Your board wants a security leader. Your budget disagrees.

There's a way to get executive-level security leadership without the executive-level price tag. And no, it's not by cutting corners.

Scroll to explore

The math doesn't work for most companies

A qualified CISO commands serious compensation. Add Sodra, benefits, the months-long search, and the ever-present risk they leave for a better offer once they’re trained on your systems.

NIS2 deadlines are coming up, your IT manager has “security responsibilities” added to their already-full plate and everyone pretends this arrangement is fine.

€53K Fully loaded annual cost of a senior in-house CISO

What if you could hire the expertise without hiring the person?

You get strategic oversight, compliance management, and risk governance that’s structured, repeatable, and documented from day one. Instead of betting on one person’s calendar, background, and tenure, you get a governance function that’s built to last.

Also known as: Virtual CISO, Fractional CISO, vCISO

Option A Hiring a full-time CISO
Time to compliance Slow, depends on hire
Knowledge coverage One background
Continuity risk Single point of failure
Regulatory readiness Depends on individual
Cost visibility Fixed, high
Management liability Often unclear
Annual cost – internal From €4,400/month €53,000 / year
Option B · CISO as a Service Outsourcing the governance function
Time to compliance Immediate governance
Knowledge coverage Multi-domain expertise
Continuity risk Built-in redundancy
Regulatory readiness Structured, repeatable
Cost visibility Predictable, scalable
Management liability Explicitly addressed
CISOaaS From €570/month €6,840 / year, excl. VAT

Sound familiar?

CISOaaS works best for organizations in these situations.

Budget won't stretch to a full-time

You need the expertise, but €53K+ annually isn't realistic. Most mid-sized companies face this exact constraint.

Compliance deadline approaching

With NIS2 or NKSC requirements coming up. You need someone who's done this before, without suffering through a learning curve.

IT manager playing double duty, illegally

Security must be a separate role. It can't be off-loaded to the IT person... Do companies care? No. Security gets added to their responsibilities, but they don't have the time, training, or authority to do it properly.

Your last CISO left

And of course, they took institutional knowledge with them. Now, you need consistent leadership that doesn't walk out the door for a better offer.

Rapid growth outpacing security

Scaling fast, but security infrastructure hasn't kept up. You need expertise to catch you up without slowing you down.

Building security from scratch

No formal program exists yet. You want to start right, but don't know where to begin.

Everything a security leader oversees

Eight areas covered by your security leader. Seven included in the monthly subscription, technical oversight available on request.

1 Risk & Compliance

Annual assessments, risk registers, treatment plans, legal compliance monitoring, management reporting.

2 Incident Management

Plan oversight, NKSC and other relevant authorities notifications, post-incident analysis coordination. While Your IT team handles hands-on response.

3 Business Continuity

BCP/DR oversight, RTO/RPO definitions, backup strategy, recovery testing, gap remediation.

4 Policies & Procedures

Policy oversight, document lifecycle, version control, annual reviews. Keep in mind that: Drafting new policies is available as a separate service.

ON REQUEST 5 Technical Oversight

Firewall review, endpoint monitoring, log analysis, configuration audits, detection tuning.

6 Supply Chain Security

Vendor identification, security assessments, contract reviews, ongoing risk monitoring.

7 Audit Preparation

Compliance planning, evidence collection, auditor coordination, corrective actions.

8 Training & Exercises

Security awareness, phishing simulations, management briefings, crisis exercises.

Scope that scales with your maturity. One subscription, three starting points.

The monthly fee is the same across all plans. What changes is the buildout work needed before steady-state oversight kicks in. Buildout work is charged separately and the service is scoped after the 2-3 week of NIS2 compliance assessment.

Here's what you get:
All CISO service areas NIS2 partial audit as gift Coordinating NKSC & other relevant institution notifications
From €570 /mo excl. VAT

Buildout cost depends on your maturity level

STARTING FROM ZERO
Maxi
Full implementation

No documentation, no processes, fragmented IT oversight. Everything is built from the ground up.

