Tenth Floor Labs

Secure — Virtual CISO (vCISO)

A virtual CISO who owns your security, without a full-time hire

Our virtual CISO service gives you a senior security leader for a few hours each month. We build your security roadmap and policies, keep a risk register, answer customer security questionnaires and join enterprise security calls. It suits startups and SMEs selling to larger clients.

Mon–Sat · 9am–8pm IST
Starting from
₹30k/mo
per month · cancel any month
Timeline
Roadmap in 30 days, then ongoing
typical
After launch
The vCISO retainer is monthly (₹30k–1.75L), cancel any month
Maulik Gupta, Founder & Lead Engineer
Maulik Gupta
Founder & Lead Engineer · you'll talk to me

Sound familiar?

"An enterprise client sent us a 200-question security questionnaire, and nobody here owns security."

  • Big deals stall at the security review, and our CTO spends weeks filling spreadsheets.
  • Investors and the board ask about cyber risk, and we don't have a clear answer.
  • We have no written policies, so every audit or questionnaire starts from zero.
  • A full-time CISO is too expensive for our size, but we can't keep ignoring this.
  • We use dozens of SaaS tools and vendors, and nobody has checked how they handle our data.

Built for

B2B SaaS startups selling to enterprises in India, the US or EuropeFintech, health-tech and insurance-tech companies under regulator scrutinyFunded startups preparing for due diligence or board reportingIT services and BPO firms whose clients demand security assuranceSMEs that have outgrown an 'IT person handles security' setupCompanies starting ISO 27001, SOC 2 or DPDP work and needing an owner

What we do

What's included in Virtual CISO (vCISO).

01

Security Roadmap & Strategy

A 12-month plan, ranked by risk and business need, so you know what to fix first and what can wait. Reviewed every quarter.

02

Information Security Policies

A right-sized policy set (access control, acceptable use, incident response, vendor management and more) that your team can actually follow.

03

Risk Register & Risk Management

A living list of your real security risks, each with an owner, a rating and a plan. It doubles as evidence for audits.

04

Security Questionnaire Support

We answer customer security questionnaires and join enterprise security calls with you, so deals move instead of stalling.

05

Board & Investor Security Reporting

A short, plain-language update on risks, progress and incidents that founders can share with the board or investors.

06

Vendor Risk Management

We list the vendors that touch your data, check the risky ones and set a simple review process for new tools.

Who delivers this

Senior security people, not juniors.

Every engagement is led and advised by our security team — a serving CISO with 31+ years in technology, and a partner with security experience across India, Europe and the USA.

Principal Security Advisor

Leads this service
Serving CISO · 31+ years in technology

A serving CISO at a global European telecom and IT services group, with 31+ years of making security a business advantage.

Serving CISO31+ years in technologyMulti-country security governanceBoard-level risk reporting

ISO 27001 · NIST CSF · GDPR · NIS2 · Risk & governance

Security & Compliance Partner

Advises
India · Europe · USA

A hands-on security specialist across India, Europe and the USA, covering cloud, privacy and penetration testing.

3 continentsCloud & privacy securityPublished IoT security researcherAzure security certified

GDPR · DPDP Act · Europrivacy · OWASP · Azure security · GRC

Pricing

Transparent packages. Fixed quotes.

Your final quote is fixed after a 20-minute call — no surprise bills.

Startup

₹30k/mo
per month · ≈8–10 hours
  • Security roadmap and quarterly review
  • Core information security policy set
  • Risk register setup
  • Customer security questionnaire support
  • Monthly call with our security partners
Get this quote
Recommended

Growth

₹1L/mo
per month · ≈16–20 hours
  • Everything in Startup
  • Monthly risk review
  • Board and investor security reporting
  • Vendor risk management
  • Joins customer security calls
  • Oversight of ISO 27001 / SOC 2 / DPDP work
Get this quote

Regulated

₹1.75L/mo
per month · fintech & health
  • Everything in Growth
  • RBI, SEBI, IRDAI or DORA requirement mapping
  • Regulator and auditor meeting support
  • Annual security audit planning
  • Incident escalation on call
Get this quote

Ongoing costs after launch

No surprises: here's everything you may pay every month, stated upfront.

