Services

    Enterprise Security Leadership. Without the Enterprise Price Tag.

    An experienced full-time CISO costs $200,000-$400,000 per year. IPV Security's CISOaaS gives you equivalent executive leadership - plus a team, methodology, and the CISOteria platform - at a fraction of the cost.

    Five Pillars. One Integrated Program.

    Everything you should expect from a CISOaaS engagement

    1

    GOVERN - Your named CISO owns the program - board visibility, a documented annual plan, and monthly reporting built in from day one.

    2

    ASSESS - A live risk register you can show your board - not a snapshot that ages for 12 months.

    3

    PROTECT - Identified gaps get closed - MFA, email security, endpoint hardening and phishing resilience tracked to completion in CISOteria.

    4

    COMPLY - Always audit-ready - continuous evidence collection against your applicable frameworks so there's no scramble before an audit.

    5

    RESPOND - A tested Incident Response Plan, scenario playbooks, and annual tabletop exercises - so the first time you practice isn't during a real incident.

    6

    CISOteria - Every pillar is tracked on one live platform - your board, CFO, and IT team each see the view they need, always current.

    Senior Security Leadership at 40% of the Cost.

    A full-time CISO costs $200,000-$400,000 per year including recruitment, salary and benefits. CISOaaS Advanced delivers full senior leadership for $90,000-$144,000 per year - with platform, full team and compliance included.

    Full-Time CISO (US market average)

    $200,000–$400,000

    Salary + benefits + equity + recruiting cost. 6+ months to hire.

    IPV Security CISOaaS Advanced

    $90,000-$180,000

    Dedicated CISO + team + platform + methodology. Active in 2 weeks.

    Includes at no extra cost

    • CISOteria platform license
    • Team of 10+ expert advisors
    • Proven methodology (21+ years)
    • 100-200 service points for additional projects
    THE FIRST 90 DAYS

    A Structured Program from Day One

    By Month 3 you have a board-approved security plan, a live platform, a tested incident response plan, and a documented risk posture.

    Week 1

    Kickoff

    Named CISO assigned. CISOteria provisioned. Scope confirmed, stakeholder map completed.

    Weeks 2-3

    Discovery

    Stakeholder interviews. Asset inventory. Regulatory obligations mapped. First executive steering meeting.

    Month 2

    Risk Assessment

    Annual Risk Survey (18 domains). Controls gap analysis. Annual Security Plan drafted.

    Month 3

    Program Launch

    Annual Security Plan approved by your board. CISOteria fully loaded. IRP v1.0 issued. First executive report distributed.

    ONE PLATFORM. EVERY STAKEHOLDER.

    CISOteria - The Platform Everyone Sees

    Every pillar feeds into one live platform. No more asking "where are we on X?" - the answer is always there.

    Always-On Visibility

    Your security posture isn't in a PDF filed away - it's live, current, and accessible to every stakeholder who needs it.

    Findings to Closure

    Every vulnerability tracked from discovery to remediation - with an owner and a due date, so nothing falls through the cracks.

    Audit-Ready Evidence

    Compliance evidence collected continuously - so when an auditor, insurer, or enterprise customer asks, the answer is already there.

    A Complete Security Program in One Retainer

    What's Included

    Dedicated CISO

    A senior IPV Security advisor leads your security program with full accountability.

    Structured Annual Plan

    Risk-based security roadmap built for your specific environment and regulatory exposure.

    Continuous Execution

    We don't just advise - we drive implementation of security improvements month after month.

    Compliance Management

    Ongoing alignment with relevant frameworks with audit-ready evidence through CISOteria.

    Points-Based Flexibility

    Annual points budget redeemable for additional services: PTs, ISO projects, training, IR exercises.

    What You Receive

    Documented outputs included in every CISOaaS engagement

    Annual security programme document

    Documented annual security program covering objectives, milestones and ownership.

    Monthly security status reports

    Monthly reports on security posture, risks and remediation progress.

    Quarterly board packs

    Quarterly board pack covering risk, compliance and program progress.

    Continuously maintained risk register

    Risk register kept current with treatment plans, ownership and status.

    Up-to-date policy library

    Policy library mapped to controls and regulatory frameworks.

    Documented incident response plan

    IR plan with playbooks, escalation paths and contact tree.

    Annual penetration test coordination

    Annual pentest scoping, vendor coordination and remediation oversight.

    Compliance evidence package

    Evidence package collected and curated for audits and certifications.

    NOT A FREELANCER. A FULL TEAM.

    One CISO. A Full Team Behind Them.

    Every client gets the same structured program, the same platform, the same team - regardless of who their CISO is. When your CISO is unavailable, a named backup steps in within 4 hours.

    Lead vCISO

    Your named advisor. Owns the program, all executive meetings, and the Annual Security Plan. 15+ years experience.

    Associate vCISO

    Keeps CISOteria current. Tracks open actions, drafts monthly reports, coordinates annual activities between meetings.

    GRC Analyst

    Compliance engine. Maintains the compliance calendar, collects evidence continuously, prepares audit packages.