Scope of work (billed separately) Full implementation, then ongoing oversight
Security processes built from the ground up Initial risk assessment performed Incident management process established 21 NIS2 compliance documents drafted IT oversight structure put in place BCP/DR plans defined
Standard
Gap closure

IT basics in place, but documentation, compliance evidence, or oversight have gaps. Most common starting point.

Scope of work (billed separately) Close the gaps, then ongoing oversight
Missing policies drafted or updated BCP/DR plans defined Compliance evidence collection set up Risk assessment process bootstrapped 21 NIS2 documents available separately
Mini
Oversight

Documentation, processes, and security tooling already in place. We maintain, exercise, and grow maturity.

Scope of work (billed separately) Ongoing oversight, exercises, maturity growth
Risk register kept current, reviewed quarterly Annual policy and DR plan reviews Vendor security reviews and contract checks Crisis exercises and tabletop simulations Audit readiness maintained continuously

About the NIS2 partial audit. Included as a gift with any CISO contract: a compliance report covering the legal part and internal technical assessment guidelines. The 30-minute discovery call and the 2-3 week NIS2 compliance assessment that follow determine which plan fits your situation. Initial buildout work for the Standard and Maxi plans is scoped separately, on top of the €570/mo subscription.

What actually happens behind the buzzwords?

01
We start by mapping what matters to your business

Rather than working from a generic checklist, we identify your critical services, the ones that would genuinely hurt if they went down. And then, map out all the assets that support them, including systems, data, people, and vendors. So, we have a real foundation to build everything else on.

02
Then we figure out what could realistically go wrong

We look at internal threats as well as external ones, essentially all the things that keep your IT manager up at night, and assess each one based on likelihood and impact. Not just theoretically, but grounded in your actual environment, your industry, and your specific threat landscape.

03
The result is a prioritized risk register that people actually use

Our goal is NOT to create a 200-page report that sits in a drawer collecting dust. We want a living document that tells management exactly what your top risks are, what's being done about each one, who owns it, and when it needs to be resolved — reviewed annually and after significant changes, in language people understand.

04
And then we make sure things actually get fixed

Each risk gets a proper treatment plan where we decide whether to accept it, mitigate it, or transfer it, and if we're mitigating, there's always an owner assigned along with a deadline and someone tracking progress. So, when auditors ask how you manage risk, you have a real answer instead of an awkward shrug.

01
We start by making sure the incident plan is clear and tested

We make sure your organization has a clear, tested incident management process before anyone needs it. So when something happens at 2am, your IT team isn't inventing the response — they're following a plan that's been worked through calmly and deliberately.

02
When something happens, we activate the plan and your IT team responds

Your IT team or SOC handles the hands-on work: registering the incident, investigating, containing, and collecting evidence. We initiate the plan, coordinate the right people, and stay close to the response.

03
We handle communication with NKSC, so legal deadlines don't slip

Lithuanian law requires reporting significant incidents to NKSC within strict deadlines. We make sure that process exists, contacts are designated, and nothing falls through the cracks while your team is busy resolving the incident.

04
And then we organize root-cause analysis, so the next response is better

We organize the root-cause analysis with your team, then update the incident plan and feed findings back into your risk register. So every incident makes the next one less likely, or at least less damaging.

01
First, we define what "down" actually costs your business

We work through questions like how long your order system can be offline before customers start leaving, or how much data you can afford to lose before it becomes catastrophic. It’s important for us to get concrete numbers that end up driving every recovery decision that follows.

02
Then we oversee the BCP and DR plans, so recovery isn't improvised

We oversee that BCP and DR plans exist, are approved by management, and stay accessible during incidents. Your team executes the recovery and maintains the backups, of course we make sure the plans behind them actually hold up.

03
RTO and RPO get agreed with management, not assumed

How fast operations must be restored, and how much data you can afford to lose: these get defined with your management and written into the plan. So when something happens, recovery is all about executing a target everyone already signed off on.

04
And we test the plan periodically, so it's not a first draft when disaster hits

Recovery plans get tested periodically and after significant changes, with results documented. So when disaster strikes, you're executing a plan you've already practiced before.

01
We oversee that your security policies are clear and current

We oversee that your security policies are clear, current, and actually followed. Drafting new policy documents is available as a separate service. But, the day-to-day oversight, alignment with IT and business, and management approval coordination is part of the subscription.

