Metaluxo
VIRTUAL CISO

Security leadership without a full-time hire

A part-time CISO with full-time accountability. Metaluxo provides virtual CISO services to small and medium businesses across the EU, with a particular focus on healthtech, fintech and cloud-native teams handling sensitive data.

Book a free 30-minute consultation
30–40HOURS A MONTH
~4 wksTO A GAP ASSESSMENT
1NAMED PERSON, NOT A TEAM
EN / ESREMOTE ACROSS THE EU
01

What a virtual CISO actually does

A CISO sets direction and owns risk. That means deciding what to protect, what to spend, what to accept and what to escalate, then defending those decisions in front of customers, auditors, investors and regulators.

We perform that function on a part-time basis. We are hands-on: we read your architecture, review your cloud configuration and talk to your engineers directly, not only to your management.

We are also clear about what we are not, and the boundaries are set out below. More often than not, though, the specialists are already there and what is missing is the layer above them: someone accountable for the strategy they execute.

02

What we own, what stays with you

The most common reason a part-time arrangement fails is that nobody agreed the boundary. This is ours, written down before the contract is signed rather than discovered in month four.

We own
The security strategy and the roadmap, including the order things happen in The risk decisions: what is accepted, what is treated, what is escalated to your board Compliance oversight, and answering for it in the audit Reporting to your board, your investors and your customers Choosing and directing the specialists you need, and holding them to a scope
Stays with you
Building and running the systems — your engineers implement, we review The budget, and the decision to spend it Day-to-day IT operations and support Legal positions and anything filed with a regulator, via your counsel Final accountability at board level, which cannot be outsourced and should not be
03

What we deliver

Over a typical first three to six months, depending on the hours contracted:

Assess FIRST WEEKS
Gap assessment against the framework that matters to you: ISO/IEC 27001, SOC 2, GDPR, or a specific customer’s requirements
A risk register your board can actually read, with named owners and dates
Build MONTHS 2–6
A prioritised security roadmap tied to budget and business milestones
The policy set your auditors and your customers will ask to see
A third-party and vendor risk process, covering cloud and AI suppliers
An incident response plan, tested through a tabletop exercise
Run ONGOING
Support answering customer security questionnaires, RFPs and due diligence requests
Board and investor reporting you can reuse each quarter
Tooling and budget recommendations, with no reseller commissions behind them
04

What you are left holding

Every engagement produces documents your own team can maintain after we stop. They are written in your language, sized for your company, and built to survive an auditor reading them line by line.

Risk register Named owners, agreed treatment and review dates. Written to be read at a board meeting, not filed.
Statement of Applicability Every Annex A control, included or excluded, each with a justification that survives questioning.
Security roadmap Sequenced against budget and business milestones, so the order can be defended as well as the content.
Policy set The documents auditors and customers ask to see, reflecting how you actually work rather than a template.
Board reporting pack A quarterly format you can reuse without us, so security stays a standing item rather than an incident.
05

How the engagement works

1Free 30-minute consultation. What triggered the call, what the deadline is, and whether a vCISO is genuinely the right answer.
2Scoping. A short written proposal setting out scope, hours and deliverables.
3Discovery. Two to four weeks to understand your systems, contracts, obligations and existing controls.
4Roadmap and execution. We work the plan alongside your team on a fixed reporting rhythm.
5Escalation. An incident, a regulator or a certification deadline changes the schedule, and we reprioritise to meet it.
Engagements run either as a monthly retainer, typically 30 to 40 hours a month, or as a fixed-scope project with a single agreed fee. Rates are quoted per engagement and depend on scope, complexity and contract length. Work is remote, with travel within the EU when being in the room matters. We work in English and Spanish.
06

Who this is for

Startups and small companies running entirely in the cloud. Small and medium businesses holding sensitive data. High-risk practices such as law firms and medical practices. Our sector focus is healthtech and medtech, fintech, and B2B SaaS selling into regulated buyers.

We do not work with large enterprises. An organisation of several thousand people needs a full-time CISO and a team, and we will tell you that rather than sell you a fraction of one.

07

Why not simply hire

A full-time CISO in Europe is a six-figure commitment before tooling and recruitment costs, and most companies under 200 people do not have enough work to fill the post.

The usual alternatives are a large consultancy that delivers a report and leaves, or a compliance platform that automates evidence collection but cannot make a judgement call for you. A virtual CISO sits between them: senior judgement, continuity, and one person who stays accountable for the outcome.

08

The names people use for this

Five terms circulate for broadly the same arrangement, and the differences that matter are about permanence and scope rather than seniority. Part-time CISO and on-demand CISO turn up too, meaning the same thing again. We answer to all of them.

