Senior as a Service

Some organisations need security judgement every week, but not a full-time security director on the payroll. CISO as a Service is exactly that: someone accountable, with a fixed schedule and the standing to say no, without the cost of a senior hire.

Who it makes sense for

Companies that have grown faster than their security function, where decisions are taken by whoever can rather than whoever should.
Organisations with a regulatory obligation on them — NIS2, DORA, the ENS, ISO 27001 — that requires an identifiable owner.
Capable IT teams that need an independent second opinion before signing off architectures or contracts.
Companies going through vendor assessment by a large client, with security questionnaires nobody knows how to answer.
Temporary cover for absence or a vacancy in the security function.

What an external CISO actually does

Governance
Decide and document
Policies that get applied, a risk assessment that gets reviewed and a security roadmap with a budget defensible to the board.
Operations
Prioritise
What gets done this quarter and what does not. On technical judgement, not on whatever made the most noise that week.
Interface
Answer
Client questionnaires, audits, contractual requirements and, when it comes to it, the conversation with the regulator or the insurer.

How we work

1
Initial assessment
One month to establish where you are: assets, risks, obligations, technical debt and who decides what today.
2
Security roadmap
What to do over the next twelve months, in what order and at what cost. Approved by management, not by the IT department.
3
Fixed cadence
An agreed commitment — days per month, not scattered hours — with attendance at the relevant committees.
4
Delivery and tracking
Progress measured against the roadmap, with indicators management understands without translation.
5
Technical escalation
When a pentest, a forensic investigation or an implementation is needed, the in-house technical team covers it without changing supplier.

What you get

Initial assessment with the risk and obligation map.
Twelve-month security roadmap, prioritised and costed.
Recurring commitment, with a named, fixed point of contact.
Periodic dashboard for management.
Responses to client questionnaires and third-party audits.
Incident support as technical interface and alongside management.
Who does the work. The same team that audits, not an account manager. Governance, risk and compliance: CISSP, CISM, ISO 27001 Lead Auditor, ENS and Risk Analysis (CCN), certified DPO, CCSP and CDPP (ISMS Forum) and PMP (PMI). On the technical side: OSCP, CRTO II and eWPTX, ranked in the top 1% of the CCN-CERT Atenea platform. We have run compliance projects for crypto exchanges, universities and public administrations.

Questions we get asked

How much time is needed?
It depends on size and regulatory pressure. Typically between two and four days a month in steady state, with more intensity in the first months or during a certification. It is set by the initial assessment.
Does it replace our IT team?
No, it complements them. IT builds and operates; the CISO decides which risks are accepted and which are not, and is accountable for that decision. They are distinct functions, and separating them is exactly what any governance framework asks for.
Does it help with NIS2?
Considerably. NIS2 makes the management body accountable, and having an identifiable security function with a plan and minutes is how you evidence diligence. What cannot be delegated is the accountability itself: that stays with the board.
Is there a minimum term?
The sensible minimum is six months, because less than that does not even cover finishing the assessment and starting the roadmap. After that, the arrangement is reviewed whenever you want.
Put a name to your security function
Half an hour to work out what commitment you need and what the first quarter should cover.

Book 30 min with an auditor

Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET)  ·  Email: info@jaymonsecurity.com
We reply within 2 working hours.
ENES