    Audit & PT Team

    Conducts the Annual Risk Survey, penetration tests, phishing simulations, and tabletop exercises. All findings in CISOteria.

    Practice Head

    Reviews every Annual Security Plan and Year-End Report. Responds to any escalation within 1 business day.

    Backup Coverage

    Named backup CISO on standby. If your CISO is unavailable, coverage continues - documented in the agreement.

    Program continues when your CISO is on holiday
    Knowledge lives in CISOteria - a CISO change is a handover, not a restart
    Every client gets the same annual deliverables, regardless of who their CISO is

    Choose the Right Level of Engagement

    Service Tiers

    // Essential

    Organizations of 50-200 employees with basic regulatory exposure

    • Dedicated CISO leadership
    • Monthly security steering meetings (4/month)
    • Quarterly risk and vulnerability scans
    • Structured annual security plan
    • Access to the CISOteria platform
    • 100 annual service points
    • Compliance monitoring (single framework)
    • Customer security questionnaire support

    What you get

    Security stops being 'someone's side task.' You can credibly answer yes when an insurer, enterprise customer, or regulator asks whether your security is professionally managed - with a named expert accountable and reachable same day in an incident.

    Scope boundary

    Not right if you are under active regulatory audit, in M&A, or need more than monthly CISO availability. Those scenarios require the Advanced tier.

    $3,750-$7,500
    per month
    Most Popular
    // Advanced

    Organizations of 200-1,000 employees with ISO/compliance requirements

    • Everything in Essential, plus:
    • Bi-weekly CISO meetings (8/month)
    • Monthly security scans
    • 200 annual service points
    • Multi-framework compliance monitoring
    • Board reporting package (quarterly)
    • Incident response readiness
    • Vendor / third-party risk oversight

    What you get

    Pass cyber-insurance renewals and customer due diligence without a crisis. Your board receives monthly evidence that security is actively managed. A structured risk register is maintained so findings do not accumulate unaddressed.

    Scope boundary

    Not a substitute for a daily embedded CISO presence or government-clearance requirements. M&A advisory is available as an add-on project.

    $6,900-$14,000
    per month
    // Enterprise

    Organizations of 1,000+ employees with a complex regulatory landscape

    • Everything in Advanced, plus:
    • Weekly executive meetings (12/month)
    • Continuous security monitoring
    • 300+ annual service points
    • Full CISOteria suite
    • Custom board reporting
    • Red Team exercise (annual)
    • Dedicated security team on standby

    What you get

    Senior CISO and security analyst capability at 30 to 40 percent of hiring cost. Security decisions happen in real time with weekly involvement. Your board has a live posture dashboard - no waiting for quarterly reports.

    Scope boundary

    Does not cover classified environments requiring government security clearance, or situations requiring 24/7 on-site physical presence.

    $15,000-$25,000
    per month

    All tiers include CISOteria platform access. Points system allows flexible use of additional services (PT, ISO projects, awareness training, IR exercises).

    Pricing is indicative and depends on organization size and engagement scope. Final pricing is confirmed after a complimentary scoping call.

    Built-In Flexibility - Redeem Points Across All Services.

    CISOaaS retainer clients earn service points that can be redeemed for any IPV Security service. Penetration testing, compliance work, IR exercises, awareness programs - all available through the points system. No separate purchases needed.

    ServicePoints Cost
    Penetration testing sessions50 points
    Compliance gap assessments45 points
    Tabletop exercises35 points
    Awareness training sessions10 points
    Cloud security reviews40 points
    AI architecture reviews60 points

    From Risk Discovery to Program Maturity

    First-Year Journey

    1

    Understand the Risk

    Months 1-2: Assessment, asset inventory, gap analysis, and structured annual security plan.

    2

    Close the Gaps

    Months 3-6: Remediation execution, policy development, compliance program implementation.

    3

    Test and Validate

    Months 7-9: Penetration tests, compliance audit readiness, tabletop exercises.

    4

    Sustain and Improve

    Months 10-12+: Continuous monitoring, quarterly reviews, maturity advancement.

    // Scope Clarity

    What CISOaaS Does Not Include

    Being explicit about scope means no surprises mid-engagement and no expectation gaps with your team or your board.

    SOC / 24×7 alert monitoring

    CISOaaS is advisory leadership, not a security operations centre. Organisations needing continuous alerting require an MSSP alongside this engagement.

    Technology deployment

    We advise on tool selection and configuration standards but do not install, configure, or manage security tools such as firewalls, EDR, or SIEM platforms.

    Legal counsel

    Security recommendations do not constitute legal advice. Data breach liability and regulatory proceedings require separate legal representation.

    Full-time employee coverage

    This is fractional leadership. Response times follow tier SLAs, not employment obligations. If you need someone in the building daily, talk to us about the Enterprise tier.

    Ready to Build a Security Program?

    Schedule a consultation and we'll design a CISOaaS proposal tailored to your specific risk profile and regulatory obligations.