Monthly vCISO · Security management as a service
Security management as a service: multi-model defensive AI + human supervision of the responsible party. Without the cost of a full-time CISO. Flexible quarterly commitment or annual at the best price.
Monthly vCISO
AI-first security management with human supervision, without hiring an in-house CISO
Most mid-sized companies do not need a full-time CISO. They need someone who makes decisions with sound judgement, who can say no to a vendor selling smoke, and who can sit in a board meeting without the room losing all technical context when they start speaking.
What it is
OCIRIA's vCISO is an AI-first hybrid service with human supervision. The ongoing analytical workload (ticket review, log correlation, draft writing, monitoring of applicable regulation) is executed by our defensive AI stack (models specialised by task: scanning, correlation and critical analysis). Validation, sign-off and quarterly accountability are assumed by the human responsible at Ibida Black Level.
It saves you two things: (1) the cost of a senior profile on your payroll (between salary costs, benefits and selection time, it does not fall below six figures annually in Spain) and (2) dependence on a single person who may fall ill, leave or become overloaded. AI scales without fatigue; human supervision guarantees judgement.
What distinguishes a well-executed vCISO from a poor one is operational depth: our defensive AI stack reads supplier contracts line by line, correlates open tickets in your incident management system, drafts responses to audits, and the human responsible validates and signs every decision, sitting across from the board with live risks on a spreadsheet, not with good intentions in a PowerPoint.
When you need it
Three typical signals indicate the moment has come to bring in a vCISO:
You are being asked things you do not know where to start with. A corporate client sends you a fifty-page security questionnaire. An insurer asks whether you have an incident response plan. A private equity fund, in the middle of due diligence, wants to see your access management policy. Your internal technical team can answer the operational questions, but someone is needed to organise, prioritise and sign.
You have had an incident, or a near-miss nearby. Ransomware at a company in your sector, a data leak at a shared supplier, a phishing email that nearly got through. The board wants to know if you are prepared. You need someone who makes the diagnosis and designs the plan, not someone who simply says "everything is fine" or "everything is wrong".
You are growing faster than your security organisation. You go from fifty to two hundred employees in two years. You open offices in another country. Your product starts handling sensitive data. The security that worked with forty people does not work with two hundred, and reacting late is expensive.
How we work
Phase 1 · Initial diagnosis (weeks 1-2). Interviews with management, technical team and, where relevant, business owners who handle sensitive data. Review of asset inventory, existing documentation, current supplier contracts and past incident records. We close with a situation report, a prioritised risk matrix and a quarterly plan proposal with three to five measurable objectives.
Phase 2 · Plan implementation (months 1-3). The vCISO leads execution. Coordinates the internal technical team or external suppliers, validates deliverables, escalates blockers and keeps management informed. One monthly meeting with management, one weekly with the technical team, asynchronous communication otherwise.
Phase 3 · Review and adjustment (end of each quarter). Progress report against the plan, lessons learned, adjustment of the following quarter's plan. If new risks emerged, they are incorporated. If something does not add value, it is discarded without ceremony.
Phase 4 · Ongoing support. Once the routine is established, the vCISO is available to represent the organisation before external auditors, respond to client security questionnaire requests, attend supplier negotiations and resolve ad-hoc questions from the management team.
What we deliver
- Monthly decision log on decisions taken and pending for management.
- Live risk matrix, updated at least quarterly, with owner and deadline per risk.
- Annual security plan reviewable quarterly, aligned with business objectives.
- Quarterly report with metrics (mean detection time, critical tickets closed, spend against budget, regulatory compliance).
- Validated responses to client and insurer questionnaires.
- Accompaniment in external audits and technical representation before management.
- Centralised document repository, owned by your organisation (it does not remain with us if the relationship ends).
Who it is for
SMEs and mid-market companies of 30 to 500 employees with sensitive data, demanding corporate clients or regulatory exposure. Typical profiles include:
- B2B SaaS company with a recent Series A/B round, enterprise contracts requiring compliance (ISO 27001, SOC 2, NIS2) and a technical team that knows how to build but not how to certify.
