What a Business Gets from a vCISO in the First 90 Days
- ESKA ITeam
- Jun 17
- 13 min read
When a company begins thinking seriously about cybersecurity, one question usually comes up:
“Fine, we bring in a vCISO. But what exactly will change in the way the business operates?”
Most descriptions of the role sound too abstract. They talk about strategy, risk management, governance, and security process development. These concepts are important, but business leaders usually want something more practical: specific actions, visible progress, and measurable outcomes.
That is why this article looks at what a vCISO actually does during the first 90 days of working with a company.
It explains which tasks are addressed first, how the vCISO interacts with management and internal teams, and what value the business receives as the foundations of an effective cybersecurity program begin to take shape.
What Is a vCISO and Who Needs One?
A vCISO, or Virtual Chief Information Security Officer, is an experienced cybersecurity professional who performs the responsibilities of an internal Chief Information Security Officer on an outsourced or fractional basis.
In a large corporation, a full-time CISO typically leads a dedicated security team, manages a significant budget, and focuses on the specific risks and regulatory requirements of the company’s industry.
For an organization with 50 to 500 employees, however, hiring a senior security executive full-time is often not economically justified. An experienced CISO may cost between $150,000 and $300,000 per year, while many growing companies do not yet have enough security-related workload to keep that person fully occupied.
A vCISO provides access to the same strategic level of expertise, but in a more flexible format.
Instead of employing a full-time executive, the company may receive 10 to 20 hours of focused senior-level support per month, concentrated on the most important security tasks. When additional expertise is needed, the vCISO can also involve supporting specialists in areas such as penetration testing, compliance, cloud security, incident response, or security monitoring.
A vCISO is particularly suitable for:
Companies without an internal CISO, where security responsibilities are handled by the IT Director, CTO, or system administrator
Businesses preparing for ISO 27001 certification, SOC 2 compliance, DORA readiness, or expansion into new markets
Companies recovering from a security incident that need to restore operations and build proper security processes
Growing startups that are scaling quickly and dealing with corporate cybersecurity requirements for the first time
The First 30 Days: Understanding Where the Company Is
The first month is not primarily about implementation.
It is about diagnosis.
A vCISO who immediately begins introducing new tools or controls during the first week, without first understanding the business, its systems, and its risks, is approaching the role incorrectly.
The first 30 days are used to establish a complete and objective picture of the company’s current cybersecurity position.
Step 1. Meeting the Key Stakeholders
The work of a vCISO does not begin with scanning systems or reviewing firewall configurations.
The first priority is to understand how the business operates, which objectives the company is pursuing, and which risks may interfere with those objectives.
To build this understanding, the vCISO meets with key stakeholders across the organization. These may include the CEO, CFO, CTO, IT Director, heads of business departments, legal representatives, compliance teams, and other decision-makers.
The main objective at this stage is to understand the business context, the company’s strategic priorities, and the role cybersecurity needs to play in supporting them.
Typical questions include:
Which processes are critical to the company’s operations?
Which data is most valuable, and where is it stored?
Which regulatory or contractual requirements already apply?
Which requirements are expected in the future?
Which security incidents have already occurred?
What changed after those incidents?
How does management currently view and tolerate risk?
Which clients, investors, or partners expect evidence of security controls?
Which business initiatives depend on security readiness?
Without this business context, even technically correct security recommendations may be irrelevant, poorly prioritized, or disconnected from the company’s real needs.
For example, a recommendation to invest in an expensive security platform may make little sense if the company’s main risk is weak access management or an undocumented incident response process.
The purpose of the stakeholder discussions is therefore not simply to collect information. It is to ensure that the security program is aligned with the business from the very beginning.
Step 2. Asset Inventory
A company cannot protect assets it does not know it has.
Together with the internal IT team, the vCISO creates, reviews, or validates an inventory of the company’s technology and information assets.
This includes:
All information systems and applications used by the company
Servers, workstations, laptops, mobile devices, and network infrastructure
Cloud platforms and hosted environments
SaaS services used by employees and departments
Locations where sensitive and critical data is stored
Business-critical databases and file repositories
Backup systems and disaster recovery environments
Code repositories and development platforms
Administrative interfaces and remote access systems
External integrations and third-party connections
Contractors and service providers with access to company systems
Users and service accounts with access to critical resources
The vCISO also examines who has access to which systems and whether that access is justified by the person’s role.
This often reveals problems such as:
Former employees with active accounts
Developers with unnecessary access to production systems
Shared administrative accounts
SaaS applications purchased without IT approval
Critical data stored in unapproved locations
External contractors with permanent access
Systems that are no longer actively managed
Business applications with no clearly assigned owner
Asset inventory is not simply an IT housekeeping exercise. It creates the baseline for risk management, vulnerability management, access control, incident response, compliance, and future investment decisions.
Without an accurate understanding of the environment, security controls will inevitably leave gaps.
Step 3. Assessing the Current Security Posture
Once the vCISO understands the business and the IT environment, the next step is a comprehensive assessment of the company’s current cybersecurity posture.
At this stage, both technical controls and organizational processes are reviewed.
The vCISO evaluates how effectively the company protects its infrastructure, applications, data, users, and endpoints.
The assessment may cover:
Identity and access management
Multi-factor authentication
Privileged account management
Endpoint protection
Network security
Cloud security
Email security
Backup protection
Vulnerability management
Patch management
Logging and security monitoring
Incident detection
Incident response
Third-party risk management
Data classification
Security awareness
Business continuity
Disaster recovery
Security policies and procedures
Regulatory and contractual compliance
The vCISO reviews not only whether a security control exists, but also whether it is working effectively.
For example, a company may have endpoint protection installed, but alerts may not be monitored. Backups may exist, but restoration may never have been tested. An incident response plan may have been written, but employees may not know where to find it or what their responsibilities are.
Security maturity is therefore assessed through both documentation and practical evidence.
By the end of the first month, the company receives an objective view of its current position:
Which controls are already working
Which processes need improvement
Which gaps create the highest risk
Which areas require immediate attention
Which security activities are missing entirely
Which controls exist only formally but are not functioning in practice
This assessment becomes the foundation for the future cybersecurity strategy and the company’s security development plan.
Days 31–60: Prioritizing and Starting with What Matters Most
After the diagnostic phase, one thing becomes clear: there will always be more security tasks than the company has time, people, or budget to complete.
The purpose of the second month is therefore not to try to fix everything at once. The purpose is to establish priorities so that every hour and every unit of budget delivers the greatest possible reduction in business risk.
Risk Assessment
The vCISO develops a risk register: a structured list of relevant cybersecurity risks, including their likelihood, potential impact, current controls, and recommended treatment.
It is a practical management tool used to make informed decisions.
The risk register helps answer questions such as:
Which risks are critical and require immediate action?
Which risks can be accepted temporarily?
Which risks can be reduced through compensating controls?
Which risks require investment in new systems or services?
Which risks may affect revenue, operations, clients, or regulatory compliance?
Which risks could delay entry into a new market?
Which risks should be transferred through insurance or contractual measures?
Who is responsible for each risk?
Typical risks may include:
Compromise of privileged accounts
Ransomware affecting business-critical systems
Loss of customer data
Unauthorized access to cloud environments
Disruption of critical SaaS services
Inadequate backup recovery
Weak vendor security
Lack of security monitoring
Failure to meet contractual security obligations
Inability to detect or respond to an incident quickly
Each risk is assessed according to the company’s real business context.
For example, the same technical vulnerability may have very different consequences for a software startup, a financial institution, a manufacturing company, or a healthcare provider.
The risk register allows management to make conscious decisions instead of reacting to isolated technical findings.
Quick Wins
At the same time as the risk assessment, the vCISO identifies measures that can be implemented quickly, at relatively low cost, and with a significant security impact.
These are often referred to as quick wins.
Typical examples include:
Enabling MFA for critical and privileged accounts
Closing Internet-exposed RDP services
Introducing VPN access for remote administration
Deactivating accounts belonging to former employees
Reviewing unnecessary administrator privileges
Improving password requirements
Securing backup administration accounts
Configuring basic email protection using SPF, DKIM, and DMARC
Restricting access to cloud administration portals
Removing unused external access
Updating critical Internet-facing systems
Conducting the first security awareness session for employees
These actions often do not require major investments in new tools.
In many cases, the company already owns the necessary technology but has not configured it properly.
Despite their simplicity, quick wins can substantially reduce the likelihood of account compromise, ransomware, unauthorized access, and phishing-related incidents.
They also create visible progress early in the engagement.
This is important because security programs need to demonstrate value. Management should be able to see that the vCISO is not only producing reports, but also reducing risk through practical actions.
Building the Cybersecurity Roadmap
By the end of the second month, the vCISO prepares a strategic cybersecurity roadmap.
This document answers three practical questions:
What are we going to do?
When are we going to do it?
Why is it necessary?
