Services Framework Engagement Model Who We Serve FAQ Contact

Home / Services

Service Register

What's covered under a CSISC vCISO engagement

Nine service domains, each scoped to your organisation. Not every engagement touches every domain — your vCISO prioritises the ones that reduce the most risk first.

Consultant reviewing security documentation with a client

How scope is set

Every domain below can be dialled up or down

During discovery, your vCISO maps which of the nine domains carry the most risk for your organisation right now, and builds the roadmap around those first.

  • No domain is compulsory — scope is agreed before work begins.
  • Priorities are revisited at each reporting cycle as risk changes.
  • Certification-driven domains (ISO 27001, Cyber Essentials) can be fast-tracked.

The register

Nine domains, scoped to what your organisation needs

§01

Governance & Compliance

  • Policy & procedure suite
  • ISO 27001 / Cyber Essentials readiness
  • Regulatory alignment (GDPR, DORA)
§02

Risk Management

  • Risk register & treatment plans
  • Asset & information classification
  • Board-level risk reporting
§03

Incident Response

  • IR plans & playbooks
  • Tabletop exercises
  • Breach communications planning
§04

Cloud & Technology

  • Architecture & configuration review
  • Vendor-neutral tooling advice
  • Cloud security posture assessment
§05

Third-Party & Supply Chain

  • Supplier due-diligence process
  • Contractual security requirements
  • Ongoing vendor risk monitoring
§06

Data Protection

  • Data flow & access mapping
  • Information handling controls
  • Data loss prevention strategy
§07

Business Continuity

  • Continuity & disaster recovery plans
  • Resilience testing
  • Recovery time / point objectives
§08

Culture & Awareness

  • Staff training programmes
  • Phishing simulation
  • Executive & board briefings
§09

Audit & Assurance

  • Independent policy assurance review
  • Audit preparation & support
  • Control effectiveness testing

How work gets delivered

Every domain is delivered one of three ways

Before any work starts, we agree which mode applies — so scope and cost are clear from the outset.

Mode 01

Review

We assess what you already have — documents, controls or processes — and give you a clear, independent opinion on where it stands.

Mode 02

Refresh

We take existing material and bring it up to current best practice, aligned to the framework and regulations relevant to you.

Mode 03

Build

Where nothing exists yet, we create it from scratch — shaped around how your organisation actually operates.

Not sure which domains apply to you?