vCISO, security leadership under contract
Most organisations do not need a full-time security director, but someone who sets the direction, reports to the board and makes sure deadlines are met.
Why the role exists at all
The Act requires somebody to be accountable by name, and the Regulation that this person is not in a conflict of interest.
Article 29 of the Act places responsibility for the measures on the management body, and it cannot be passed to IT or to an outside contractor. But the management body cannot discharge that responsibility on its own either, because doing so requires somebody who tracks the state of things month by month, measures it and reports on it.
The Regulation spells this out. Sub-measure 1.4 requires established roles and responsibilities, sub-measure 1.6 the appointment of a person operationally responsible for cyber security, and sub-measure 1.5 the separation of roles that could create a conflict of interest. The last two are binding from the medium level upwards. Sub-measure 1.7 then requires annual reporting to the responsible persons on the state of cyber security, and sub-measure 1.8 security metrics.
Separation of roles is why the head of IT is often not a good fit for this role. The same person should not both implement a measure and judge whether it has been implemented. A vCISO is not in that reporting line but answers to the management body.
We contract a monthly volume of hours and clear deliverables, with no open-ended advice. Anything that does not appear in the report to the management body has not been done.
Which sub-measures the role covers
It does not cover them all, but it covers exactly those that need a standing person rather than a one-off project.
Sub-measures 1.5 and 1.6 are binding at the medium and advanced levels and voluntary at the basic level. The same applies to sub-measure 1.8. Which level binds you is set by the national risk assessment during categorisation.
What the contract carries
Six deliverables that repeat on an agreed rhythm, plus hours for whatever comes up unplanned.
A regular report to the management body, in the language of decisions
What has changed, which risks are open, what we are asking to have approved and what it costs. No technical vocabulary and no tool lists. The report goes to a meeting and leaves minutes, which are themselves the evidence for sub-measure 1.7.
Oversight of the thirteen measures
We track the state of each sub-measure and flag whatever has slipped. The role is not to implement the measures instead of your people, but to know where each one stands and whose turn it is.
Risk register and treatment plan
We keep the register alive rather than as a document opened before an audit. A new project, a new supplier and every incident go into the register, because those are the three most common sources of new risk.
Taking part in the cyber security committee
Where a committee exists we take part in its work and prepare the materials. Where none exists we help set one up, because decisions with no body to take them usually are not taken.
Supplier and contract clause reviews
We maintain the register of direct suppliers and track whether they meet the security clauses in their contracts. This is the measure most easily neglected and hardest to catch up on, because it requires negotiation.
Support during an incident and its reporting
We guide you through assessing whether the incident is significant, through reporting within the 24 and 72 hour deadlines, and through communication to the board and to service recipients. Availability and response time are set in the contract, while technical recovery is done by your team or your contractor.
Three roles that get confused
The difference is not formal, because it determines who may sign what.
Frequently asked questions
The questions we are asked most often before we start.
How many hours a month?
It depends on size and maturity. For a mid-sized organisation a few days a month is usually enough, with more at the start while the risk register and the plan are set up. The volume is contracted and changes by agreement, not quietly.Does a vCISO satisfy sub-measure 1.6?
The sub-measure requires the appointment of a person operationally responsible for cyber security. The appointment is made by the management body’s own decision, and the person may be external, under a contract that clearly sets out responsibilities and availability. What matters is that a decision, a description of responsibilities and a trail of that person’s work all exist.Does this transfer responsibility to you?
No. Article 29 of the Act places responsibility on the management body and no contract transfers it. The same applies where an external provider runs the systems, under Article 26(4). Our responsibility is contractual, towards you, not towards the authority.How quickly can you start?
From the first call to starting work usually takes two weeks, the time needed for a proposal and a signed confidentiality agreement. The first month is always denser, because it covers the picture of the current state.Do you work alongside an existing security lead?
We do. In that case we do not take over the role but support the person already appointed, most often on reporting to the board, on the risk register and on audit preparation.Can the same person be both vCISO and data protection officer?
As a rule no, because the data protection officer must be independent and must not end up supervising their own decisions. With us these are separate roles held by separate people.What if the authority requests an audit?
We prepare you and help assemble the evidence, but we do not carry out the audit. Riskoria does not hold the national security certificate for auditing, so that role stays separate, and the separation protects you too.Where to go next
The work a vCISO leads, set out in full on its own pages.
From the blog: cyber security
The three latest texts on attacks, incidents and the human factor.
Need somebody to set the direction?
Half an hour, no obligation. Tell us what is missing in your security leadership and we will see whether a vCISO covers it.
