Metaluxo
VIRTUAL CISO FOR SMALL BUSINESS

You run the business.
We handle the security.

A CISO is the person accountable for security decisions. A full-time one costs six figures, and most companies under 200 people cannot fill the role. We do the job part time instead — security leadership, ISO 27001 and incident response, for small and medium businesses across the EU.

Book a review with Roberto How vCISO works
THREAT MONITOR EMEA REGION · ILLUSTRATIVE VIEW
INTRUSIONS BLOCKED · 30 DAYS 0
PROTECTED SYSTEMS
Attempted intrusion Protected site
ILLUSTRATION — NOT LIVE TELEMETRY
ISO 27001 SOC 2 EU GDPR CYBER ESSENTIALS · IN PROGRESS NIS2 READINESS
ISO 27001 SOC 2 EU GDPR CYBER ESSENTIALS · IN PROGRESS NIS2 READINESS
WHY COMPANIES CALL US

Almost nobody goes looking for this until something forces it

It is usually one specific thing, and it has a deadline attached. These six cover nearly every company that gets in touch — if one of them sounds familiar, you are in the right place.

01 A deal is blocked An enterprise buyer will not sign until you can evidence a real security programme, a certification, or credible answers to their assessment. CLOCKUntil signature
02 A questionnaire has landed Forty pages, and nobody whose job it is to answer it. It reaches the founder by default, at eleven at night. CLOCKTwo weeks, typically
03 Due diligence is underway An investor or acquirer is examining how you govern security, and the answers need to hold up under scrutiny. CLOCKThe data room date
04 The board wants assurance Someone has to own security risk, and it cannot keep sitting with the CTO by default. CLOCKNext board meeting
05 A regulator is asking questions Deadlines are short and the response has to be right the first time. There is rarely a second draft. CLOCKSet by the authority
06 Insurance renewal Cyber insurers now ask detailed control questions and price the policy accordingly. CLOCKThe renewal date
Every one of these needs the same thing: one person who owns the answer and is accountable for it. That is the job we do.
WHAT WE DO

Four services, one accountable owner

vCISO & interim CISO A virtual CISO: someone senior owning your security without a full-time hire. You get the risk register, the security roadmap, the policies and the board reporting — plus the answers to the security questionnaires your buyers are waiting on. ENGAGED AS30–40 hrs a month, or fixed scope Read more →
Compliance The certifications enterprise buyers ask for before they sign. ISO 27001 end to end, SOC 2 Type II readiness and the security duties GDPR puts on you — run as a project with a real date on it. TYPICAL PATH~9 months to ISO 27001 Stage 2 Read more →
Emergency response Incident response for when you have been breached and nobody is in charge. We contain it, keep you inside the legal deadlines for reporting it, and brief the specialists properly. RESPONSEWithin 12 hours, often faster in CET Read more →
Blockchain security Security governance for regulated crypto businesses: key management and custody — how keys and customer assets are actually protected — plus insider risk and the security sections of MiCA and DORA. OUT OF SCOPEWe do not audit smart contracts Read more →
WHO IT'S FOR

Companies held to big-company security standards, without a big-company security team

Four sectors, because the rules, the buyers and the questions are different in each one.

