vCISO — Virtual CISO

A security leader on retainer.
Accountable between incidents, ready during them.

Most organizations can't justify a full-time CISO — and can't afford to have no one own security either. The HackFirstAid vCISO is the middle: a named security leader who runs your program, keeps your risk register, and is the one contact your insurer, your auditor, your biggest customer, and your board can point to.

We own the decisionsIndependent partners do the hands-on workYou keep the budget & control
Where the vCISO sits
vCISO
Reports to
Owner / Board
Directs
IT / MSP
Partners
DFIR · SOC · Legal · Broker
The middle option

The gap we fill.

A full-time CISO

CA$180K–255K all-in. Right when there's 30+ hours a week of CISO work. Below that, you're paying for idle capacity.

“Our MSP handles it”

MSPs run tools and tickets. Almost none own the program, sign as your security contact, sit in the board meeting, or read your insurance policy with you.

“We'll deal with it later”

The 60-day breach clock, the insurer's controls audit, and the customer freezing the contract until you produce a risk assessment all arrive faster than a program can be built reactively.

The vCISO is the middle — and the one thing you can't stand up after the incident.

What we deliver

What your vCISO owns.

We own — the leadership layer
  • Security strategy & budgeted roadmap
  • A living risk register (not a one-time PDF)
  • Your policy & governance layer, kept current
  • Cadenced program reviews with a written brief
  • The named security contact for insurers, auditors, regulators & customer questionnaires
  • Vendor & third-party risk reviews before you sign
  • Incident decision support & tabletop readiness
  • Program metrics your board can actually read
We orchestrate but don't perform — the execution layer
  • Digital forensics & incident response→ vetted partner
  • 24/7 SOC / managed detection→ vetted partner
  • Penetration testing & red-team→ vetted partner
  • Tooling & licenses (EDR, SIEM, backup)→ vetted partner
  • Legal counsel & breach coaching→ vetted partner
  • Cyber-insurance brokerage→ vetted partner
We own the decisions and the accountability to you. Independent specialist partners do the hands-on work — on purpose, so our advice isn't tied to a tool we're selling or homework we're grading.
The on-ramp

Your first 90 days.

Weeks 0–2
Baseline

Discovery + baseline risk assessment, quick wins.

Day 30
Roadmap

Baseline report, risk register v1, 12-month roadmap.

Day 60
Governance

Policy set, vendor register, IR plan.

Day 90
Program live

First formal review, metrics baseline, a program with a named owner.

Available as a standalone 90-Day vCISO Sprint — credited toward your retainer if you continue.

Pricing

Three tiers. One owned program. Different cadence and reach.

Pick the tier that fits how much of your program you want us running and how often we meet. Every tier includes the 90-day Sprint, a named vCISO, a live risk register, and household coverage — no metered hours, no surprise bills.

Foundations
Small org or on-ramp
CA$3,000/mo
CA$36,000 /yr, billed annually
  • 90-day vCISO Sprint on-ramp
  • Quarterly program review + written brief
  • Owned risk register + 12-month roadmap
  • Core policy set, maintained
  • Up to 4 vendor risk reviews / yr
  • Annual tabletop + cyber-insurance readiness
  • Up to 16 incident-advisory hours / yr, 24/7
  • Household coverage included
Book a vCISO fit call
Most chosen
Managed
Growing org, real owned program
CA$6,500/mo
CA$78,000 /yr, billed annually
  • Everything in Foundations
  • Monthly review + written brief
  • Live risk register + roadmap, re-cut quarterly
  • Full policy set, maintained
  • Up to 12 vendor risk reviews / yr
  • Insurer + auditor + customer-questionnaire interface
  • 40 incident hours / yr + 2 named incidents retainered
  • Board / owner briefings included
Book a vCISO fit call
Embedded
Multi-entity / high-stakes
CA$12,000/mo
CA$144,000 /yr, billed annually
  • Everything in Managed
  • Bi-weekly named-CISO cadence
  • Multi-entity risk register + roadmap
  • Unlimited vendor risk reviews
  • Full board / regulator / M&A-diligence interface
  • 2 tabletops / yr
  • Unlimited incident-advisory; 4 named incidents retainered
  • Named, board-facing security leadership
Book a vCISO fit call
On-ramps
Security Risk Assessment
from CA$5,000
Credited toward your retainer.
90-Day vCISO Sprint
from CA$18,000
Credited toward your retainer.
Cyber-Insurance Readiness
from CA$3,500
Credited toward your retainer.

More than a few entities, or a multi-jurisdiction footprint? Custom engagement — travis@hackfirstaid.com.

Prices in CAD. Annual term, billed monthly (quarterly on Managed & Embedded). On-ramp projects credited toward your retainer. No metered hours, no overage charges, no surprise bills. HackFirstAid is your advisory security leader — independent specialist partners perform hands-on execution.

Straight talk

What's not included.

The vCISO is the leadership layer. The hands-on execution below is done by independent specialist partners we coordinate — never by us — so our advice stays independent.

  • Hands-on incident responsewe run the command seat; a vetted DFIR partner touches the systems.
  • 24/7 SOC / managed detectionwe spec and coordinate it; a partner runs it.
  • Security tooling & licenseswe help you choose and buy it — from vendors that aren't us.
  • Penetration testing / red-teamcoordinated through an independent tester; we don't grade our own homework.
  • Legal counsel & breach coachinga law firm's job; we coordinate, we don't advise on the law.
  • Cyber-insurance brokerageyour broker sells the policy; we make you underwritable and read it with you.
  • Custody of your datawe're advisory; your data stays on your systems.
Who's accountable

A named security leader — not a rotating queue.

25+ years incident response · 580+ engagements · Founder, Atlantic Security Conference. You get the same person on your monthly review, in the board room, and on the 3 a.m. bridge.

580+
Engagements
60-day
Breach clock we own for you
0
Tools we resell
"The one thing our board actually asks about is who owns security. Now we have an answer."
— Placeholder testimonial. Real client quote to be added with permission.
Questions

Frequently asked.

What's the difference between a vCISO and our MSP?

Your MSP runs tools and tickets. Your vCISO owns the program above them — strategy, risk, governance, and the board/insurer/auditor conversations — and makes your MSP more effective. We sit above your IT, not against it.

Do you take over during a breach?

We take the command seat — decisions, disclosure, the notification clock, insurer and regulator liaison. A vetted DFIR partner does the hands-on forensics and recovery, and we quarterback them for you.

Do you hold our data?

No. We're advisory. Your data stays on your systems, which also keeps your third-party exposure to us minimal.

What if we outgrow the retainer?

Then you should hire a full-time CISO — and we'll help you write the job description, interview, and hand off a running program. We'd rather graduate you well than defend a renewal you no longer need.

How fast can you start?

The 90-day Sprint begins within two weeks of signing; you have quick wins in motion by day 30 and a running program by day 90.

Ready when you are

Get a security leader without the search.

Book a 30-minute fit call. We'll tell you honestly whether you need a vCISO yet — and which tier fits — before you spend a dollar.