Picking the Virtual CISO for your business – Free eBook

Share this post

How to not pick a vCISO Provider: throwing a dart at a board
How to not pick a vCISO Provider: throwing a dart at a board

Picking the right Virtual CISO for your business is easier said than done. There are so many different vendors and individuals offering vCISO services these days that it’s hard to know where to start. We wanted to provide a guide to help businesses figure out the right type of vendor for them.

While Fractional CISO does operate in this space, we firmly believe that there is no one-size-fits-all solution in cybersecurity. We want every business to find the right cybersecurity solution for their unique needs, and so have published an ebook to help you make the right choice.

The ebook includes a quick-decision chart intended to help you quickly get in the ballpark area of what type of vCISO provider you should be looking for. A sample of the ebook and the chart is provided below.

How to pick the right type of vCISO for you chart sample

Picking a vCISO: The Story of Three CEOs

Carl, Ernie, and Sarah are three CEOs of three very different companies who meet regularly in a business leadership group to share insights and learn from one another. Recently, they have been discussing cybersecurity practices and management. Each organization is currently facing its own, very different set of cybersecurity concerns they want a leader to help them solve. 

Carl’s Consulting Company is a 100-employee consulting company specialized in technical consulting, customer experience, user retention, and rewards programs. They issue Macbooks to all employees and primarily use Google Workspace. They also use AWS in a limited capacity, where needed for certain contracts. Beyond attempts to securely configure their own systems, they have not yet paid much attention to cybersecurity. As their company has grown and built out an impressive portfolio of work, larger businesses have taken an interest in their services – but they want to see a stronger cybersecurity program in place and a SOC 2 attestation to prove it. 

Ernie’s Enterprise provides healthcare management software and has approximately 2,000 employees across three office spaces in Boston, Austin, and San Francisco. They all use company-issued desktops and laptops both Macbooks and Laptops. They have a relatively robust cybersecurity team, but were recently hit with a HIPAA violation, landing them on the dreaded “Wall of Shame.” They want to quickly replace their current CISO with someone who can set a new path forward while maintaining or improving their existing HIPAA, SOC 2, and ISO 27001 compliance efforts. 

Sarah’s SaaS Startup is a small, 15-employee company that provides a SaaS application intended for construction company administrators. They are a complete Microsoft shop, using Windows for devices, Microsoft 365, and running their product on Azure. Sarah doesn’t have any compliance needs, but is concerned about the damage a cybersecurity attack could do to her small business. 

A Virtual CISO for All Three? 

After sharing their myriad cybersecurity concerns. The mentor of the peer group, Margaret, suggests that three look into acquiring the services of a Virtual CISO provider. She explains that vCISOs are often able to perform the cybersecurity tasks an organization needs while being faster to hire and costing less than a full-time CISO.

The three start to evaluate vCISO providers only to discover that there are so many different options! They aren’t sure who to select. To help walk them through the decision, Margaret walks them through several points to consider in their evaluations, and the different types of vCISOs they could choose from. 

Download the full ebook to learn:

  1. What the five common types of vCISO providers are
  2. What specializations each vCISO provider can bring to the table
  3. The four major points to consider when making your decision
Rob Black
Rob founded Fractional CISO in 2017 and has helped dozens of mid-size SaaS and technology companies improve their security posture as a vCISO. He consults, speaks, and writes on IoT and security. Rob has held product security and corporate security leadership positions at PTC ThingWorx, Axeda and RSA Security. He received his MBA from the Kellogg School of Management and holds two Bachelor of Science degrees from Washington University in St. Louis in Computer Science and System Science and Engineering. He is also a Certified Information Systems Security Professional (CISSP).

Tales From The Click

Sign up for our monthly newsletter for business leaders on minimizing cybersecurity risk.

Suceed at SOC 2

Free eBook:
5 Things to Know for your First SOC 2

  • How to scope your SOC 2
  • Estimate the cost and length of your SOC 2
  • Prepare for your SOC 2
  • Manage the SOC 2 audit period
  • Leverage your SOC 2 for growth

Related Posts

Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales
Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales