top of page

What a Business Gets from a vCISO in the First 90 Days

  • ESKA ITeam
  • Jun 17
  • 13 min read

When a company begins thinking seriously about cybersecurity, one question usually comes up:

“Fine, we bring in a vCISO. But what exactly will change in the way the business operates?”

Most descriptions of the role sound too abstract. They talk about strategy, risk management, governance, and security process development. These concepts are important, but business leaders usually want something more practical: specific actions, visible progress, and measurable outcomes.

That is why this article looks at what a vCISO actually does during the first 90 days of working with a company.


It explains which tasks are addressed first, how the vCISO interacts with management and internal teams, and what value the business receives as the foundations of an effective cybersecurity program begin to take shape.



What Is a vCISO and Who Needs One?


A vCISO, or Virtual Chief Information Security Officer, is an experienced cybersecurity professional who performs the responsibilities of an internal Chief Information Security Officer on an outsourced or fractional basis.

In a large corporation, a full-time CISO typically leads a dedicated security team, manages a significant budget, and focuses on the specific risks and regulatory requirements of the company’s industry.


For an organization with 50 to 500 employees, however, hiring a senior security executive full-time is often not economically justified. An experienced CISO may cost between $150,000 and $300,000 per year, while many growing companies do not yet have enough security-related workload to keep that person fully occupied.


A vCISO provides access to the same strategic level of expertise, but in a more flexible format.

Instead of employing a full-time executive, the company may receive 10 to 20 hours of focused senior-level support per month, concentrated on the most important security tasks. When additional expertise is needed, the vCISO can also involve supporting specialists in areas such as penetration testing, compliance, cloud security, incident response, or security monitoring.


A vCISO is particularly suitable for:

  • Companies without an internal CISO, where security responsibilities are handled by the IT Director, CTO, or system administrator

  • Businesses preparing for ISO 27001 certification, SOC 2 compliance, DORA readiness, or expansion into new markets

  • Companies recovering from a security incident that need to restore operations and build proper security processes

  • Growing startups that are scaling quickly and dealing with corporate cybersecurity requirements for the first time



The First 30 Days: Understanding Where the Company Is


The first month is not primarily about implementation.

It is about diagnosis.

A vCISO who immediately begins introducing new tools or controls during the first week, without first understanding the business, its systems, and its risks, is approaching the role incorrectly.

The first 30 days are used to establish a complete and objective picture of the company’s current cybersecurity position.


Step 1. Meeting the Key Stakeholders


The work of a vCISO does not begin with scanning systems or reviewing firewall configurations.

The first priority is to understand how the business operates, which objectives the company is pursuing, and which risks may interfere with those objectives.


To build this understanding, the vCISO meets with key stakeholders across the organization. These may include the CEO, CFO, CTO, IT Director, heads of business departments, legal representatives, compliance teams, and other decision-makers.


The main objective at this stage is to understand the business context, the company’s strategic priorities, and the role cybersecurity needs to play in supporting them.


Typical questions include:

  • Which processes are critical to the company’s operations?

  • Which data is most valuable, and where is it stored?

  • Which regulatory or contractual requirements already apply?

  • Which requirements are expected in the future?

  • Which security incidents have already occurred?

  • What changed after those incidents?

  • How does management currently view and tolerate risk?

  • Which clients, investors, or partners expect evidence of security controls?

  • Which business initiatives depend on security readiness?


Without this business context, even technically correct security recommendations may be irrelevant, poorly prioritized, or disconnected from the company’s real needs.


For example, a recommendation to invest in an expensive security platform may make little sense if the company’s main risk is weak access management or an undocumented incident response process.


The purpose of the stakeholder discussions is therefore not simply to collect information. It is to ensure that the security program is aligned with the business from the very beginning.


Step 2. Asset Inventory

A company cannot protect assets it does not know it has.

Together with the internal IT team, the vCISO creates, reviews, or validates an inventory of the company’s technology and information assets.

This includes:

  • All information systems and applications used by the company

  • Servers, workstations, laptops, mobile devices, and network infrastructure

  • Cloud platforms and hosted environments

  • SaaS services used by employees and departments

  • Locations where sensitive and critical data is stored

  • Business-critical databases and file repositories

  • Backup systems and disaster recovery environments

  • Code repositories and development platforms

  • Administrative interfaces and remote access systems

  • External integrations and third-party connections

  • Contractors and service providers with access to company systems

  • Users and service accounts with access to critical resources


The vCISO also examines who has access to which systems and whether that access is justified by the person’s role.

This often reveals problems such as:

  • Former employees with active accounts

  • Developers with unnecessary access to production systems

  • Shared administrative accounts

  • SaaS applications purchased without IT approval

  • Critical data stored in unapproved locations

  • External contractors with permanent access

  • Systems that are no longer actively managed

  • Business applications with no clearly assigned owner


Asset inventory is not simply an IT housekeeping exercise. It creates the baseline for risk management, vulnerability management, access control, incident response, compliance, and future investment decisions.

