everything in Essentials
  • Preparation for ISO 27001 and NIS2
  • Vendor risk management
  • Oversight of rollouts and the SOC
  • Quarterly board reports
  • Incident response plan
Choose Growth

Enterprise

Priced individually
a dedicated vCISO, available on demand
  • Everything in Growth
  • A dedicated vCISO leading the work
  • Full support for audits and certification
  • Leading your team during an incident
  • Attendance at board meetings
  • SLA and availability on demand
Let's talk

Prices are net, on a monthly contract with a notice period. Can be combined with PWNONE penetration tests and audits.

Get the CISO you need today

Book a free consultation. We will assess your readiness, point out the priorities and propose a way of working together.