Virtual CISO (vCISO) A senior security leader engaged part-time and remotely, accountable for the same decisions as a permanent CISO. The most common term, and the one we use.
Fractional CISO The same function, described by how it is bought: a defined fraction of a full-time post, typically 30 to 40 hours a month. In practice interchangeable with virtual CISO.
Interim CISO A temporary appointment covering a specific gap — a departure, a parental leave, or the run-up to hiring a permanent CISO. Distinguished by being time-boxed and usually more hands-on.
CISO as a service A packaged, subscription-style version of the same thing. The label tends to signal a productised offer with a fixed deliverable list rather than judgement applied to your situation.
Outsourced security leadership The umbrella phrase, used most often by buyers writing a procurement brief. Broader than the others: it can cover the CISO function, a security manager, or a whole managed programme.
The distinction worth caring about is a different one: whether the person is accountable for the outcome or delivering an output. A consultancy report is an output. Sitting in the audit and answering for the decision is accountability.
WHAT WE DO NOT DO Being told you need someone else is part of what you are paying for
Not a testing firm We do not carry out penetration testing. We define what needs testing, help you select and brief a qualified provider, review the findings and make sure remediation happens.
Not a security engineering team Some companies looking for a vCISO in fact need a tester or an engineer. We will say so in the first call rather than take the contract.
Not for large enterprises Several thousand people needs a full-time CISO and a team. We will tell you that rather than sell you a fraction of one.
THE DELIVERABLE

One page your board can actually read

Every engagement reports the same way: where you stand, the Annex A controls behind it, and the date of the next review. Written for the board, not for the auditor.

The full findings sit underneath it. The page above is what gets read in the meeting.

4 WEEKS TO
FINDINGS
93 ANNEX A
CONTROLS
1 PAGE FOR
THE BOARD
Ask to see the format
SECURITY POSTURE
ISO 27001
62 /100
29 PTS
BASELINE 62 TARGET 90
Access control A.9
Incident response A.16
Supplier risk A.15
Cryptography A.10
NEXT REVIEW 14 AUG ILLUSTRATION
4 WEEKS TO
FINDINGS
93 ANNEX A
CONTROLS
1 PAGE FOR
THE BOARD
FAQ

Questions we get asked

What is a virtual CISO? A virtual CISO is a senior security leader engaged part-time, accountable for the same decisions as a permanent Chief Information Security Officer. In practice that means owning your security strategy, your risk decisions and your answers to customers, auditors and regulators — without the cost of a full-time executive hire. The terms fractional CISO, part-time CISO, on-demand CISO and CISO as a service describe broadly the same arrangement.
When should a company hire one? Almost always in response to a specific event rather than a general ambition: an enterprise buyer blocking a deal until you can evidence a security programme, a funding round or acquisition bringing due diligence, a regulator asking questions, an insurance renewal, a first serious customer security questionnaire, or an incident. If none of those has happened yet, a gap assessment is usually the cheaper starting point.
How much does a virtual CISO cost? The commercial model is a monthly retainer scoped to your obligations — typically 30 to 40 hours a month — or a fixed-scope project with one agreed fee. What moves the number is scope, complexity and contract length, so we quote per engagement after the first conversation rather than publishing a rate card that would be wrong for most of the companies reading it. For comparison, a full-time CISO in Europe is a six-figure commitment before tooling and recruitment.
What is the difference between a virtual CISO and a full-time CISO? The responsibilities are the same. The difference is commercial: you buy a defined number of hours a month instead of a salaried post, and you scale them up or down as your obligations change.
How many hours a month do we need? Most clients start between 30 and 40. A certification deadline, a regulatory response or an incident can justify more for a defined period.
Do you carry out penetration testing? No. We define what needs testing, help you select and brief a qualified provider, review the findings and make sure remediation actually happens.
Can you take us through ISO 27001 or SOC 2? Yes. We run the programme, prepare the evidence and manage the relationship with the certification body or audit firm. We are not the certification body, and no consultant can guarantee a certificate.
Do you work with compliance platforms such as Vanta or Drata? We are platform agnostic. We will work inside whichever tool you already use, or advise on whether one is worth the cost at your size.
Where are you based? We are based in Poland and work remotely with clients across the EU and beyond, travelling within the EU for meetings where it makes a difference. We work in English and Spanish.
How quickly can you start? Usually within a few weeks. If you are facing an incident or a regulator deadline, say so in your first message and we will tell you honestly whether we have the capacity to help.
RELATED SERVICES Compliance → Emergency response → Blockchain security →

Book a free 30-minute consultation

Tell us what triggered your search: the blocked deal, the questionnaire, the audit date, the investor request. We will tell you what it would realistically take, and whether we are the right people to do it.

vciso@metaluxo.com
FIRST CALL 30 MIN
That did not go through. Please write to vciso@metaluxo.com directly — we will still reply within a working day. Thank you — your message is on its way. Roberto replies within one working day. No slide deck, no discovery call chain — one conversation with Roberto.
Who it is for

Sectors we do this in

FintechPayments and financial data companies under DORA and ICT risk rulesHealthcare & HealthTechSpecial category patient data, NIS2 duties and hospital procurement reviewsStartups & SMEsBlocked enterprise deals, security questionnaires and investor due diligence
Send us a message
Message us Book now