Without an accurate understanding of the environment, security controls will inevitably leave gaps.


Step 3. Assessing the Current Security Posture


Once the vCISO understands the business and the IT environment, the next step is a comprehensive assessment of the company’s current cybersecurity posture.

At this stage, both technical controls and organizational processes are reviewed.


The vCISO evaluates how effectively the company protects its infrastructure, applications, data, users, and endpoints.

The assessment may cover:

  • Identity and access management

  • Multi-factor authentication

  • Privileged account management

  • Endpoint protection

  • Network security

  • Cloud security

  • Email security

  • Backup protection

  • Vulnerability management

  • Patch management

  • Logging and security monitoring

  • Incident detection

  • Incident response

  • Third-party risk management

  • Data classification

  • Security awareness

  • Business continuity

  • Disaster recovery

  • Security policies and procedures

  • Regulatory and contractual compliance


The vCISO reviews not only whether a security control exists, but also whether it is working effectively.


For example, a company may have endpoint protection installed, but alerts may not be monitored. Backups may exist, but restoration may never have been tested. An incident response plan may have been written, but employees may not know where to find it or what their responsibilities are.

Security maturity is therefore assessed through both documentation and practical evidence.


By the end of the first month, the company receives an objective view of its current position:

  • Which controls are already working

  • Which processes need improvement

  • Which gaps create the highest risk

  • Which areas require immediate attention

  • Which security activities are missing entirely

  • Which controls exist only formally but are not functioning in practice

This assessment becomes the foundation for the future cybersecurity strategy and the company’s security development plan.



Days 31–60: Prioritizing and Starting with What Matters Most


After the diagnostic phase, one thing becomes clear: there will always be more security tasks than the company has time, people, or budget to complete.

The purpose of the second month is therefore not to try to fix everything at once. The purpose is to establish priorities so that every hour and every unit of budget delivers the greatest possible reduction in business risk.


Risk Assessment


The vCISO develops a risk register: a structured list of relevant cybersecurity risks, including their likelihood, potential impact, current controls, and recommended treatment.

It is a practical management tool used to make informed decisions.

The risk register helps answer questions such as:

  • Which risks are critical and require immediate action?

  • Which risks can be accepted temporarily?

  • Which risks can be reduced through compensating controls?

  • Which risks require investment in new systems or services?

  • Which risks may affect revenue, operations, clients, or regulatory compliance?

  • Which risks could delay entry into a new market?

  • Which risks should be transferred through insurance or contractual measures?

  • Who is responsible for each risk?


Typical risks may include:

  • Compromise of privileged accounts

  • Ransomware affecting business-critical systems

  • Loss of customer data

  • Unauthorized access to cloud environments

  • Disruption of critical SaaS services

  • Inadequate backup recovery

  • Weak vendor security

  • Lack of security monitoring

  • Failure to meet contractual security obligations

  • Inability to detect or respond to an incident quickly


Each risk is assessed according to the company’s real business context.

For example, the same technical vulnerability may have very different consequences for a software startup, a financial institution, a manufacturing company, or a healthcare provider.

The risk register allows management to make conscious decisions instead of reacting to isolated technical findings.


Quick Wins


At the same time as the risk assessment, the vCISO identifies measures that can be implemented quickly, at relatively low cost, and with a significant security impact.

These are often referred to as quick wins.

Typical examples include:

  • Enabling MFA for critical and privileged accounts

  • Closing Internet-exposed RDP services

  • Introducing VPN access for remote administration

  • Deactivating accounts belonging to former employees

  • Reviewing unnecessary administrator privileges

  • Improving password requirements

  • Securing backup administration accounts

  • Configuring basic email protection using SPF, DKIM, and DMARC

  • Restricting access to cloud administration portals

  • Removing unused external access

  • Updating critical Internet-facing systems

  • Conducting the first security awareness session for employees

These actions often do not require major investments in new tools.


In many cases, the company already owns the necessary technology but has not configured it properly.

Despite their simplicity, quick wins can substantially reduce the likelihood of account compromise, ransomware, unauthorized access, and phishing-related incidents.


They also create visible progress early in the engagement.

This is important because security programs need to demonstrate value. Management should be able to see that the vCISO is not only producing reports, but also reducing risk through practical actions.


Building the Cybersecurity Roadmap


By the end of the second month, the vCISO prepares a strategic cybersecurity roadmap.

This document answers three practical questions:

  • What are we going to do?

  • When are we going to do it?

  • Why is it necessary?

The roadmap usually covers the next 12 months and organizes security initiatives according to priority, business value, cost, complexity, and regulatory deadlines.