02
Then we cover the core documents auditors and regulators look for

We oversee the core security documents: information security policy, access control, incident management, backup and recovery, third-party security, and user security rules. All the foundational pieces that auditors and regulators expect to find.

03
Every change is tracked, so "what was the policy in March" has a real answer

Every change gets tracked, old versions get properly archived, and staff get notified when things update. So, when someone asks "what was the policy back in March?" you can answer precisely rather than approximately.

04
And we review everything annually, so paper matches reality

Policies that were drafted 3 years ago for what was essentially a different company don't actually help anyone. So, we review everything annually, update for new threats and regulations, and make sure what's written on paper actually matches what's happening in reality.

On request
01
We start by checking your security tools are actually doing their job

This means checking that firewalls are configured correctly, EDR agents are healthy on every endpoint, and patches are being applied. Because it's not enough to have purchased the software, someone needs to continuously confirm it's actually doing its job.

02
Then we make sure your logs catch what matters and survive long enough to investigate

We make sure critical systems are sending logs somewhere useful, that suspicious events get flagged and investigated rather than ignored, and that retention policies satisfy both your security needs as well as your compliance requirements.

03
Configuration drift gets caught before it quietly becomes a vulnerability

Settings naturally drift and people make "temporary" changes that somehow become permanent, so we regularly review critical configurations, catch unauthorized modifications when they happen, and restore secure baselines when needed.

04
And detection rules get tuned to your environment, not left on default

Your SIEM rules, EDR policies, and network monitoring all get tuned based on what we're actually seeing in your environment. This means, false positives get reduced, real threats get caught, and the overall system gets smarter over time rather than going stale.

01
We map out everyone who has access to your environment

This includes every vendor, every integration, and every third party with credentials or data access — because you simply can't manage supply chain risk if you don't know who's actually in your supply chain. And, most companies end up quite surprised by how long this list turns out to be.

02
Critical vendors get proper security assessments

We skip the checkbox questionnaires that vendors get to fill out themselves and do a real evaluation of their security controls, their incident history, and their compliance status, with the vendors who could hurt you most getting the most scrutiny.

03
Then we get into the contracts, because most are surprisingly quiet on security

We look at data handling obligations, breach notification timelines, and audit rights, since many contracts are surprisingly silent on security matters. Then we identify the gaps and work with your legal team to fix them before renewal comes around.

04
And risk reports go to management in language they can act on

Rather than burying findings in technical assessments that nobody reads, we provide a clear summary of your riskiest vendors, why they're risky, and what we recommend doing about it. With all decisions properly documented so there are no surprises later.

01
Every audit and review lives on a calendar with owners assigned

NIS2 compliance audits, ISO 27001 certification, regulator inspections, customer questionnaires and internal audits, all five categories tracked continuously, with owners assigned. Keep in mind that we only prepare you for the audit, we don't perform the audit itself.

02
Evidence gets gathered as you go

Rather than assembling everything in a frantic week before the auditor arrives, we gather policies, logs, configurations, and training records on an ongoing basis. Systematic, organized and verified so the evidence package is essentially always ready.

03
Gaps get flagged early, with a clear action plan to close them

We track evidence, identify gaps, and produce an action plan for each finding across all audit types. So when the auditor walks in, the answers are already there, the gaps are already being closed, and nothing arrives as a surprise.

04
Findings actually get fixed rather than just filed away

Every finding gets assigned an owner along with a correction plan and deadline, with progress tracked until completion. So, when the next audit comes around, the same findings don't embarrassingly reappear and you're demonstrably improving rather than just repeating.

Oversight included · Delivery on request
01
Different audiences get training built for the decisions they make

All-hands security awareness is fundamentally different from management risk briefings, which is different again from specialized IT technical training. Each audience gets content that's actually relevant to the decisions they make and the responsibilities they carry instead of being a bland, boring and corporate instructional video that targets “everyone”.

02
Phishing simulations and white-hacker exercises run on a schedule

All employees get phishing simulations and cybersecurity training. White-hacker exercises stress-test what people actually do under pressure. Results are tracked over time, so improvement is can be measured.

