Proposal
CISO Insight
A twelve month programme with a dedicated CISO Advisor, the chief information security officer role in an advisory seat: a weekly executive meeting, a monthly report for the board and two maturity assessments, one at the start and one at the end. The second exists for one reason, to show side by side with the first how far the company has moved. This is the route for anyone who has to prove progress to a board, a customer or an auditor, beyond simply having someone to consult.
No price appears on this page. Scope does: what we do, how we run it, who runs it and what is not included. The people who read your request are the ones who will look after you, and they come back with the proposal and with time to talk it through.
CISO Insight
A year of executive presence, with the progress proven on paper.
How we run it
What this work consists of
It is a fixed twelve-month program with a dedicated CISO Advisor: one executive meeting per week, a monthly report written for the board, and two maturity assessments, one at kickoff and one at close. The second exists for one purpose only: to prove, side by side with the first, how far the company moved during the year.
The work opens with the initial diagnostic, the baseline everything gets measured against. From there, the engine is the cadence. The weekly meeting keeps the topic alive between one session and the next, and the monthly report translates progress into the language of decision makers. At close, the evolution roadmap points to the next period.
On your side, the program asks for leadership's time at the weekly meeting and access to people and evidence during both assessments. It is little time, but it is the right time: without decision makers in the room, any advisor becomes a hallway consultant. At the end you receive the evidence-backed comparison, the material that convinces boards, clients, and auditors.
The two options differ in who executes. In executive advisory, the advisor guides and your team does the work. In the option with execution, a bank of hours lets the advisor unblock what is missing: answering a client security questionnaire, supporting an audit on site, writing the document nobody had time to write.
How we conduct it, stage by stage
Opening assessment
A snapshot of the starting point: what exists, what is written down and what actually works. Progress will be measured against it at the end of the period, so we record it with method, not from memory.
Executive follow-up
A weekly meeting with the leadership, a monthly report and an alert when something changes. The rhythm is what moves security forward between one meeting and the next.
Proof of progress
A fresh assessment, a side by side comparison and a presentation of what changed in the period, with evidence.
What is not included
- Day-to-day operation of tools and monitoring, which belongs to the technical team or a managed operations provider
- Statutory executive liability for the company, which cannot be outsourced
- Large implementation projects, which are scoped separately when the bank of hours cannot cover them
- Technical testing, such as pentests and phishing simulations, which are separate services; the advisor tells you when to run them and reads the results with you
- On-call incident response, which is emergency operations and does not fit in one executive hour per week
- Day-to-day execution in the advisory option: there the advisor guides and follows up, and your team does the work
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.