Skip to main content
Cybersecurity · Advisory

vCISO and security advisory

Not every organization needs, or can recruit, a full-time chief information security officer. A Dark Pools vCISO provides that leadership on demand: setting strategy, building the security program, preparing for ISO 27001, NIST and POPIA requirements and reporting to the board. The work is sized to your risk and budget.

How we engage
vCISO leadershipPolicy and governanceCompliance readinessTabletop exercisesvCISO & securityadvisoryADVISORY SERVICE · DELIVERED BY ONE ACCOUNTABLE TEAM
Outcomes

What you get

  • A security strategy and roadmap tied to business risk and agreed with leadership
  • Policies and standards that match how the organization actually works
  • Readiness for ISO 27001 certification audits, NIST alignment and POPIA obligations
  • Board and executive reporting written in business terms
  • Incident response plans tested through tabletop exercises before a real incident tests them
How we engage

The engagement, step by step

  1. 01AssessReview current controls, policies, risks and obligations through interviews, documentation and technical evidence.
  2. 02PrioritizeRank gaps by risk and effort, and agree with leadership what the program will address first.
  3. 03RoadmapTurn priorities into a sequenced plan with owners, dependencies and budget implications.
  4. 04BuildWrite policies, define controls, select tooling and support the teams putting them in place.
  5. 05ExerciseRun tabletop exercises that walk leadership and responders through realistic incident scenarios.
  6. 06GovernReport progress to the board, track risk and keep the program aligned as the business changes.
Scope

What we cover

vCISO leadership

A senior security leader working with your executive team on a part-time or interim basis and accountable for the security program.

Compliance readiness

Gap analysis and remediation support for ISO 27001, the NIST Cybersecurity Framework and POPIA, ahead of audits or regulatory review.

Policy and governance

Policies, standards and governance structures that give every security decision a clear owner and a documented basis.

Tabletop exercises

Facilitated scenarios such as ransomware, a data breach or insider misuse, testing decisions, communications and escalation.

Deliverables

What you receive

  • 01Security maturity assessment and risk register
  • 02Security strategy and sequenced roadmap
  • 03Policies and standards aligned to the chosen framework
  • 04Readiness gap analysis for ISO 27001, NIST or POPIA
  • 05Tabletop exercise scenarios, after-action reports and improvement actions
  • 06Board-level security reporting
FAQ

Questions buyers ask

Get started

Take the next step

Scope vciso & security advisory with a security lead. We will tell you plainly what you need, and what you do not.

All cybersecurity services