A security executive without the executive hire
Gulf organisations facing NCA ECC, SAMA CSF and PDPL obligations rarely need a full-time CISO before they need the compliance. Our vCISO carries the mandate, with accredited partner capacity behind them.
vCISO — mandate, roadmap and regulator readiness
A named security executive who owns the program, reports to your board in Arabic or English, and is accountable to the regulator's timeline rather than a consulting statement of work.
- Security strategy mapped to NCA ECC domains and your sector regulator's expectations
- A risk register your board can read (5×5) and your CFO can price (FAIR)
- SAMA CSF maturity uplift plan for regulated financial institutions
- PDPL readiness: lawful basis, cross-border transfer, breach notification, DPO duties
- Aramco CCC / SACS-002 supplier certification path where it applies
- Incident response plan written, tested and rehearsed with your executive team
- Security strategy and a 12-month roadmap costed against Essential Eight maturity targets
- A risk register your board can read (5×5) and your CFO can price (FAIR)
- Essential Eight ML1 → ML2 uplift plan with the evidence assessors actually ask for
- Incident response plan written, tested and rehearsed with your executive team
- Third-party and supply-chain assessment for your critical vendors
- Security input to tenders, customer due diligence and cyber insurance renewals
What lands on the board table
- Quarterly board pack in Arabic and English, generated from live control evidence
- NCA ECC compliance position by domain, with gaps and owners named
- SAMA CSF maturity level and the specific evidence holding you at it
- Third-party and supplier cybersecurity status across the register
- Top five risks with financial exposure, not a heat map of coloured squares
- Quarterly board pack generated from live control evidence, not last quarter's memory
- Essential Eight maturity scorecard, strategy by strategy
- Notifiable data breach readiness under the Privacy Act, with the 30-day clock mapped
- SOCI and APRA CPS 230 obligation status where they apply to you
- Top five risks with dollar exposure, not a heat map of coloured squares
Arabic and English reporting · partner-delivered execution · data residency options in KSA
The eight domains a SAK vCISO owns
Not a menu to pick from — all eight are in scope from day one. What changes between tiers is depth and cadence, not coverage.
Security strategy & roadmap
Current state assessed in the first fortnight, a target state defined against the framework that actually binds you, and a costed 12-month roadmap with sequencing, owners and dependencies — re-baselined quarterly, not written once and filed.
Roadmap tracked in GRCorbGovernance
The full branded policy set — information security, acceptable use, access control, cryptography, supplier security, secure development, continuity, incident response — plus the machinery around it: roles, a steering group with a standing agenda, an exception register with expiry dates, and an annual management review.
Satisfies ISO 27001 clause 9.3Risk management
A register your board can read (5×5, plain language) and your CFO can price (FAIR quantification on the top risks, in dollars). A written risk appetite statement, so "acceptable" stops being a matter of opinion. Treatment plans with named owners and due dates.
ISO 31000 · FAIRCompliance & certification
Framework selection and scoping, gap assessment, and an evidence program configured once and then collecting continuously — rather than assembled in a panic before an audit. Your assessor works inside the platform. Covers NCA ECC, SAMA CSF, PDPL, Aramco CCC (SACS-002), NDMO data standards, ISO/IEC 27001:2022 and PCI DSS v4.0.1.
Gulf frameworks mapped natively in GRCorb · Arabic reportingThird-party & supply chain risk
A vendor register tiered by the access each supplier actually has. Security requirements written into contracts and renewal checklists. Assessments proportionate to tier — not a 300-question spreadsheet for the company that supplies your coffee.
Monitored by SAK VendorTechnical standards & oversight
Identity and MFA, privileged access, patching SLAs by severity, logging and retention, backup and restore testing, cloud baselines, endpoint hardening, secure development. The vCISO sets the standard and verifies it is met; your team does the hands-on work.
Each becomes a control with evidence attachedIncident readiness & response
An incident response plan written for your organisation, playbooks for the scenarios that actually apply to you, an annual tabletop with your executive team, and a breach-notification decision tree mapped to your obligations. When something happens, the vCISO leads the executive response.
PDPL notification duties · NCA incident reportingBusiness enablement
Security questionnaires and RFP responses answered properly and fast. Customer due-diligence calls attended, so sales isn't defending a control set it doesn't understand. Cyber insurance renewals, board and investor reporting, security diligence for funding or acquisitions.
