What prompted your enquiry
Most organizations do not start looking for security leadership in the abstract. Something arrived: a customer assessment, a questionnaire attached to a deal, a question from an auditor that nobody could answer cleanly.
Starting points
If one of these is why you are here
- You have received a third-party cybersecurity assessment A customer has sent an assessment of your security, and it has a deadline. What the document is, what your answers commit you to, and what to establish before you reply.
- Somebody asked who owns security, and there was no answer An auditor, a board member or an insurer asked for the name of the person accountable for security. What the question is really testing, and what to put in place before it is asked again.
- Your cyber insurance renewal asks for controls you cannot evidence The renewal application asks whether specific controls are in place everywhere, and the honest answer is not a clean yes. What the questions are for, and what to do before the form goes back.
Something else
If none of these is it
These are the situations described in detail here. They are not the only reasons organizations get in touch, and the underlying question is usually the same one whichever event prompted it: who is accountable for security, and could the organization evidence its position if asked.
The situations that most often prompt an engagement are set out on the vCISO page, and the work each one calls for is described across the services portfolio.