Home All services
Start a project → Call Now

vCISO services in India

Part-time security leadership, sized to what your board and regulators expect.

A vCISO (virtual chief information security officer) is a senior security leader you retain rather than employ. We offer two tiers: mid-market / growth, about 20 to 25 hours a month, and enterprise, about 40 to 50 hours a month. Both run on a 6-month minimum term, 12 months by default. Treat the hours as the size of the commitment.

  • Audit readiness in both tiers
  • Your leadership keeps the final say
  • We reply within one working day.
  • NIST CSF 2.0
  • ISO/IEC 27001:2022
  • SEC Regulation S-K Item 106
  • NIST SP 800-61 Rev. 3
Illustration: a miniature boardroom table ringed by empty chairs, with a ribbon shield and a board pack binder on the table and a chart stand showing a steadily rising line

In brief

What it is
Security leadership on a retainer. A vCISO runs your security program, keeps your risk register current and prepares the decisions your executives have to take.
Why it matters
Boards, regulators, customers and auditors expect someone to lead your security program and report on cyber risk, while your leadership stays accountable. Who your security lead answers to decides how much leadership you need, not the hours on a proposal.
What you get
Board-ready reporting, continuous audit readiness and standards your engineers can build against, on a 6-month minimum term.

Choosing a tier

Choose the tier by who reads the reports, not by the hours.

A proposal puts its hours up front, which makes them easy to compare and easy to misread. What separates our two tiers is audience: above all, whether your board wants a security lead reporting to it directly.

Tier contents follow SecWiz's retainer terms as of September 2026. Which tier fits each request is our recommendation.
If you are being asked forThe tier that fits
A security lead reporting to your board directlyEnterprise, about 40 to 50 hours a month
Security leadership, without direct board reportingMid-market / growth, about 20 to 25 hours a month
Someone to coordinate incident escalation to leadership, regulators and othersEither tier; enterprise hours include coordination
Evidence for an ISO/IEC 27001:2022 or SOC 2 auditEither tier; audit readiness comes with both

Both tiers sit inside our managed security and compliance services. For the compliance programs themselves, see governance, risk and compliance.

Where the hours go

Each part of the work is written for the people who act on it.

Your board, your auditors and your engineers each need something different from a security lead.

For your board

A board-ready cyber posture pack, with risk heat maps that show where exposure sits. It draws on a living risk register: every risk with an owner, a treatment and its current state. Direct board-level reporting is part of the enterprise tier. The register itself is covered under risk management as a service.

For auditors and customers

Continuous audit readiness and control validation (checking that each control still works) across ISO/IEC 27001:2022, SOC 2 (an independent auditor's report on a service company's controls), the NIST Cybersecurity Framework (CSF) 2.0 or ISO/IEC 42001:2023 (AI management systems), whichever your customers and auditors hold you to. The mid-market / growth tier adds continuous automated compliance monitoring: automated checks that your controls keep working and producing evidence. The evidence work itself is covered under compliance as a service.

For engineering

The policies your executives approve reach engineering as policy-as-code blueprints: the rules written in a form your systems can check automatically, so engineers can build against them. We review your cryptographic and secure development standards twice a year, and a security configuration review shows where live settings drift from them.

Before comparing proposals

Gather the papers that show who is asking questions today.

Each one shows which audience your security lead will answer to, and so which tier fits.

  1. Your last board pack

    The last pack your board saw on cyber risk, and the name of whoever presented it.

  2. Your SEC filing, if you report to the SEC

    The cybersecurity section of your annual report on Form 10-K to the US Securities and Exchange Commission (SEC). Regulation S-K Item 106, in force as of September 2026, requires it to describe how the board oversees cybersecurity risk and what role and expertise management brings. Item 106 also asks whether you engage assessors, consultants or auditors in your cybersecurity risk processes. A non-US company filing as a foreign private issuer carries comparable disclosures in its Form 20-F.