03
Management gets crisis response exercises and executive briefings

Leadership gets crisis response exercises and executive briefings, so when something happens they know how to act. Our goal is to make all of the necessary decisions before something happens.

04
And IT personnel train with the SOC team and tools they actually use

IT personnel train on Sentinel, BTT Armour, and incident exercises with the SOC team. So when a real incident hits, your IT and the SOC aren't meeting for the first time, they've actually practiced working side by side.

Security is not the place where you want to improvise on the go. So, each area of expertise comes with a detailed level of structure behind it.

Where are our backups stored? What are our top 5 security risks? Who's in charge if we get breached? Are we compliant with NIS2? When was our last DR test? Which vendors have our data? What security clauses do our contracts include?

The goal isn't to drown you in paperwork. It's to give you answers.

Right now, these questions probably make you uncomfortable. After a few months of oversight, you’ll answer them without hesitation, because you’ll actually know.

#StayVisible #StayConsistant #StayCompliant

Let's be honest. Questions you should ask before signing anything

Common concern

"How do I know you'll actually be available when something goes wrong? You're not sitting in my office, you have other clients."

Team-backed delivery, with formal SLAs when you bundle the SOC

We don't pretend you're our only client. But our delivery is team-backed rather than dependent on a single consultant, so you're never waiting for one person's calendar to open up. For organizations that need formal written response-time guarantees (4-hour response, 8-hour resolution, 24/7 coverage), our SOC add-on provides specific SLAs backed by a 30+ person team.

Common concern

"An in-house CISO absorbs context just by being here. How can someone external really understand our business?"

We build deliberate bridges instead of relying on osmosis

You're right that we won't overhear hallway conversations, which is why we establish scheduled sync meetings, dedicated communication channels, and shared dashboards from day one. The relationship requires intentional effort from both sides. But, many clients find that structured communication actually surfaces issues faster than hoping someone notices.

Common concern

"What if you give us recommendations we can't actually implement? We don't have a big security team to execute on strategy."

Strategy without execution capability is just expensive advice

We agree, which is why we establish clear ownership boundaries upfront about what we advise versus what you execute. When implementation support is needed beyond guidance, we can connect you directly to our technical specialists who handle implementation across SOC, SIEM, IAM, and other areas. So, recommendations don't just pile up in a backlog that never gets addressed.

Common concern

"Credentials look great on paper, but how do I know we'll actually work well together?"

We map the work before you commit

Every engagement starts with a no-obligation 30-minute call where we assess your security maturity, tell you whether NIS2 applies to you, and give you a preliminary CISO price. Then a 2-3 week NIS2 compliance assessment maps your current state in detail, and the readiness report goes to your management before any long-term contract is signed.

If any of these considerations are dealbreakers for your situation, CISOaaS might not be the right model, and we'd rather you know that upfront.

Find out what scope makes sense for you

In the first conversation, we'll walk through:
1
First step: 30-minute call

We will discuss NIS2 scope, current IT situation, and timelines. No technical preparation needed from your side.

2
NIS2 Compliance Assessment: 2-3 weeks

NIS2 gap analysis, infrastructure review, and readiness report delivered to management. The 2 to 3 week timeline starts when we receive all required documents from your side.

3
Service start

After that, we can tell you whether CISOaaS fits your situation and what engagement model would make sense.
Schedule an assessment call 30 minutes - No commitment - We'll tell you if it's not a fit

Every engagement starts with a 30-minute call

The call comes with no obligation and needs no technical preparation from your side, and if CISOaaS is not the right model for you, we will tell you.

  • We assess your security maturity and talk through your current IT situation
  • We tell you whether NIS2 applies to you and which timelines you need to meet
  • We give you a preliminary CISO price for your organisation
Trusted by
ISO 27001 Sophos Syntricks
Book a 30-min call →
Skaylink
Privacy Policy

We use cookies on this website to ensure smooth website performance and improve your browsing experience. Cookies help us save your preferences, recognize returning visitors, and analyze which parts of the website are most relevant to you.

Privacy Policy