A security leader on retainer.
Accountable between incidents, ready during them.
Most organizations can't justify a full-time CISO — and can't afford to have no one own security either. The HackFirstAid vCISO is the middle: a named security leader who runs your program, keeps your risk register, and is the one contact your insurer, your auditor, your biggest customer, and your board can point to.
The gap we fill.
CA$180K–255K all-in. Right when there's 30+ hours a week of CISO work. Below that, you're paying for idle capacity.
MSPs run tools and tickets. Almost none own the program, sign as your security contact, sit in the board meeting, or read your insurance policy with you.
The 60-day breach clock, the insurer's controls audit, and the customer freezing the contract until you produce a risk assessment all arrive faster than a program can be built reactively.
The vCISO is the middle — and the one thing you can't stand up after the incident.
What your vCISO owns.
- Security strategy & budgeted roadmap
- A living risk register (not a one-time PDF)
- Your policy & governance layer, kept current
- Cadenced program reviews with a written brief
- The named security contact for insurers, auditors, regulators & customer questionnaires
- Vendor & third-party risk reviews before you sign
- Incident decision support & tabletop readiness
- Program metrics your board can actually read
- Digital forensics & incident response→ vetted partner
- 24/7 SOC / managed detection→ vetted partner
- Penetration testing & red-team→ vetted partner
- Tooling & licenses (EDR, SIEM, backup)→ vetted partner
- Legal counsel & breach coaching→ vetted partner
- Cyber-insurance brokerage→ vetted partner
Your first 90 days.
Discovery + baseline risk assessment, quick wins.
Baseline report, risk register v1, 12-month roadmap.
Policy set, vendor register, IR plan.
First formal review, metrics baseline, a program with a named owner.
Available as a standalone 90-Day vCISO Sprint — credited toward your retainer if you continue.
Three tiers. One owned program. Different cadence and reach.
Pick the tier that fits how much of your program you want us running and how often we meet. Every tier includes the 90-day Sprint, a named vCISO, a live risk register, and household coverage — no metered hours, no surprise bills.
- 90-day vCISO Sprint on-ramp
- Quarterly program review + written brief
- Owned risk register + 12-month roadmap
- Core policy set, maintained
- Up to 4 vendor risk reviews / yr
- Annual tabletop + cyber-insurance readiness
- Up to 16 incident-advisory hours / yr, 24/7
- Household coverage included
- Everything in Foundations
- Monthly review + written brief
- Live risk register + roadmap, re-cut quarterly
- Full policy set, maintained
- Up to 12 vendor risk reviews / yr
- Insurer + auditor + customer-questionnaire interface
- 40 incident hours / yr + 2 named incidents retainered
- Board / owner briefings included
- Everything in Managed
- Bi-weekly named-CISO cadence
- Multi-entity risk register + roadmap
- Unlimited vendor risk reviews
- Full board / regulator / M&A-diligence interface
- 2 tabletops / yr
- Unlimited incident-advisory; 4 named incidents retainered
- Named, board-facing security leadership
More than a few entities, or a multi-jurisdiction footprint? Custom engagement — travis@hackfirstaid.com.
Prices in CAD. Annual term, billed monthly (quarterly on Managed & Embedded). On-ramp projects credited toward your retainer. No metered hours, no overage charges, no surprise bills. HackFirstAid is your advisory security leader — independent specialist partners perform hands-on execution.
What's not included.
The vCISO is the leadership layer. The hands-on execution below is done by independent specialist partners we coordinate — never by us — so our advice stays independent.
- Hands-on incident response— we run the command seat; a vetted DFIR partner touches the systems.
- 24/7 SOC / managed detection— we spec and coordinate it; a partner runs it.
- Security tooling & licenses— we help you choose and buy it — from vendors that aren't us.
- Penetration testing / red-team— coordinated through an independent tester; we don't grade our own homework.
- Legal counsel & breach coaching— a law firm's job; we coordinate, we don't advise on the law.
- Cyber-insurance brokerage— your broker sells the policy; we make you underwritable and read it with you.
- Custody of your data— we're advisory; your data stays on your systems.
A named security leader — not a rotating queue.
25+ years incident response · 580+ engagements · Founder, Atlantic Security Conference. You get the same person on your monthly review, in the board room, and on the 3 a.m. bridge.
"The one thing our board actually asks about is who owns security. Now we have an answer."
Frequently asked.
What's the difference between a vCISO and our MSP?
Your MSP runs tools and tickets. Your vCISO owns the program above them — strategy, risk, governance, and the board/insurer/auditor conversations — and makes your MSP more effective. We sit above your IT, not against it.
Do you take over during a breach?
We take the command seat — decisions, disclosure, the notification clock, insurer and regulator liaison. A vetted DFIR partner does the hands-on forensics and recovery, and we quarterback them for you.
Do you hold our data?
No. We're advisory. Your data stays on your systems, which also keeps your third-party exposure to us minimal.
What if we outgrow the retainer?
Then you should hire a full-time CISO — and we'll help you write the job description, interview, and hand off a running program. We'd rather graduate you well than defend a renewal you no longer need.
How fast can you start?
The 90-day Sprint begins within two weeks of signing; you have quick wins in motion by day 30 and a running program by day 90.
Get a security leader without the search.
Book a 30-minute fit call. We'll tell you honestly whether you need a vCISO yet — and which tier fits — before you spend a dollar.