What a virtual CISO actually does
A CISO sets direction and owns risk. That means deciding what to protect, what to spend, what to accept and what to escalate, then defending those decisions in front of customers, auditors, investors and regulators.
We perform that function on a part-time basis. We are hands-on: we read your architecture, review your cloud configuration and talk to your engineers directly, not only to your management.
We are also clear about what we are not, and the boundaries are set out below. More often than not, though, the specialists are already there and what is missing is the layer above them: someone accountable for the strategy they execute.
What we own, what stays with you
The most common reason a part-time arrangement fails is that nobody agreed the boundary. This is ours, written down before the contract is signed rather than discovered in month four.
What we deliver
Over a typical first three to six months, depending on the hours contracted:
What you are left holding
Every engagement produces documents your own team can maintain after we stop. They are written in your language, sized for your company, and built to survive an auditor reading them line by line.
How the engagement works
Who this is for
Startups and small companies running entirely in the cloud. Small and medium businesses holding sensitive data. High-risk practices such as law firms and medical practices. Our sector focus is healthtech and medtech, fintech, and B2B SaaS selling into regulated buyers.
We do not work with large enterprises. An organisation of several thousand people needs a full-time CISO and a team, and we will tell you that rather than sell you a fraction of one.
Why not simply hire
A full-time CISO in Europe is a six-figure commitment before tooling and recruitment costs, and most companies under 200 people do not have enough work to fill the post.
The usual alternatives are a large consultancy that delivers a report and leaves, or a compliance platform that automates evidence collection but cannot make a judgement call for you. A virtual CISO sits between them: senior judgement, continuity, and one person who stays accountable for the outcome.
The names people use for this
Five terms circulate for broadly the same arrangement, and the differences that matter are about permanence and scope rather than seniority. Part-time CISO and on-demand CISO turn up too, meaning the same thing again. We answer to all of them.
Questions we get asked
Book a free 30-minute consultation
Tell us what triggered your search: the blocked deal, the questionnaire, the audit date, the investor request. We will tell you what it would realistically take, and whether we are the right people to do it.
vciso@metaluxo.com