Clinician reviewing patient data on a tablet
HEALTHCARE Healthcare & healthtech
Patient data carries the highest consequences and the tightest supplier scrutiny under GDPR Article 9 and NIS2. We help healthtech and medtech teams build the assurance pack hospital and health-system buyers expect, settle their NIS2 position, and prepare for procurement review before it becomes a blocker. USUALLY IN PLAYGDPR Article 32, ISO 27001, supplier assurance WHO CALLSFounders answering a health system’s security review Read more →
Market data on a phone screen
FINTECH Fintech
Payments and financial data companies answer to buyers, investors, and regulators at the same time, with DORA now supervised rather than advisory. We help fintech teams run the DORA gap assessment, build the third-party ICT register, and get ahead of the security review that comes with every raise or enterprise deal. USUALLY IN PLAYSOC 2 Type II, ISO 27001, DORA WHO CALLSCTOs facing a bank or PSP due-diligence pack Read more →
Source code on a monitor
B2B SAAS B2B SaaS, startups and SMEs
The first enterprise deal, funding round, or breach all raise the same questions, usually with a deadline attached. We help B2B SaaS teams with no security hire yet decide what they actually need (ISO 27001, SOC 2, or neither), unblock the deal in front of them, and build a programme sized for their headcount. USUALLY IN PLAYISO 27001, security questionnaires, insurance renewals WHO CALLSFounders and CTOs with no security hire yet Read more →
Digital asset on a market chart
DIGITAL ASSETS Blockchain and digital assets
Regulated crypto businesses need someone accountable for security across the whole organisation, not just the smart contract layer. We provide security leadership, key management and custody governance, and the ICT and security sections DORA and MiCA require, for exchanges, custodians, wallet providers, and payment firms. USUALLY IN PLAYMiCA security sections, DORA, key management policy WHO CALLSCompliance leads preparing an authorisation file Read more →
Roberto Arias, founder of Metaluxo
Roberto Arias Founder · Virtual CISO and GRC consultant
WHO RUNS IT

One named person, on every engagement

Metaluxo is led by Roberto Arias: nearly 20 years in IT, 14 of them in information security and five as a fractional CISO, with a Master's in Information Security. The person who scopes your engagement is the person who reads your architecture and talks to your engineers.

20 YEARS
IN IT
14 IN INFORMATION
SECURITY
5 AS A FRACTIONAL
CISO
More about Roberto →
QUESTIONS

The ones we get asked first

If yours is not here, ask it directly — replies come from Roberto, not a form queue.

Ask a question →
What is the difference between a virtual CISO and a full-time CISO?
The responsibilities are the same. The difference is commercial: you buy a defined number of hours a month instead of a salaried post, and you scale them up or down as your obligations change. Most clients start between 30 and 40 hours.
Why not simply hire a full-time CISO?
A full-time CISO in Europe is a six-figure commitment before tooling and recruitment costs, and most companies under 200 people do not have enough work to fill the post. A virtual CISO sits between that and a consultancy report: senior judgement, continuity, and one person who stays accountable for the outcome.
How long does ISO 27001 certification take?
Around nine months is a reasonable planning assumption for a small cloud-based company, but it varies widely with contracted hours, scope and how quickly your team responds. We give you a realistic date after the gap assessment, not before.
Can you guarantee we pass the audit?
No, and nobody honestly can. Only an accredited certification body issues the certificate. What we can do is make sure nothing reaches Stage 2 that we have not already tested ourselves. If you have already failed or stalled an attempt, that is a common starting point.
Do you work with compliance platforms such as Vanta or Drata?
We are platform agnostic. We will work inside whichever tool you already pay for, and we will tell you honestly if the subscription is not earning its keep at your size. Automation collects evidence well; it cannot scope your ISMS or make a risk decision for you.
We are dealing with an incident right now. What do we do?
Email emergency@metaluxo.com with INCIDENT in the subject line: what you are seeing, when you noticed it, whether personal data may be involved, and a phone number. We respond within 12 hours and frequently much faster in CET business hours. Contracting can be completed the same day.

Book a free 30-minute consultation

Tell us what triggered your search: the blocked deal, the questionnaire, the audit date, the investor request. We will tell you what it would realistically take, and whether we are the right people to do it. Most engagements then start with a fixed-scope gap assessment of around four weeks.

Email Roberto
FIRST CALL 30 MIN
That did not go through. Please write to vciso@metaluxo.com directly — we will still reply within a working day. Thank you — your message is on its way. Roberto replies within one working day. No slide deck, no discovery call chain — one conversation with Roberto.
Send us a message
Message us Book now