The roadmap usually covers the next 12 months and organizes security initiatives according to priority, business value, cost, complexity, and regulatory deadlines.
A strong roadmap is:
Aligned with the company’s business objectives
Based on identified risks
Realistic in terms of available resources
Connected to compliance and contractual requirements
Structured into clear phases
Supported by estimated budgets
Assigned to responsible owners
Measurable through defined outcomes
The roadmap may include initiatives such as:
Implementing centralized identity and access management
Introducing privileged access management
Improving endpoint detection and response
Building or outsourcing security monitoring
Conducting penetration testing
Establishing vulnerability management
Formalizing incident response
Improving backup resilience
Conducting security awareness training
Preparing for ISO 27001 or SOC 2
Introducing third-party risk assessment
Improving cloud security controls
Developing business continuity and disaster recovery plans
The roadmap is not based on abstract best practices alone.
Every initiative should be connected to a specific business risk, customer requirement, regulatory obligation, or strategic objective.
For example, the reason for implementing logging and monitoring may not simply be “because it is recommended.” It may be necessary to reduce incident detection time, meet SOC 2 requirements, support a client contract, or prepare for an investor due diligence process.
The roadmap also contains estimated budget requirements for each initiative.
This allows the company to plan security spending instead of responding to unexpected demands throughout the year.
The roadmap becomes the basis for a structured discussion with the CEO and CFO about cybersecurity priorities and budget.
Days 61–90: Structure, Processes, and the First Measurable Results
The third month marks the transition from assessment and planning to structured, repeatable security management.
During this period, the vCISO begins formalizing the processes that will support the company’s cybersecurity program over the long term.
Core Security Documentation
One of the most underestimated elements of cybersecurity is clear, practical, and usable documentation.
Many companies either have no security policies or rely on documents that were copied from templates, written for audit purposes, and never used in daily operations.
A vCISO develops or updates the core documents the company actually needs.
These typically include:
Information Security Policy
This is the foundational document that defines the company’s general security principles, responsibilities, and expectations.
It explains:
Who is responsible for cybersecurity
Which security rules apply to employees and contractors
How company information should be handled
How access should be controlled
Which activities are prohibited
How security violations are managed
How security responsibilities are distributed
The policy should be understandable and relevant to the organization. It should not be a collection of generic statements that employees cannot apply in practice.
Incident Response Procedure
The incident response procedure explains what the company should do when something goes wrong.
It defines:
What qualifies as a security incident
How employees report suspicious activity
Who must be contacted
Who coordinates the response
Which technical and business teams are involved
How evidence is preserved
How management is informed
When clients, partners, insurers, or regulators must be notified
How lessons learned are documented
In a real incident, people do not have time to invent a process.
They need a clear instruction that tells them who does what and in which order.
Password and Access Management Policy
This document defines specific access control requirements instead of relying on vague wording such as “users must choose secure passwords.”
It may include:
Password length and complexity requirements
MFA requirements
Rules for privileged accounts
Password manager usage
Access approval procedures
Prohibition of shared accounts
Periodic access reviews
Requirements for service accounts
Procedures for emergency access
Account lockout and recovery rules
Onboarding and Offboarding Procedure
This procedure ensures that new employees receive only the access they need, while departing employees lose access immediately.
The process defines:
Who requests access
Who approves it
Which systems are included
Which equipment is issued
Which security training is required
How access is reviewed when an employee changes roles
How accounts are disabled during offboarding
How company equipment and credentials are returned
How access granted to contractors is terminated
This procedure reduces one of the most common security risks: uncontrolled and outdated access rights.
These documents are not bureaucracy.
They are operating instructions for people who need to make correct decisions during routine and non-routine situations.
The First Employee Security Training
Technical controls protect systems.
Training helps protect people, who remain one of the most frequently targeted parts of any organization.
During the first 90 days, the vCISO organizes the company’s first structured cybersecurity awareness session.
The training typically covers:
How to recognize phishing emails
How to verify suspicious requests
What to do after clicking a suspicious link
How to report a potential incident
How to handle corporate data securely
How to use passwords and MFA correctly
How to work securely from home or while traveling
How to recognize social engineering
How to protect corporate devices
How to avoid unauthorized applications and cloud services
This should not be a generic one-hour lecture with attractive slides and no practical relevance.
Effective training uses realistic scenarios based on actual attack methods and is adapted to the company’s industry, technology, and employee roles.
For example, the risks relevant to finance employees may differ from those relevant to developers, sales teams, or system administrators.