- Industrial manufacturer or distributor with international presence, OT (operational technology) in production, and a growing obligation to demonstrate resilience to clients and insurers.
- Professional services (consulting, legal, accountancy) handling third-party information and needing to cover their liability without over-dimensioning.
FAQs
How many hours per month do I need to contract?
It depends on size and maturity. The usual range for mid-market is between twenty and sixty hours per month. The initial diagnosis defines the right range. It can be adjusted quarterly.
Is there a minimum commitment?
You choose the commitment: annual, at the best price, or quarterly, at a slightly higher price in exchange for full flexibility. In both cases, at the end of the chosen commitment you can leave without penalty with one month's notice.
Do you work remotely or in person?
By default remote, with in-person visits when they add value (kick-off, key board meeting, management of a major incident). We do not require mandatory office presence nor charge travel costs without prior agreement.
What happens if I need someone outside my contracted hours?
If it is a real incident, we respond. If it is additional plannable work, it is agreed and invoiced separately without surprises. We do not use the "hour pool that evaporates" method nor charge for unused hours.
Can you cover multiple regulations or only one?
We cover those that apply to your sector: NIS2, GDPR, ISO 27001, ISO 42001, DORA if applicable, national security scheme if applicable, and contractual requirements from corporate clients. The vCISO is specifically trained in the regulatory framework relevant to you.
How is confidentiality managed?
Confidentiality agreement signed before the diagnosis. The vCISO does not share your company's information with other clients, not even in anonymised form in public reports. If a conflict of interest arises (direct competitor), we will tell you before accepting the engagement.
Typical use cases
Case 1 · The SaaS preparing its first certification. Software company with seventy people, recently closed Series B, two enterprise clients requesting SOC 2 Type II as a renewal condition. Initial diagnosis reveals absence of a formal access management policy, partial audit logs and lack of a continuity plan. The vCISO leads the programme for six months, coordinating the internal technical team to implement controls and prepare for the external audit. Result: certification obtained on the first attempt, enterprise contract renewed.
Case 2 · The industrial manufacturer post-incident. Family business, one hundred and twenty employees, two production plants. After a ransomware attempt contained by an old internal system but with luck, management decides to professionalise the function. The vCISO enters as security management without formal appointment, defines a twelve-month plan, segments the OT/IT network, formalises incident response, and represents the company before the insurer when the cyber-risk policy is renegotiated (with an effective premium reduction due to improved controls).
Case 3 · The professional firm with cross-cutting obligations. Law firm with forty professionals, client data with high-value profiles, exposure to both GDPR and specific sectoral regulation. The vCISO leads a security programme focused on confidentiality and traceability, formalises protocols for collaborations with foreign firms, and prepares responses to questionnaires from banks and listed companies that require annual due diligence.
Pricing
AI-first vCISO is offered in three monthly retainer modalities. All plans include the defensive AI stack and the personal signature of the person responsible at Ibida Black Level S.L.
| Plan | Dedication | Price/month · annual commitment | Price/month · quarterly |
|---|---|---|---|
| Base | 2 days/month · quarterly reporting + RFP/questionnaire support | 1,890 € | 2,090 € |
| Standard | 4 days/month · monthly reporting + biannual tabletop + pre-audit support | 3,490 € | 3,890 € |
| Premium | 6-8 days/month · board presence + full GRC programme management | 5,890 € | 6,490 € |
The annual commitment offers the best price; the quarterly modality adds full flexibility. Prices are indicative for companies up to two hundred and fifty employees with a single primary technology environment. Multi-site, regulated sectors (health, financial, energy) or programmes with three or more simultaneous certifications are adjusted in the proposal following the initial diagnosis.
Payment terms. Monthly invoicing, first month in advance. Exit without penalty with thirty days' notice at the end of the chosen commitment (quarter or year).
How to start
The first step is always an initial diagnosis of one week. No commitment. If after the diagnosis we decide not to work together, there is no cost.
We will tell you exactly how the supervision mechanics will work: which tasks our defensive AI assumes, which deliverables the human responsible signs, what the validation cadence is. If the proposal does not suit you, there is no relationship. It is as simple as that.
Write to us at [email protected]