A strong roadmap is:

  • Aligned with the company’s business objectives

  • Based on identified risks

  • Realistic in terms of available resources

  • Connected to compliance and contractual requirements

  • Structured into clear phases

  • Supported by estimated budgets

  • Assigned to responsible owners

  • Measurable through defined outcomes


The roadmap may include initiatives such as:

  • Implementing centralized identity and access management

  • Introducing privileged access management

  • Improving endpoint detection and response

  • Building or outsourcing security monitoring

  • Conducting penetration testing

  • Establishing vulnerability management

  • Formalizing incident response

  • Improving backup resilience

  • Conducting security awareness training

  • Preparing for ISO 27001 or SOC 2

  • Introducing third-party risk assessment

  • Improving cloud security controls

  • Developing business continuity and disaster recovery plans


The roadmap is not based on abstract best practices alone.

Every initiative should be connected to a specific business risk, customer requirement, regulatory obligation, or strategic objective.

For example, the reason for implementing logging and monitoring may not simply be “because it is recommended.” It may be necessary to reduce incident detection time, meet SOC 2 requirements, support a client contract, or prepare for an investor due diligence process.

The roadmap also contains estimated budget requirements for each initiative.

This allows the company to plan security spending instead of responding to unexpected demands throughout the year.

The roadmap becomes the basis for a structured discussion with the CEO and CFO about cybersecurity priorities and budget.



Days 61–90: Structure, Processes, and the First Measurable Results


The third month marks the transition from assessment and planning to structured, repeatable security management.

During this period, the vCISO begins formalizing the processes that will support the company’s cybersecurity program over the long term.


Core Security Documentation


One of the most underestimated elements of cybersecurity is clear, practical, and usable documentation.

Many companies either have no security policies or rely on documents that were copied from templates, written for audit purposes, and never used in daily operations.

A vCISO develops or updates the core documents the company actually needs.

These typically include:


Information Security Policy


This is the foundational document that defines the company’s general security principles, responsibilities, and expectations.

It explains:

  • Who is responsible for cybersecurity

  • Which security rules apply to employees and contractors

  • How company information should be handled

  • How access should be controlled

  • Which activities are prohibited

  • How security violations are managed

  • How security responsibilities are distributed

The policy should be understandable and relevant to the organization. It should not be a collection of generic statements that employees cannot apply in practice.


Incident Response Procedure


The incident response procedure explains what the company should do when something goes wrong.

It defines:

  • What qualifies as a security incident

  • How employees report suspicious activity

  • Who must be contacted

  • Who coordinates the response

  • Which technical and business teams are involved

  • How evidence is preserved

  • How management is informed

  • When clients, partners, insurers, or regulators must be notified

  • How lessons learned are documented

In a real incident, people do not have time to invent a process.

They need a clear instruction that tells them who does what and in which order.


Password and Access Management Policy


This document defines specific access control requirements instead of relying on vague wording such as “users must choose secure passwords.”

It may include:

  • Password length and complexity requirements

  • MFA requirements

  • Rules for privileged accounts

  • Password manager usage

  • Access approval procedures

  • Prohibition of shared accounts

  • Periodic access reviews

  • Requirements for service accounts

  • Procedures for emergency access

  • Account lockout and recovery rules


Onboarding and Offboarding Procedure


This procedure ensures that new employees receive only the access they need, while departing employees lose access immediately.

The process defines:

  • Who requests access

  • Who approves it

  • Which systems are included

  • Which equipment is issued

  • Which security training is required

  • How access is reviewed when an employee changes roles

  • How accounts are disabled during offboarding

  • How company equipment and credentials are returned

  • How access granted to contractors is terminated

This procedure reduces one of the most common security risks: uncontrolled and outdated access rights.

These documents are not bureaucracy.

They are operating instructions for people who need to make correct decisions during routine and non-routine situations.



The First Employee Security Training


Technical controls protect systems.

Training helps protect people, who remain one of the most frequently targeted parts of any organization.

During the first 90 days, the vCISO organizes the company’s first structured cybersecurity awareness session.

The training typically covers:

  • How to recognize phishing emails

  • How to verify suspicious requests

  • What to do after clicking a suspicious link

  • How to report a potential incident

  • How to handle corporate data securely

  • How to use passwords and MFA correctly

  • How to work securely from home or while traveling

  • How to recognize social engineering

  • How to protect corporate devices

  • How to avoid unauthorized applications and cloud services

This should not be a generic one-hour lecture with attractive slides and no practical relevance.


Effective training uses realistic scenarios based on actual attack methods and is adapted to the company’s industry, technology, and employee roles.

For example, the risks relevant to finance employees may differ from those relevant to developers, sales teams, or system administrators.


The goal is to help employees recognize a threat and respond correctly when they encounter one.



Metrics and Management Reporting


By the end of the 90-day period, the vCISO establishes a reporting system for management.

