Virtual CISO Monthly Report
AI-powered virtual CISO. Monthly threat briefing, board risk report and strategic roadmap. £120K CISO at 3% cost.
🛡️ CYBER ESSENTIALS 2026 UPDATE — EFFECTIVE 28 APRIL 2026
The Cyber Essentials scheme is updated from 28 April 2026 with stricter criteria: mandatory multi-factor authentication (MFA) for all cloud services and admin accounts, tighter password policies, expanded scope for home workers and BYOD devices, and new vulnerability management timelines. All UK government suppliers must meet the updated standard. This product is aligned with the CE 2026 requirements.
🛡️ UK CISO SHORTAGE: 18,000 UNFILLED ROLES — SMEs LEFT EXPOSED
A full-time CISO costs £90,000–£175,000/year in salary alone — before national insurance, benefits, and recruitment fees. Yet NIS2 Article 20 requires board-level security governance documentation. The UK CS&R Bill (2026) expects regulated entities to demonstrate strategic security leadership. Fewer than 15% of UK SMEs have any dedicated security leadership role.
The Equivalent of a £120K CISO — for £299/month
Strategic security leadership is no longer optional for regulated businesses. Cyber insurers, procurement frameworks, and regulators all expect evidence of ongoing security governance — not just a policy document from two years ago. Our virtual CISO service delivers monthly strategic output: threat intelligence, board reporting, policy reviews, incident response, and regulatory alignment — powered by AI with human expert escalation for complex scenarios.
- Monthly Threat Briefing: Sector-specific threat intelligence — what attack campaigns are targeting your industry this month, with defensive actions prioritised
- Board Risk Report: One-page non-technical risk summary for directors — traffic light status, trend indicators, and actions required, in plain English
- Security Policy Review: Annual review of all security policies with gap analysis and update recommendations — kept aligned as regulations evolve
- Incident Response Plan: Quarterly review and tabletop exercise — tested against current threat scenarios for your sector
- 12-Month Strategic Roadmap: Prioritised security investments sequenced by risk reduction per pound — aligned to your actual budget
- Third-Party Vendor Review: One supplier security assessment per month — essential for NIS2 Article 21(d) and CS&R Bill supply chain obligations
- On-Demand Consultation: 2 hours/month via Telegram or video — for urgent board questions, incident decisions, or insurer enquiries
- Regulatory Alignment Dashboard: NIS2, UK CS&R Bill, Cyber Essentials, ISO 27001 — your posture mapped monthly across all relevant frameworks
💷 THE MATHS
£299/month = £3,588/year. In-house CISO: £90,000–175,000/year + NI + benefits. Interim CISO day rate: £800–2,000. Fractional CISO retainer: £2,000–5,000/month. Our vCISO delivers comparable strategic output at 3–5% of in-house cost. Cyber insurers increasingly reduce premiums for documented CISO-equivalent governance.
📋 ISO 27001:2022 TRANSITION
ISO 27001:2013 certifications expired 31 October 2025. All organisations must now operate under ISO 27001:2022, which adds 11 new controls including threat intelligence, cloud security, data masking, and secure development. This product's controls are mapped to the 2022 standard.
📅 How this subscription works — month-1 to month-12
- Day 1 onboarding: instant portal access, automated onboarding checklist and baseline assessment intake — getting started guide delivered automatically.
- First week setup: integrations wired, first report generated, MLRO / DPO / IT lead invited to the portal.
- Ongoing monthly delivery: updated compliance report, new-regulation tracker delta, audit-trail snapshot, continuous regulatory updates aligned to your sector.
- Cancellation: cancel any time from the portal — no contract lock-in; 30-day data export window after cancellation.
⚠️ Legal disclaimer (COMPLIANCE): This product is provided for information and compliance documentation only; it is not regulatory advice. Read the full disclaimer below or in our Terms of Service before purchase.
NIS2 Article 23 Reporting Readiness — vCISO Oversight
The Virtual CISO Monthly Report includes ongoing oversight of the organisation's NIS2 Article 23 incident reporting readiness as a standard board-reporting dimension:
- 24-hour early warning capability check — monthly review of whether the security team can produce the early warning notification within the 24-hour window with current staffing, templates, and contact lists
- 72-hour formal notification capability check — monthly review of formal report readiness: template freshness, evidence-gathering capacity, classification taxonomy alignment
- One-month follow-up report capability — review of the one-month follow-up report capability per Article 23(4)
- Tabletop exercise tracking — vCISO ensures at least one Article 23 reporting tabletop exercise per year, with documented findings and remediation
- National CSIRT contact maintenance — quarterly verification that national CSIRT contacts and reporting portal access remain valid
The monthly report includes a NIS2 Article 23 readiness traffic-light: green (ready), amber (gaps identified and remediation in progress), red (significant gap requiring board awareness).
Cyber Essentials 2026 Oversight (Monthly)
The vCISO monthly report includes ongoing CE 2026 control oversight as a standard board-reporting dimension:
- Firewalls — Monthly review of network boundary configuration, perimeter rule drift, and inbound/outbound policy effectiveness
- Secure configuration — Monthly check on CIS-benchmark hardening drift, configuration baseline freshness
- User access control + MFA mandate — Monthly MFA enforcement audit (CE 2026 mandate 28 April 2026); admin sprawl detection; least-privilege RBAC review; quarterly access review verification
- Malware protection — Monthly EDR/endpoint security coverage report (uncovered devices flagged); antivirus signature freshness
- Security update management — Monthly patch management cadence audit (vulnerability management SLA tracking; outstanding high-severity patches flagged for board review)
£299.00/mo
MONTHLY SUBSCRIPTION · No VAT (not registered)
Trust & Delivery
ICO registered ZC112810
UK Information Commissioner's Office data controller registration.
Companies House 16419201
SummitBridge Horizon Ltd — registered 30 April 2025, London.
14-day satisfaction guarantee
See refund policy for full terms.
Sample materials available
Compare with the market
4 direct and adjacent competitors tracked.
| Vendor | Their price | Threat | vs SBH | Their advantages | Our advantages |
|---|---|---|---|---|---|
| Cyberfort GB | £5K+ /mo (enterprise) | HIGH | pricier | Enterprise SOC · Large UK footprint | SMB-priced · Founder-led · Monthly contract |
| IT Governance UK GB | £800+ per assessment | MEDIUM | pricier | — | — |
| Drata US | $7,500+ /yr | LOW | pricier | — | — |
| Vanta US | $7,500+ /yr | LOW | pricier | — | — |
Compliance Snapshot
Regulatory posture for this product — for procurement and security teams.
Conformity scaffold in place — formal record not yet published