Part-time security leadership

Virtual CISO for UK organisations

A named senior lead to coordinate security strategy, risk treatment and incident readiness without a full-time appointment. I lead the remit personally; Dead Simple Computing Ltd contracts the work, which is delivered within its applicable insurance and governance controls. The board and business risk owners retain ultimate responsibility.

What I can maintain and coordinate

  • Maintain a proportionate security plan, risk register and programme of agreed actions.
  • Coordinate named business risk owners and make overdue or disputed decisions visible.
  • Set and review policies, architecture principles and evidence requirements.
  • Scrutinise supplier controls, reports and claims rather than accepting assurance at face value.
  • Prepare and exercise incident plans, escalation routes and decision records.
  • Prepare evidence-based responses for customer, insurer and board review and approval.
  • Report material risk, progress, limitations and decisions in plain language.

When a vCISO fits

The role is useful when security responsibilities are distributed but nobody senior holds the whole picture; when customers, insurers or regulators are asking questions that operational teams cannot answer consistently; or when a growing organisation needs a credible security direction before it can justify a permanent CISO.

A vCISO is leadership, not a replacement for day-to-day IT operations, a managed security service or a security operations centre. Those capabilities may sit underneath the role, but their providers should have clear requirements and remain accountable for their contracted work.

Risk remains owned by the organisation

I can maintain the process, challenge evidence, recommend treatment and exercise agreed authority. I cannot remove the board's accountability or accept risks on behalf of unnamed business owners. Each material risk needs an owner able to make the commercial decision it requires.

The point of the role is to make that ownership work in practice: decisions are prepared properly, limitations are explicit, and progress is reported often enough that security does not drift between annual audits or customer questionnaires.

Credentials and certification boundary

My relevant credentials include CISSP, MCIIS and Cyber Advisor (Cyber Essentials). I am also a Cyber Essentials Assessor and Defence Cyber Certification Assessor at Level 0.

Advice and certification are separate. Cyber Essentials and Defence Cyber Certification assessments are delivered through Dead Simple Computing under the applicable licensed process, not automatically bundled into a Daniel-led vCISO remit. Potential conflicts are identified before certification work begins; where adequate separation cannot be demonstrated, another certification body should be used.

How the engagement is shaped

  1. Baseline. Establish the material services, information, obligations, existing risks and current decision-makers.
  2. Remit. Agree priorities, days, reporting line, authority, risk owners and boundaries with internal teams and suppliers.
  3. Operate. Maintain the plan and risk process, prepare decisions, coordinate actions and report progress.
  4. Exercise and review. Test incident readiness, revisit the threat and business context, and adjust the remit or hand it over cleanly.

If the gap covers technology strategy and delivery as well as security, see the fractional CTO service. A combined remit is possible only when the available time and responsibilities remain credible.

Common questions

What does a virtual CISO do?

A virtual CISO provides continuing senior security leadership on a part-time basis. The role can maintain the security plan and risk register, coordinate risk owners, prepare incident plans, scrutinise suppliers and report risk and progress to the board within an agreed remit.

Does appointing a vCISO transfer security accountability?

No. The board and the organisation's named business risk owners retain ultimate accountability. I can maintain the process, challenge evidence, prepare decisions and exercise specific delegated authority, but organisational risk cannot simply be outsourced.

Can a vCISO help with Cyber Essentials?

Yes, as an advisory and coordination role, but advice and certification are separate activities. Potential conflicts are identified before certification work starts, and the assessment route must comply with the scheme requirements. Where sufficient separation is not available, another certification body should be used.

Personally led

You deal with me and I do the work. Dead Simple Computing Ltd contracts and invoices the engagement, while I personally scope, lead and substantially deliver the vCISO remit. Any potential supplier, certification or commercial conflict is raised before it can affect the remit.

Fees are separately scoped to reflect direct senior involvement, complexity, discretion, limited capacity and the bespoke responsibility and availability agreed for the role.

Read about my background and credentials.

Discuss a retained security leadership role

Describe what is driving the need, where security responsibility currently sits and who the role would report to. I will tell you whether a vCISO remit or a focused project is the better fit.