How scope is set
Every domain below can be dialled up or down
During discovery, your vCISO maps which of the nine domains carry the most risk for your organisation right now, and builds the roadmap around those first.
- No domain is compulsory — scope is agreed before work begins.
- Priorities are revisited at each reporting cycle as risk changes.
- Certification-driven domains (ISO 27001, Cyber Essentials) can be fast-tracked.
The register
Nine domains, scoped to what your organisation needs
§01
Governance & Compliance
- Policy & procedure suite
- ISO 27001 / Cyber Essentials readiness
- Regulatory alignment (GDPR, DORA)
§02
Risk Management
- Risk register & treatment plans
- Asset & information classification
- Board-level risk reporting
§03
Incident Response
- IR plans & playbooks
- Tabletop exercises
- Breach communications planning
§04
Cloud & Technology
- Architecture & configuration review
- Vendor-neutral tooling advice
- Cloud security posture assessment
§05
Third-Party & Supply Chain
- Supplier due-diligence process
- Contractual security requirements
- Ongoing vendor risk monitoring
§06
Data Protection
- Data flow & access mapping
- Information handling controls
- Data loss prevention strategy
§07
Business Continuity
- Continuity & disaster recovery plans
- Resilience testing
- Recovery time / point objectives
§08
Culture & Awareness
- Staff training programmes
- Phishing simulation
- Executive & board briefings
§09
Audit & Assurance
- Independent policy assurance review
- Audit preparation & support
- Control effectiveness testing
How work gets delivered
Every domain is delivered one of three ways
Before any work starts, we agree which mode applies — so scope and cost are clear from the outset.
Mode 01
Review
We assess what you already have — documents, controls or processes — and give you a clear, independent opinion on where it stands.
Mode 02
Refresh
We take existing material and bring it up to current best practice, aligned to the framework and regulations relevant to you.
Mode 03
Build
Where nothing exists yet, we create it from scratch — shaped around how your organisation actually operates.