The goal is to help employees recognize a threat and respond correctly when they encounter one.
Metrics and Management Reporting
By the end of the 90-day period, the vCISO establishes a reporting system for management.
The purpose is not to overwhelm executives with technical details.
The purpose is to provide a clear, business-oriented view of the company’s cybersecurity posture.
Typical metrics may include:
Number of critical vulnerabilities identified
Number of critical vulnerabilities remediated
Percentage of privileged accounts protected by MFA
Number of inactive accounts removed
Status of high-priority risks
Progress against the cybersecurity roadmap
Security incidents and suspicious events identified
Average time to respond to security issues
Employee training completion
Status of compliance initiatives
Backup restoration testing results
Completion of priority security projects
The CEO and CFO should be able to understand:
What the company’s most significant risks are
Which actions have already been completed
Which risks remain unresolved
Which investments are required
Whether the company’s security posture is improving
Whether deadlines and regulatory obligations are being met
Management reporting turns cybersecurity from an isolated technical function into a visible part of corporate governance.
What the Company Has After 90 Days
After the first three months of working with a vCISO, the company should have a clear and practical set of results.
These include:
A complete picture of the current cybersecurity posture
A clear understanding of what controls already exist
Identification of the most significant security gaps
A prioritized cybersecurity risk register
Immediate high-risk issues addressed through quick wins
A 12-month strategic cybersecurity roadmap
Budget estimates for major security initiatives
A core package of information security policies and procedures
A formal incident response process
A structured onboarding and offboarding procedure
Improved access management
The first employee cybersecurity awareness training
A management reporting system
Clear security ownership and responsibilities
A stronger basis for communication with clients, investors, auditors, and regulators
A structured foundation for future compliance initiatives
A clear explanation of where security investment is needed and why
In practical terms, the company moves from a fragmented and reactive approach to a managed cybersecurity program.
Before the vCISO engagement, security may depend on individual employees, informal decisions, and isolated technical tools.
After 90 days, the company has a documented understanding of its risks, agreed priorities, assigned responsibilities, measurable actions, and a realistic development plan.
The Most Common Question: What Happens After the First 90 Days?
A vCISO is not a project with a fixed end date.
It is an ongoing security leadership function adapted to the company’s size, risks, and pace of development.
After the first 90 days, the work moves into a continuous management and improvement phase.
This usually includes:
Monthly or quarterly meetings with management
Monitoring the implementation of the cybersecurity roadmap
Updating the risk register
Responding to new threats
Reviewing significant security incidents
Supporting internal IT and security teams
Managing security priorities
Reviewing new systems and business initiatives
Assessing new vendors and contractors
Supporting compliance projects
Preparing for audits and client assessments
Reviewing security metrics
Updating policies and procedures
Coordinating security testing
Supporting incident response
Advising management on security-related investments
The vCISO also participates in strategic decisions that have a cybersecurity dimension.
These may include:
Entering a new market
Launching a new product
Migrating to a new cloud platform
Selecting a critical technology provider
Outsourcing business processes
Working with a new enterprise client
Responding to an investor due diligence request
Preparing for an acquisition
Expanding the workforce
Opening a new office
Integrating another company’s systems
The company therefore receives more than a one-time assessment.
It receives continuous access to senior cybersecurity expertise without having to hire a full-time executive whose workload may not justify a permanent position.
Is a vCISO Right for Your Company?
A vCISO may be the right choice if:
You do not have an internal CISO
Security responsibilities are handled informally by the IT Director or CTO
Your company needs a systematic approach instead of isolated technical solutions
You are preparing for ISO 27001, SOC 2, DORA, or another compliance framework
You are facing an investor or customer security assessment
You are entering the EU or another regulated market
You are scaling quickly and security processes are not keeping pace
You understand that cybersecurity risks exist but do not know where to begin
You need strategic expertise but do not need a full-time security executive
Your clients increasingly expect evidence of mature security practices
You need to build a security budget based on business risk
You want independent oversight of your current security activities
The value of a vCISO is not limited to producing policies or recommending tools.
The real value lies in turning cybersecurity into a structured business function with clear priorities, defined responsibilities, measurable progress, and a direct connection to the company’s strategic objectives.
If you want to understand whether the vCISO model fits your situation, the best place to start is a short consultation.
The ESKA team will ask several practical questions about your business, current security posture, regulatory requirements, and development plans.
Based on those answers, we will explain honestly whether your company needs ongoing vCISO support, a one-time assessment, a compliance project, technical security improvements, or a different approach entirely.



Comments