vCISO & Ongoing GRC Support
Senior security leadership, without the cost of a full-time CISO.
Most growing organisations need someone accountable for security strategy, risk and compliance, but can't justify a full-time CISO. Our virtual CISO service gives you experienced security leadership for a fixed monthly fee, tied to agreed outcomes rather than hours on a timesheet.
What you get
Each engagement is built around a defined set of outcomes. A typical scope includes:
Security strategy and roadmap. A clear, prioritised plan aligned to your business goals, risk appetite and customer or regulatory requirements, reviewed and updated as you grow.
Risk management. A maintained risk register, with risks assessed, owned and tracked to treatment.
Policies and governance. A security policy suite that stays current, with the governance structure to keep it working.
Board and executive reporting. Regular, plain-language reporting that helps directors understand cyber risk and meet their obligations.
Compliance maintenance. Ongoing support to keep ISO 27001 certification, APRA obligations or Essential Eight maturity on track, including surveillance audit preparation.
Customer and supplier assurance. Help answering customer security questionnaires, and reviewing the security of your own suppliers.
Incident readiness. An incident response plan your team has actually practised, through a tabletop exercise each year.
How it works
1. Baseline
In the first month, we assess your current security posture, risks and obligations, and agree the outcomes that matter most.
2. Agreed scope and fee
We set a fixed monthly fee for a defined set of deliverables. You know exactly what you're getting and what it costs.
3. Ongoing leadership
We work as part of your team, attending key meetings, guiding decisions, and delivering against the agreed scope.
4. Regular review
We review progress and scope with you quarterly, so the service changes as your needs do.
Who this is for
Growing companies facing their first serious security requirements from customers, investors or insurers
Organisations that have achieved certification and need to maintain it without hiring a full-time security leader
APRA-regulated entities and their suppliers needing ongoing oversight of CPS 234 and CPS 230 obligations
Organisations between CISOs that need experienced leadership while they recruit
Why Cyber Systems HQ
Real vCISO experience. Dan Goldberg has served as a delegated vCISO for multiple organisations and brings three decades of experience leading security and technology transformation programs.
Risk and governance credentials. Gavin Oh holds ISACA's CISM and CRISC certifications, covering security leadership and IT risk management.
Outcomes, not hours. You pay for agreed results, not time spent. That keeps us focused on what actually moves your security forward.
Connected to everything else we do. If you need ISO 27001 certification, APRA compliance or an Essential Eight assessment, it fits within the same program, run by the same people.
Start with a conversation
Every organisation's needs are different. Talk to us about what you need from a security leader, and we'll propose a scope and fixed monthly fee that fits.
Frequently asked questions
How is this different from hiring a full-time CISO?
You get senior expertise for a fraction of the cost of a full-time executive, with a scope sized to what your organisation needs now. As you grow, the scope can grow with you.
Is it really a fixed fee?
Yes. We agree a set of deliverables and a monthly fee up front. If your needs change significantly, we review the scope together rather than surprising you with extra charges.
Do you respond to security incidents?
We guide your response, coordinate decision-making and help manage communications and obligations, such as notifying regulators. Technical forensics and recovery are usually handled by a specialist incident response provider, and we can help you arrange one in advance.