Working model

Establish truth first, then ownership, then an operating cadence.

vciso.tr connects security leadership, assurance, AI governance, privacy, and vendor risk to business risk, decisions, and evidence—not a product-resale agenda.

Independent working principles

  • No software/license resale
  • No vendor commissions
  • Direct senior-practitioner involvement
  • Evidence and business risk first
  • No claim of legal advice or certification guarantee
01 · Fit

Who is this model for?

Companies that are early for a full-time CISO but too mature for informal security ownership

Teams under ISO 27001, SOC 2, DORA, or enterprise customer-review pressure

Leadership teams that need clearer ownership across AI, privacy, vendor risk, or board reporting

02 · Engagement

Choose the shape around the actual need

One retainer format does not fit every company.

03 · First 90 days

A 30 / 60 / 90-day operating model

  1. 0–30 days — Establish truth: make scope, obligations, customer commitments, material risks, current controls, and evidence visible.
  2. 31–60 days — Establish ownership: assign risk owners, control owners, evidence owners, exception paths, and executive reporting.
  3. 61–90 days — Establish rhythm: begin recurring reviews, board/executive briefs, assurance backlog management, and the longer roadmap.
04 · Outputs

An engagement should answer “what is materially different now?”

Executive cyber risk brief
90-day security roadmap
Risk and exception decision register
Control-owner-evidence matrix
Customer security questionnaire response library
Board / leadership dashboard
Vendor risk tiering and review model
AI use-case inventory and risk tiering
Assurance and evidence-maintenance calendar

Open illustrative output examples

Good fit

When does this model make sense?

  • Senior security judgment is missing
  • Customer-assurance demand is recurring
  • Risk and evidence are fragmented across teams
  • No leadership decision cadence exists
  • You want an operating program rather than a binder of policies
Not a fit

What is this not?

  • 24/7 SOC/MDR service
  • Only a penetration test
  • Scanner or agent resale
  • Legal advice or regulatory representation
  • A certification guarantee without operational change
Before buying

Common questions

What happens in the first conversation?

We clarify current pressure, scope, customer/audit expectations, material risks, decision owners, and what output needs to exist in the first 30–90 days.

Does a virtual CISO replace a full-time CISO?

Not for every company. Fractional leadership can close the gap during growth; a full-time role is more appropriate when daily leadership of a larger team and continuous executive presence are required.

Are deliverables only documents?

No. The goal is an operable system: risk ownership, evidence map, executive reporting cadence, decision records, customer-assurance library, and an owned priority plan.

Does vciso.tr sell security products?

No. There is no software/license resale or vendor-commission model. Adding a new product is not the default answer when the current environment can solve the problem.

Start with your own data

See your readiness before completing a contact form.

Assessments calculate in the browser and require no email or account to see results.