vCISO · Virtual Chief Information Security Officer

CISO-level experience.
In the capacity your company needs.

CISO360 is a vCISO practice for fintechs and software houses — security strategy, compliance and operational resilience, without the cost of a full-time hire.

DORA NIS2 ISO 27001 KNF requirements Secure SDLC

20+ years of hands-on practice in cybersecurity — financial services and the public sector.

Scope

What we do

A full picture of your organisation's security — from strategy and board conversations to security DNA built into your company's processes.

Security leadership

Security strategy, priorities and budget. Board language, not just tech — security reported in a way that supports business decisions.

Compliance that makes sense

DORA, NIS2, ISO 27001, supervisory expectations. Implementations aimed at real security — the certificate is a result, not the goal.

Risk & resilience

Risk management, business continuity, incident readiness. When every minute counts, procedures must work — not merely exist.

Secure product

Secure SDLC and security built into the delivery cycle. Good answers to the questions enterprise clients ask more and more often.

Clients

Specialisation, not everything for everyone

We work where security is a condition for business growth.

Fintech

Financial supervision, DORA, investor due diligence. In a regulated business, security is not optional — it is a condition for growth. We help you get it in order before a regulator or a fund asks about it.

Software house

Your clients ask about security in ever greater detail. Due diligence questionnaires, NIS2 supply-chain requirements, enterprise client audits — we help you have good answers in your processes, not just on slides.

Engagement model

How we work

From a first review to ongoing care — at a pace and scale that fits your organisation.

01

Assessment

A review of your security posture and key risks. A 360° picture — specific, with no scare tactics and no finger-pointing.

02

Roadmap

Priorities in quarters, not years. A plan that respects your actual budget and your team's actual capacity.

03

Ongoing care

A vCISO on retainer — from a few days a month to on-demand readiness when things heat up.

Contact

Let's talk about security

Most people find CISO360 through a referral. If that's how you got here — write to us.

 

Security reports: security.txt