With us

The vCISO retainer is monthly (₹30k–1.75L), cancel any month

See all ongoing plans
Paid to third parties, at cost, no markup

Compliance platform, if used (e.g. Sprinto, Vanta)

  • —Security tools and SaaS subscriptions (for example, a compliance platform or endpoint protection) are paid directly by you.
  • —Penetration tests, audits and certification projects are quoted separately, though the vCISO plans and oversees them.
  • —Certification-body or CPA-auditor fees, if you pursue ISO 27001 or SOC 2, are paid directly by you.
  • —Hours beyond your plan are billed at the plan's hourly rate, only with your approval.

Want a quick estimate for your exact project? Try the cost estimator.

Process

From first message to launch.

Clear stages, a live preview link every week, and payments tied to milestones you approve.

  1. Step 01Day 1

    20-min call

    We learn your business, your customers' demands and any deadlines. You get a fixed monthly plan.

  2. Step 02Weeks 1–2

    Discovery

    We review your systems, people and current practices, and talk to your tech lead.

  3. Step 03Weeks 3–4

    Roadmap & quick wins

    You get the 12-month roadmap, the first policies and the fixes that close the biggest gaps fast.

  4. Step 04Ongoing

    Run the programme

    Monthly hours on risk reviews, questionnaires, vendor checks and reporting. Plans are reviewed each quarter.

Technology

Tools we trust.

ISO 27001:2022SOC 2NIST CSF 2.0CIS ControlsDPDP Act 2023GDPRCERT-In DirectionsRBI Cyber Resilience DirectionsSEBI CSCRFDORANIS2

Our promises

Working with us is low-risk.

Fixed quote

A clear, fixed price after a 20-minute call. No surprise bills.

Pay in milestones

Projects: 40% to start, 30% on design approval, 30% at launch.

You own everything

Code, domain, ad accounts, WhatsApp number and data — in your name.

Weekly previews

See real progress on a live link every week, not just status updates.

30 days of free fixes

Anything not working as agreed after launch, we fix at no cost.

Talk to the builder

No account managers. You speak with the engineers doing the work.

FAQ

Questions, answered.

What does a vCISO cost compared with a full-time CISO?+

Our plans run from ₹60k to ₹1.75L a month, which is a fraction of a full-time CISO's cost in India. The price depends on hours, how regulated you are and how many customers or auditors need attention each month.

How quickly will we see results?+

Most clients have a roadmap, core policies and a risk register within 30 days. Questionnaire help starts in week one, because that is usually the most urgent need.

Can a vCISO get us ISO 27001 or SOC 2 certified?+

We can lead the programme and get you audit-ready, but we don't issue certificates or reports. ISO 27001 certificates come from accredited certification bodies, and SOC 2 reports from licensed CPA firms. We coordinate with them for you.

Who is the vCISO, and will we deal with a junior?+

You work directly with our senior security team, advised by a serving CISO (principal advisor) and led by our security partner with experience across India, Europe and the USA. There are no account managers in between.

Will you sign an NDA? How do you handle our data?+

Yes. We sign your NDA (or ours) before discovery. We ask for only the access we need, use your systems where possible and return or delete documents when the engagement ends.

What happens if we want to stop?+

You can cancel any month. You keep the roadmap, policies, risk register and all questionnaire answers, so a future hire or another provider can pick up where we stopped.

We are not regulated. Do we still need this?+

If you sell to larger companies, yes. Enterprise buyers ask security questions long before any regulator does. A vCISO turns those questions into a repeatable answer set and a clear plan.

Let's scope your project.

One message is enough. You'll speak directly with the engineer who builds your system — and get a fixed quote, not a sales pitch.

Call WhatsApp us