  3. What your customers ask to see

    The certificates and audit reports your customers request.

  4. Your incident response plan

    With the name of whoever would call regulators and outside parties if it had to run today.

  5. Today's risk owners

    A list, from business unit heads to the engineer who looks after production.

What stays with you

A vCISO takes on the work. Your leadership keeps the accountability.

Hiring a vCISO changes who prepares each decision, not who makes it.

NIST's guidance says your leadership is accountable for cyber risk and oversees incident response. A vCISO does not change that. What changes is who does the work around each decision: the options, the evidence and a recommendation. Your leadership still makes the call.

Decisions your executives keep

  • Risk acceptance. Choosing to live with a risk instead of fixing it, with the reason on record.
  • Risk appetite. How much cyber risk the business will accept: the line every later risk decision is measured against.
  • Budget. Setting the security budget and approving how it is spent.
  • Policies. Approving policies before they bind staff and suppliers.
  • The board's view. What the board is told about cyber risk, even when the vCISO presents it.

Our part during an incident is on the incident response page, along with the plans and runbooks written before one. Tabletop exercises and incident response drills run under Blue Team services. Log coverage and alert routing sit under threat detection support.

What NIST says leadership keeps

NIST's Cybersecurity Framework (CSF) 2.0 describes leadership as responsible and accountable for cybersecurity risk, in outcome GV.RR-01.

NIST SP 800-61 Revision 3, NIST's incident response guidance, says leadership oversees incident response, funds it and may decide high-impact actions such as shutting down or rebuilding critical services.

What this does not include. A vCISO keeps you ready for audits, but readiness is not an audit and produces no certificate. Audits and certificates come from an accredited or empanelled body, which we are not, and nobody can honestly promise you an audit result. SecWiz does not claim court-grade digital forensics credentials for incident work.

FAQ

Questions buyers ask about vCISO retainers.

Hours, term, incidents and frameworks. For anything else, ask us directly.

A fractional CISO leads a company's security program for a committed share of time instead of as a full-time employee. The work covers keeping the risk register current, preparing what the board and executives see about cyber risk, holding audit readiness and setting the standards engineering builds against. Accountability for risk decisions stays with the company's leadership.

SecWiz's vCISO services come as a mid-market / growth tier of about 20 to 25 committed fractional executive hours a month, or an enterprise tier of about 40 to 50 dedicated hours a month. Continuous automated compliance monitoring is part of the first, while the enterprise hours take in direct board-level reporting and incident escalation coordination. Let what your board and regulators expect, not the hours, decide between them.

Six months is the minimum term for a SecWiz vCISO retainer, and 12 months is the default. Both tiers share that term, so choosing enterprise for direct board-level reporting does not lengthen the commitment. A 12-month term takes in two rounds of the twice-yearly reviews of your cryptographic and secure development standards.

Ask whether the provider will report to your board directly or only brief your executives, since that is a tier decision, not a detail. Ask who runs the escalation if an incident reaches regulators, and whether hands-on containment is in the retainer. Get the term and hours in writing, and be wary of anyone guaranteeing an audit result.

At SecWiz, yes, for retainer clients, in two ways. Coordination means running the escalation plan with your leadership, regulators and other parties, and hands-on response means containment and investigation. On the enterprise tier, escalation coordination is part of the dedicated hours. SecWiz does not claim court-grade digital forensics credentials for this work.

A SecWiz vCISO retainer covers ISO/IEC 27001:2022, SOC 2, NIST CSF 2.0 and ISO/IEC 42001:2023, keeping audit readiness and control validation current for each you need. Which apply depends on what your customers, auditors and regulators expect, and a company can answer to more than one at once. Readiness comes with both tiers, so the framework list does not decide which tier fits; who reads your security reporting does.

Let's talk

Start with who reads your security reports.

Tell us who sees your cyber risk reporting now and what your last audit asked of you. From there we can work out which tier fits. We reply within one working day.