Governance, Risk & Compliance | vCISO Services | Revolution InfoSec
Governance, Risk & Compliance

Security leadership for your business, led by your vCISO

Everything we do starts with understanding your risk: what your strategic goals are, and how much risk you are willing to carry. Your virtual Chief Information Security Officer turns that understanding into a security programme you can actually run, and actually prove.

Get a free security health check
Virtual CISO

Your own security leader, without the six-figure salary

Most businesses don't need a full-time Chief Information Security Officer. They need an experienced one, on hand when it counts: setting direction, answering the board, satisfying customers and auditors, and steering the response when something goes wrong.
Our vCISO gives you all of this for a predictable monthly investment, sized to small, medium and large businesses alike.

What you get with your vCISO
A security leader you can trust
A trusted senior cybersecurity executive who gets to know your business and provides governance to your senior leadership or board.
Risk assessment & roadmap
A framework-based cyber maturity assessment, then a prioritised plan: highest-impact fixes first, sized to your budget.
Policies & standards
A practical policy suite your staff will actually read, kept current rather than filed away.
Board & management reporting
Clear, jargon-free reporting on your posture and progress, in language a board can act on.
Compliance leadership
Guidance through frameworks such as ISO 27001, NIST CSF, NZ Cyber Minimum Standards, Essential 8, as well as the Privacy Act and other legal obligations, and government assurance processes such as the NZ CSC for Tier One Marketplace suppliers.
Vendor & supply-chain review
Assessment of the partners and suppliers who hold your data, before they become your weakest link.
Incident readiness tabletop exercises
Customised scenarios for your business. Response plans that are rehearsed, not just written. We can run exercises with your leadership team and/or operational staff.
Need less seniority?
If you just need your framework managed day to day, our vISM service may be the better fit.
SecurityCentral access
Your risks, roadmap, policies and evidence in one platform, so you can see and prove your progress at any time.
Why it works

Compliance is the floor. Assurance is the goal.

Frameworks such as ISO 27001 matter, and we will get you there. But a certificate only says you passed an audit on one day. Your vCISO builds the habits, evidence and testing behind it, so that when a customer, insurer or regulator asks "are you secure?", you can show them, not just tell them.

"Revolution InfoSec provide vCISO services to TEAM IM and have integrated themselves into the fabric of our company and culture... they have guided us through many facets of information security."
Craig Hampson ยท Co-Founder and Director, TEAM IM
The wider GRC toolkit

Every service your security programme draws on

Available within a vCISO engagement or as standalone pieces of work, all delivered efficiently with the latest technology to keep them affordable.

Business risk appetite profiling
How much risk can your business carry, and where? The foundation every other decision builds on.
Asset-based risk assessment
A clear register of what you own, what it is worth and what threatens it, in business terms.
Compliance, including ISO 27001
Gap assessment, implementation and certification support for the standards your customers ask about.
Strategy & investment planning
A multi-year security strategy with spend prioritised where it reduces the most risk.
Vendor & supply-chain strategy
Assessment and ongoing management of third-party risk across your supplier base.
Privacy & statutory requirements
Practical help meeting the NZ Privacy Act, Australian Privacy Principles and your sector's obligations.
Which one do I need?

vCISO, vISM or a Cyber Officer?

VCISO
Sets the direction
  • Security strategy, roadmap and investment decisions
  • Answers to your board or senior leadership
  • Leads tabletop exercises
  • Senior counsel when the stakes are high
Talk to us about a vCISO โ†’
VISM
Keeps it running
  • Operates the framework your strategy has chosen
  • Keeps risks, policies and evidence up to date
  • Gets you through audits and customer questionnaires
  • Escalates to vCISO-level help only when needed
Find out more about our vISM service โ†’
CYBER OFFICER: FOR SMALLER BUSINESSES
Both, in one service
  • Combines vCISO and vISM in a single offering
  • Strategic direction and day-to-day management together
  • One point of contact, one predictable investment
  • Right-sized for smaller businesses
Ask about our Cyber Officer service โ†’

Many clients use both: a vCISO to set and govern the programme, and a vISM to run it week to week. For smaller businesses, we can provide a mini Cyber Officer service which combines vCISO & vISM to provide cross-outcomes. Other businesses may start with a vISM and add senior leadership as they grow. We will recommend whichever fits your size and risk.

Not sure how much security leadership you need?

Start with a free health check. We will tell you honestly what you need, and what you don't.

Get a free security health check