vCISO & Advisory Services
A full-time CISO costs £150,000 or more per year. Most mid-market organisations need the strategic capability but not the overhead of a full-time hire.
Who this is for: Organisations that need board-level security leadership but cannot justify, or do not yet need, a full-time hire.
The problem: Security decisions pile up with no named, accountable executive to own them.
The outcome: Fractional CISO leadership with real accountability, scoped to the engagement model and days your organisation needs.
The problem
Security decisions pile up in organisations that do not have a dedicated security executive. IT teams make strategic calls they are not equipped for. Boards approve security budgets without understanding the risk. Regulators ask questions that nobody can answer with authority. Incidents happen and no one is accountable for the response.
Hiring a full-time CISO is one solution. But the search takes six to twelve months, the salary is substantial, and many organisations do not need full-time security leadership. They need it at the right moments. A board meeting. A regulatory audit. An incident. A procurement decision that carries real security risk.
The same gap exists across UK and Nigerian markets but looks different in each. In Nigeria it often means no one owns CBN cybersecurity compliance or NDPA 2023 accountability. In the UK it often means a board that has approved a security budget but cannot articulate what it is buying.
The cost comparison is often misunderstood. A full-time CISO hire in the UK typically costs upward of £150,000 a year once salary, benefits, and recruitment cost are included, and Nigerian market rates for equivalent seniority carry their own sizeable overhead. Many organisations assume a vCISO is simply a cheaper version of the same role, when the real difference is that you pay for engaged days rather than a permanent headcount you may not need every week.
Without named accountability, incident response defaults to whoever is available at the time rather than someone with the authority and experience to make fast, defensible decisions. That gap is invisible until the moment it matters most.
What we do
FortressPoint provides vCISO engagements for enterprises across UK and Nigerian markets. Each engagement is structured around a fixed number of days per month. We attend your security committee meetings, brief your board, manage regulatory relationships, and provide strategic direction to your internal team or managed security providers.
We own the outcome rather than only the advice. When an incident happens we lead the response. When a regulator asks a question we answer it. When the board needs a clear picture of the organisation’s security risk we provide one.
Engagements scale with activity. During audits, incidents, or M&A, we increase capacity. During quieter periods we reduce it. You pay for what you need.
Engagement models vary by organisation. Some clients want a fixed monthly retainer with a set number of days. Others prefer a day-rate arrangement tied to specific projects such as an audit cycle or a certification push. We agree the model at the start based on how your security workload actually moves through the year, not a one-size-fits-all package.
We are explicit about what a vCISO is not. It is strategic leadership and accountability, not a replacement for your technical operations team. Where technical implementation is needed, we either direct your internal team or coordinate with the specialist FortressPoint practices that deliver it, such as Cloud, Azure & Identity Security or Vulnerability & Exposure Management.
Who this is for
What you get
Why FortressPoint
We are practitioners, not advisors. The difference is accountability. When you engage FortressPoint as your vCISO, we own the security programme, not only the recommendation. We show up when it matters, not only at the monthly meeting.
We understand the regulatory environment in both Nigeria and the UK in detail. If your organisation operates across both markets, one vCISO engagement covers both. You are not explaining your Nigerian operations to a UK-only advisor or your UK obligations to someone who only knows CBN frameworks.
Our engagements are designed to end. We build the programme, embed the governance, and either hand it to your team or support a permanent hire when the time comes. Indefinite dependency on external security leadership is not a sustainable outcome.
We are transparent about cost from the first conversation. You will understand what drives your specific quote, retainer size, day-rate, or project scope, rather than receiving a number with no explanation behind it.
Common questions
vCISO pricing usually runs as either a monthly retainer for a fixed number of days, a day-rate for specific engagements, or a project-based fee for a defined piece of work such as audit preparation. It is set against your organisation’s size, risk profile, and how many days of senior leadership you actually need each month, and it is typically a fraction of the total cost of a full-time CISO hire once salary, benefits, and recruitment are included.
Nigerian vCISO engagements follow the same retainer, day-rate, or project-based models as the UK, scaled to local market conditions. The main cost drivers are the same: organisational size, regulatory scope such as CBN or NDPA 2023 obligations, and how many engagement days per month the role actually requires.
They are the same thing. Virtual CISO and vCISO both describe a fractional, part-time Chief Information Security Officer engagement, as opposed to a full-time, permanently employed CISO.
This varies by organisation, from a few days a month for a smaller business needing board reporting and light oversight, to significantly more for organisations mid-audit, mid-incident, or going through M&A. Engagements are usually scoped against your specific security committee cadence, regulatory calendar, and current risk profile rather than a fixed default.
No. A vCISO provides strategic leadership, governance, and accountability. Your IT team or managed service provider still carries out technical implementation. The vCISO directs that work and takes ownership of the overall security programme, but does not replace day-to-day technical operations.
A consultant is typically engaged for a specific project with a defined start and end. A vCISO holds an ongoing leadership role, attending governance meetings, owning board reporting, and taking accountability for the security programme over time, closer to an executive function than a single piece of advisory work.
If your organisation needs security leadership without a full-time hire, contact us.