Where the retainer pays for itselfSecurity strategy & roadmap
Current state assessed in the first fortnight, a target state defined against the framework that actually binds you, and a costed 12-month roadmap with sequencing, owners and dependencies — re-baselined quarterly, not written once and filed.
Roadmap tracked in GRCorbGovernance
The full branded policy set — information security, acceptable use, access control, cryptography, supplier security, secure development, continuity, incident response — plus the machinery around it: roles, a steering group with a standing agenda, an exception register with expiry dates, and an annual management review.
Satisfies ISO 27001 clause 9.3Risk management
A register your board can read (5×5, plain language) and your CFO can price (FAIR quantification on the top risks, in dollars). A written risk appetite statement, so "acceptable" stops being a matter of opinion. Treatment plans with named owners and due dates.
ISO 31000 · FAIRCompliance & certification
Framework selection and scoping, gap assessment, and an evidence program configured once and then collecting continuously — rather than assembled in a panic before an audit. Your assessor works inside the platform. Covers Essential Eight (ML1 → ML3), ISO/IEC 27001:2022, SOC 2, the Privacy Act and Notifiable Data Breaches scheme, the SOCI Act risk management program, APRA CPS 234 and CPS 230, and ISM/IRAP where you sell to government.
Australian frameworks mapped natively in GRCorbThird-party & supply chain risk
A vendor register tiered by the access each supplier actually has. Security requirements written into contracts and renewal checklists. Assessments proportionate to tier — not a 300-question spreadsheet for the company that supplies your coffee.
Monitored by SAK VendorTechnical standards & oversight
Identity and MFA, privileged access, patching SLAs by severity, logging and retention, backup and restore testing, cloud baselines, endpoint hardening, secure development. The vCISO sets the standard and verifies it is met; your team does the hands-on work.
Each becomes a control with evidence attachedIncident readiness & response
An incident response plan written for your organisation, playbooks for the scenarios that actually apply to you, an annual tabletop with your executive team, and a breach-notification decision tree mapped to your obligations. When something happens, the vCISO leads the executive response.
Privacy Act serious-harm test · 30-day OAIC clock · SOCI reportingBusiness enablement
Security questionnaires and RFP responses answered properly and fast. Customer due-diligence calls attended, so sales isn't defending a control set it doesn't understand. Cyber insurance renewals, board and investor reporting, security diligence for funding or acquisitions.
Where the retainer pays for itselfOne named executive, one standard behind them
You are not buying a personality, and you are not buying a pool. You are assigned one named security executive who works to a method the whole practice shares — so what you get does not depend on which individual you happened to draw.
- Assigned, not pooled
- You get one named executive for the life of the engagement, introduced by name at proposal stage — before you sign, not after. They chair your leadership meeting and they present to your board.
- The minimum bar
- Every SAK vCISO holds CISSP or CISM, has held security leadership accountability inside a regulated organisation, and has taken at least one organisation through a certification end to end.
- Matched to you
- Matched on sector and on the framework that binds you. The vCISO who took a scale-up through Essential Eight is not automatically the right one for a SAMA-regulated bank.
- A named second
- Every engagement has a named backup who attends the quarterly review and can step in without a handover period. Your program does not depend on one person's calendar, health or notice period.
- How we work
- Remote-first, in Gulf working hours, with Arabic and English reporting. On-site for the kickoff, the annual tabletop, and board meetings where being in the room matters. Additional on-site days can be added to any tier.
- Why the bench is the point
- Every SAK vCISO runs the same method: the same discovery on SAK Surface, the same control library in GRCorb, the same risk model, the same board-pack format. Consistency is engineered, not hoped for — which is also why we can scale without the quality drifting.
- Assigned, not pooled
- You get one named executive for the life of the engagement, introduced by name at proposal stage — before you sign, not after. They chair your leadership meeting and they present to your board.
- The minimum bar
- Every SAK vCISO holds CISSP or CISM, has held security leadership accountability inside a regulated organisation, and has taken at least one organisation through a certification end to end.
- Matched to you
- Matched on sector and on the framework that binds you. The vCISO who took a scale-up through Essential Eight is not automatically the right one for an APRA-regulated insurer.
- A named second
- Every engagement has a named backup who attends the quarterly review and can step in without a handover period. Your program does not depend on one person's calendar, health or notice period.
