Virtual CISO for SMBs

A senior security lead for your business, without the full-time salary.

When a customer, your insurer or a regulator asks how you manage cyber risk, you have a clear answer, and one senior person in charge of the plan. Part-time, in English or French.

What we do

Five ways we help, and when you need each one.

01 / Leadership

Virtual CISO

When customers, insurers or the board ask who is in charge of security. You get one senior person who leads it for you, part-time.

Learn about our vCISO service
02 / AI

AI governance

When your team already uses AI tools. You get clear rules to use them safely, and you know what the EU AI Act asks of you, if anything.

See AI governance
03 / Compliance

Regulatory compliance

When a law or a customer contract sets security requirements. You get a clear view of what applies to you and a plan to meet it.

Explore compliance services
04 / Training

Training & awareness

When fake invoices and phishing emails reach your staff. You get a team that pauses before acting, and a training record for customers and insurers.

See training programmes
05 / Audit

Internal audit

Before a certification audit or a key customer's review. You get an independent check and a list of fixes, before they look.

Learn about internal audits

Laws and standards

Not sure which rules apply to you?

We cover the EU laws and the certifications customers ask for, from NIS2 and GDPR to ISO 27001 and the AI Act. Each page starts with one question: does it apply to you?

Why Cyber-Management

Senior leadership, sized for a small business.

We lead, your IT provider builds

We set the priorities, write the rules and check the work. Your IT team or provider keeps the technical side.

One senior person, start to finish

The same certified consultant from the first call to the final report. No junior hand-offs.

Fixed fees, never hourly

You know the price before you sign, and it does not move with the hours.

In English or French, across the EU

Remote by default, on-site when it helps. Based in France, working with companies across Europe.

Certifications held personally by your consultant

CISSP
(ISC)²

The reference certification for senior security professionals.

PECB
ISO/IEC 27001 Lead Auditor

Qualified to audit a company’s security management.

PECB
ISO/IEC 42001 Lead Auditor

Qualified to audit how a company manages AI.

Questions

What owners ask us first.

What is a virtual CISO, and does my company need one?
A virtual CISO is a part-time head of security. If customers, your insurer or a regulator ask how you manage cyber risk and nobody can answer, you probably need one. It costs a fraction of a full-time hire.
How quickly can you start?
Within one to two weeks of the first call. We start by reviewing where you stand, then agree a plan with you in the following weeks.
Do you replace our IT provider?
No. We lead security: priorities, rules, checks and reporting. Your IT team or provider keeps running and configuring your systems, and we make sure their work adds up to the plan.
Where do you work?
Across the EU, in English or French: France (mainland and overseas regions), Belgium, Luxembourg, Switzerland and the wider European market. Remote by default, on-site when it helps.