
Sound familiar?
"An enterprise client sent us a 200-question security questionnaire, and nobody here owns security."
- Big deals stall at the security review, and our CTO spends weeks filling spreadsheets.
- Investors and the board ask about cyber risk, and we don't have a clear answer.
- We have no written policies, so every audit or questionnaire starts from zero.
- A full-time CISO is too expensive for our size, but we can't keep ignoring this.
- We use dozens of SaaS tools and vendors, and nobody has checked how they handle our data.
Built for
What we do
What's included in Virtual CISO (vCISO).
Security Roadmap & Strategy
A 12-month plan, ranked by risk and business need, so you know what to fix first and what can wait. Reviewed every quarter.
Information Security Policies
A right-sized policy set (access control, acceptable use, incident response, vendor management and more) that your team can actually follow.
Risk Register & Risk Management
A living list of your real security risks, each with an owner, a rating and a plan. It doubles as evidence for audits.
Security Questionnaire Support
We answer customer security questionnaires and join enterprise security calls with you, so deals move instead of stalling.
Board & Investor Security Reporting
A short, plain-language update on risks, progress and incidents that founders can share with the board or investors.
Vendor Risk Management
We list the vendors that touch your data, check the risky ones and set a simple review process for new tools.
Who delivers this
Senior security people, not juniors.
Every engagement is led and advised by our security team — a serving CISO with 31+ years in technology, and a partner with security experience across India, Europe and the USA.
Principal Security Advisor
Leads this serviceA serving CISO at a global European telecom and IT services group, with 31+ years of making security a business advantage.
ISO 27001 · NIST CSF · GDPR · NIS2 · Risk & governance
Security & Compliance Partner
AdvisesA hands-on security specialist across India, Europe and the USA, covering cloud, privacy and penetration testing.
GDPR · DPDP Act · Europrivacy · OWASP · Azure security · GRC
Pricing
Transparent packages. Fixed quotes.
Your final quote is fixed after a 20-minute call — no surprise bills.
Startup
- Security roadmap and quarterly review
- Core information security policy set
- Risk register setup
- Customer security questionnaire support
- Monthly call with our security partners
Growth
- Everything in Startup
- Monthly risk review
- Board and investor security reporting
- Vendor risk management
- Joins customer security calls
- Oversight of ISO 27001 / SOC 2 / DPDP work
Regulated
- Everything in Growth
- RBI, SEBI, IRDAI or DORA requirement mapping
- Regulator and auditor meeting support
- Annual security audit planning
- Incident escalation on call
Ongoing costs after launch
No surprises: here's everything you may pay every month, stated upfront.
Compliance platform, if used (e.g. Sprinto, Vanta)
- —Security tools and SaaS subscriptions (for example, a compliance platform or endpoint protection) are paid directly by you.
- —Penetration tests, audits and certification projects are quoted separately, though the vCISO plans and oversees them.
- —Certification-body or CPA-auditor fees, if you pursue ISO 27001 or SOC 2, are paid directly by you.
- —Hours beyond your plan are billed at the plan's hourly rate, only with your approval.
Want a quick estimate for your exact project? Try the cost estimator.
Process
From first message to launch.
Clear stages, a live preview link every week, and payments tied to milestones you approve.
- Step 01Day 1
20-min call
We learn your business, your customers' demands and any deadlines. You get a fixed monthly plan.
- Step 02Weeks 1–2
Discovery
We review your systems, people and current practices, and talk to your tech lead.
- Step 03Weeks 3–4
Roadmap & quick wins
You get the 12-month roadmap, the first policies and the fixes that close the biggest gaps fast.
- Step 04Ongoing
Run the programme
Monthly hours on risk reviews, questionnaires, vendor checks and reporting. Plans are reviewed each quarter.
Technology
Tools we trust.
Our promises
Working with us is low-risk.
Fixed quote
A clear, fixed price after a 20-minute call. No surprise bills.
Pay in milestones
Projects: 40% to start, 30% on design approval, 30% at launch.
You own everything
Code, domain, ad accounts, WhatsApp number and data — in your name.
Weekly previews
See real progress on a live link every week, not just status updates.
30 days of free fixes
Anything not working as agreed after launch, we fix at no cost.
Talk to the builder
No account managers. You speak with the engineers doing the work.
FAQ
Questions, answered.
What does a vCISO cost compared with a full-time CISO?+
Our plans run from ₹60k to ₹1.75L a month, which is a fraction of a full-time CISO's cost in India. The price depends on hours, how regulated you are and how many customers or auditors need attention each month.
How quickly will we see results?+
Most clients have a roadmap, core policies and a risk register within 30 days. Questionnaire help starts in week one, because that is usually the most urgent need.
Can a vCISO get us ISO 27001 or SOC 2 certified?+
We can lead the programme and get you audit-ready, but we don't issue certificates or reports. ISO 27001 certificates come from accredited certification bodies, and SOC 2 reports from licensed CPA firms. We coordinate with them for you.
Who is the vCISO, and will we deal with a junior?+
You work directly with our senior security team, advised by a serving CISO (principal advisor) and led by our security partner with experience across India, Europe and the USA. There are no account managers in between.
Will you sign an NDA? How do you handle our data?+
Yes. We sign your NDA (or ours) before discovery. We ask for only the access we need, use your systems where possible and return or delete documents when the engagement ends.
What happens if we want to stop?+
You can cancel any month. You keep the roadmap, policies, risk register and all questionnaire answers, so a future hire or another provider can pick up where we stopped.
We are not regulated. Do we still need this?+
If you sell to larger companies, yes. Enterprise buyers ask security questions long before any regulator does. A vCISO turns those questions into a repeatable answer set and a clear plan.
Often paired with
Find out where you stand: a security maturity check, gap analysis and a 90-day fix plan.
Get audit-ready for ISO 27001:2022 and SOC 2 Type I/II: policies, evidence and auditor coordination.
Get ready for India's DPDP Act and GDPR: data map, notices, consent flows built into your site, app and WhatsApp.
Let's scope your project.
One message is enough. You'll speak directly with the engineer who builds your system — and get a fixed quote, not a sales pitch.