- How we work
- Remote-first, in Australian working hours — your vCISO is in your meetings, on your calendar and reachable in your day, not catching up overnight. On-site for the kickoff, the annual tabletop, and board meetings where being in the room matters. Additional on-site days can be added to any tier.
- Why the bench is the point
- Every SAK vCISO runs the same method: the same discovery on SAK Surface, the same control library in GRCorb, the same risk model, the same board-pack format. Consistency is engineered, not hoped for — which is also why we can scale without the quality drifting.
What the retainer does not cover
Almost nobody publishes this. We do, because an engagement that starts with an unspoken assumption ends badly — and because the buyer who reads this section carefully is the buyer worth having.
| Not included | What happens instead |
|---|---|
| 24/7 monitoring and alert triage | We do not offer round-the-clock monitoring. Managed exposure covers continuous external discovery in business hours; where genuine 24/7 operations are required we will say so and help you select a provider. |
| Hands-on remediation and engineering | The vCISO sets the standard and verifies it. The work is done by your team, or scoped as a separate SAK engagement. |
| Being the on-call responder at 3am | The vCISO leads the executive response to an incident — decisions, comms, notification, post-incident review. They are not the person staffing a rota. |
| Penetration testing | A separate engagement, deliberately. A tester should not assess controls they helped design. |
| Legal advice and regulatory filings | We prepare the facts and draft the notification content. Your lawyer advises and files. |
| Statutory roles that require an employee | Some regulator-facing designations must sit with an officer of your entity. The vCISO supports the person holding it; they cannot be it. |
| Unlimited availability | Days are fixed per tier. Incident surge time is agreed and billed at the time, not absorbed silently. |
Three levels, one minimum term
Minimum one quarter, then month to month. Anything shorter doesn't produce something worth paying for — the first ninety days is where the value is created.
| Essentials | Standard | Embedded | |
|---|---|---|---|
| Days per month | 2 | 4 | 8 |
| Typical fit | 20–80 staff, first framework, insurance or customer pressure | 80–300 staff, certifying, regulated, or selling to enterprise | Regulated entity, multi-framework, or post-incident rebuild |
| Leadership meeting | Monthly | Fortnightly | Weekly |
| Board reporting | Quarterly | Quarterly + on request | Quarterly + committee attendance |
| Frameworks in scope | 1 | Up to 2 | Unlimited |
| Incident response leadership | Business hours | Business hours + escalation | Business hours + escalation |
| Platforms included | SAK Surface + GRCorb | Full SAK Exposure + GRCorb | Full SAK Exposure + GRCorb |
Priced as a flat monthly retainer, not a day rate. Arabic and English board reporting. Minimum one quarter, then month to month.
The first 90 days
A vCISO who spends the first month "getting up to speed" has wasted a sixth of the year. SAK Exposure does discovery on day one, so the assessment starts with facts rather than a questionnaire.
- Days 1–14
Discovery
Stakeholder interviews. A SAK Surface baseline of everything internet-facing, including what nobody remembered owning. Asset and vendor registers built from discovery, not from a questionnaire.
- Days 15–30
Assessment
Gap assessment against the chosen framework. Risk register v1. Roadmap costed and sequenced. First leadership presentation: here is where you are, here is what it costs to get where you need to be.
- Days 31–60
Foundations
Branded policy pack issued. Incident response plan written. Quick wins started — MFA coverage, patching SLA, restore testing, privileged account cleanup. Evidence collection configured, so proof starts accumulating.
- Days 61–90
Operating rhythm
First board pack. Tabletop exercise with the executive team. Tier-1 vendor assessments underway. The roadmap moves from a document to a tracked program.
What we need from you
- An executive sponsor with authority to decide — without one, a vCISO produces recommendations nobody acts on
- Read-only access for evidence collection: cloud tenants, identity provider, endpoint console
- A named technical counterpart who can implement
- Attendance at the monthly leadership meeting
- Honesty in discovery — we will find what is there anyway, and finding it early is cheaper
What you have after 90 days
- A costed roadmap your board has seen and approved
- A complete, branded policy set with evidence attached to each control
- A risk register in both board language and dollars
- An incident response plan that has been rehearsed, not just written
- Continuous control evidence accumulating without anyone chasing it
- A named executive accountable for all of it
A 20-minute call, then a written proposal
We confirm scope and the framework that binds you, then send a written proposal with a fixed monthly retainer — and the executive you would get, introduced by name before you sign.
Book a vCISO discovery call