The purpose is not to overwhelm executives with technical details.

The purpose is to provide a clear, business-oriented view of the company’s cybersecurity posture.

Typical metrics may include:

  • Number of critical vulnerabilities identified

  • Number of critical vulnerabilities remediated

  • Percentage of privileged accounts protected by MFA

  • Number of inactive accounts removed

  • Status of high-priority risks

  • Progress against the cybersecurity roadmap

  • Security incidents and suspicious events identified

  • Average time to respond to security issues

  • Employee training completion

  • Status of compliance initiatives

  • Backup restoration testing results

  • Completion of priority security projects


The CEO and CFO should be able to understand:

  • What the company’s most significant risks are

  • Which actions have already been completed

  • Which risks remain unresolved

  • Which investments are required

  • Whether the company’s security posture is improving

  • Whether deadlines and regulatory obligations are being met

Management reporting turns cybersecurity from an isolated technical function into a visible part of corporate governance.



What the Company Has After 90 Days


After the first three months of working with a vCISO, the company should have a clear and practical set of results.

These include:

  • A complete picture of the current cybersecurity posture

  • A clear understanding of what controls already exist

  • Identification of the most significant security gaps

  • A prioritized cybersecurity risk register

  • Immediate high-risk issues addressed through quick wins

  • A 12-month strategic cybersecurity roadmap

  • Budget estimates for major security initiatives

  • A core package of information security policies and procedures

  • A formal incident response process

  • A structured onboarding and offboarding procedure

  • Improved access management

  • The first employee cybersecurity awareness training

  • A management reporting system

  • Clear security ownership and responsibilities

  • A stronger basis for communication with clients, investors, auditors, and regulators

  • A structured foundation for future compliance initiatives

  • A clear explanation of where security investment is needed and why

In practical terms, the company moves from a fragmented and reactive approach to a managed cybersecurity program.

Before the vCISO engagement, security may depend on individual employees, informal decisions, and isolated technical tools.

After 90 days, the company has a documented understanding of its risks, agreed priorities, assigned responsibilities, measurable actions, and a realistic development plan.



The Most Common Question: What Happens After the First 90 Days?


A vCISO is not a project with a fixed end date.

It is an ongoing security leadership function adapted to the company’s size, risks, and pace of development.


After the first 90 days, the work moves into a continuous management and improvement phase.

This usually includes:

  • Monthly or quarterly meetings with management

  • Monitoring the implementation of the cybersecurity roadmap

  • Updating the risk register

  • Responding to new threats

  • Reviewing significant security incidents

  • Supporting internal IT and security teams

  • Managing security priorities

  • Reviewing new systems and business initiatives

  • Assessing new vendors and contractors

  • Supporting compliance projects

  • Preparing for audits and client assessments

  • Reviewing security metrics

  • Updating policies and procedures

  • Coordinating security testing

  • Supporting incident response

  • Advising management on security-related investments

The vCISO also participates in strategic decisions that have a cybersecurity dimension.

These may include:

  • Entering a new market

  • Launching a new product

  • Migrating to a new cloud platform

  • Selecting a critical technology provider

  • Outsourcing business processes

  • Working with a new enterprise client

  • Responding to an investor due diligence request

  • Preparing for an acquisition

  • Expanding the workforce

  • Opening a new office

  • Integrating another company’s systems

The company therefore receives more than a one-time assessment.

It receives continuous access to senior cybersecurity expertise without having to hire a full-time executive whose workload may not justify a permanent position.



Is a vCISO Right for Your Company?


A vCISO may be the right choice if:

  • You do not have an internal CISO

  • Security responsibilities are handled informally by the IT Director or CTO

  • Your company needs a systematic approach instead of isolated technical solutions

  • You are preparing for ISO 27001, SOC 2, DORA, or another compliance framework

  • You are facing an investor or customer security assessment

  • You are entering the EU or another regulated market

  • You are scaling quickly and security processes are not keeping pace

  • You understand that cybersecurity risks exist but do not know where to begin

  • You need strategic expertise but do not need a full-time security executive

  • Your clients increasingly expect evidence of mature security practices

  • You need to build a security budget based on business risk

  • You want independent oversight of your current security activities

The value of a vCISO is not limited to producing policies or recommending tools.


The real value lies in turning cybersecurity into a structured business function with clear priorities, defined responsibilities, measurable progress, and a direct connection to the company’s strategic objectives.


If you want to understand whether the vCISO model fits your situation, the best place to start is a short consultation.


The ESKA team will ask several practical questions about your business, current security posture, regulatory requirements, and development plans.

Based on those answers, we will explain honestly whether your company needs ongoing vCISO support, a one-time assessment, a compliance project, technical security improvements, or a different approach entirely.

 
 
 

Comments


bottom of page