Who it is for
- Healthcare, legal, financial, and professional services
- Defense contractors and government-adjacent firms
- SaaS and MSP teams
- Companies that need security leadership before hiring a full-time CISO
Problem
Security decisions often stall because nobody owns risk, compliance, vendors, incident readiness, and executive communication at the same time.
vCISO base tiers
Choose the level of security leadership, compliance support, and incident readiness that fits your operating reality. Each tier is a starting point for scoping the right cadence, coverage, and business outcome. AI governance attaches to any tier as an add-on (above).
| Features |
Essentials
For small offices
|
Professional
Most popular
|
Enterprise
Best for multi-location
|
| Starting at |
$4,500/month | $7,500/month | Custom scoped |
| vCISO hours |
1 hour | 3-5 hours | 10+ hours |
| Compliance readiness |
Baseline | Quarterly snapshots | Full program build-out |
| Vendor risk audits |
Scoped as needed | Included | Included plus escalation |
| Incident response |
On-call guidance | Included planning | 24/7 coverage planning |
| Support |
Email / business hours | Phone + email | Dedicated SLA planning |
| Deployment |
Customer-supplied hardware to a certified spec; managed appliance optional | Customer-supplied hardware to a certified spec; managed appliance optional | Customer-supplied hardware to a certified spec; managed appliance optional |
Starting-at pricing is a budgetary qualifier for light retainer support. Professional and enterprise tiers scale by scope, urgency, regulatory exposure, and required coverage. Partner ecosystem support includes Dell, ASUS, Acer, Lenovo, Microsoft, MSI, Carahsoft, D&H, and others for hardware and software integration where the engagement requires it.
AI Governance (add it to any vCISO retainer)
Adopt AI without losing control of it. Your team wants modern AI, but your contracts and CUI obligations do not disappear because a chatbot is convenient. We help you stand up an AI governance program, governed workflow enablement rather than unchecked automation, aligned to NIST AI RMF and ISO/IEC 42001. A governed AI posture includes an AI risk assessment, an acceptable-use policy, data-handling rules, human-oversight design, a model-risk register, and safe-use training: the practice of using AI deliberately, with a human in the loop. It attaches to any vCISO tier as an additional offering.
AI Governance Assessment
Starting at
$7,500 (one-time)
A fixed-scope read of your AI risk and governance posture against NIST AI RMF and ISO 42001, with findings and a prioritized roadmap.
What's included
- AI-use inventory
- Acceptable-use policy
- Data-handling rules
- Human-oversight design
- A prioritized governance roadmap
Quote-based. Add $2,500 for 11 to 25 use cases; custom above 25.
vCISO AI Add-On
From $2,000/month
An ongoing AI-governance cadence attached to any vCISO retainer: acceptable-use policy upkeep, a model-risk register, new-tool vetting, and oversight reviews.
What's included
- Acceptable-use policy upkeep
- Model-risk register upkeep
- New-tool vetting and workflow review
- Ongoing oversight reviews as your AI use grows
Recurring: Essentials $2,000/month, Professional $3,500/month, Enterprise scoped. Attaches to any vCISO tier.
What we deliver
- Cybersecurity roadmap and policy design
- Audit readiness consultation
- Incident response planning and leadership
- Vendor risk and supply chain reviews
- Compliance guidance across HIPAA, ABA, GLBA, SOC, FedRAMP, CMMC, PCI, and NIST contexts
Engagement model
- Essentials: baseline security leadership and quarterly guidance
- Professional: recurring vCISO hours, vendor risk, and quarterly readiness snapshots
- Enterprise: deeper program build-out, incident escalation, and dedicated SLA planning
- All tiers are scoped to the organization, regulatory exposure, and operational need
Outcomes
- Security decisions with executive context
- Compliance operations that do not sit idle
- Incident response leadership before an event