CISO as a Service from Razorthorn Security

Not every organisation needs a full time CISO, but every organisation needs someone making sure security is being managed properly. Razorthorn’s CISO as a Service gives you experienced security leadership on a flexible or retained basis, tailored to your size, stage and complexity.

You can engage us for a one off security review, an ongoing advisory relationship or a structured monthly retainer with defined inclusions. However you work with us, you get a named consultant who knows your business, backed by a full cybersecurity consultancy that can deliver testing, compliance and managed services when your roadmap calls for them.

The difference between Razorthorn and a standalone virtual CISO or a generalist IT consultancy is what sits behind the service. When your consultant identifies that you need a penetration test, a compliance assessment, a phishing simulation or a vulnerability scanning programme, those services are already available in-house. You do not need to find a separate supplier, brief them from scratch or manage another relationship.

That means your security roadmap is not just a document full of recommendations. It is a plan your consultant can actually help you deliver, with a team of specialists behind them covering penetration testing, compliance consulting, managed phishing, managed vulnerability scanning, CTEM and incident response testing.

Book a Free Consultation

Please leave a few contact details and one of our team will get back to you.

What is CISO as a Service?

CISO as a Service (also called CISOaaS, virtual CISO or fractional CISO) is an outsourced security leadership model. Instead of hiring a full time Chief Information Security Officer, you bring in an experienced security professional to provide the strategic guidance, risk management and governance oversight your organisation needs.

This is not a monitoring service or a helpdesk. Your consultant operates at a strategic level: setting security priorities, managing risk, overseeing compliance, reporting to your board or management team and making sure security investment is going where it will have the most impact.

Razorthorn has been providing cybersecurity consultancy since 2007. Our CISOaaS consultants draw on experience across hundreds of security programmes rather than the perspective of a single hire and they have direct access to our testing, compliance and managed services teams when your security roadmap needs more than advice.

When does your organisation need a CISO as a Service?

Most organisations reach a point where security can no longer be managed as a side responsibility. Common triggers include clients or procurement teams asking about your security posture, a compliance requirement like ISO 27001 or Cyber Essentials that needs someone to own it, board members asking questions about cyber risk that nobody can confidently answer, or simply growing to a size where the lack of a security leader is becoming a visible gap.

A full time CISO is the right answer for some organisations, but for many the cost is hard to justify. The average UK CISO salary is over £130,000 (according to Glassdoor) before benefits, and that is before you factor in the tooling, training and team they will need to be effective. CISO as a Service gives you the leadership without the overhead.

How does Razorthorn’s CISO as a Service work?

1. Scoping

Razorthorn’s CISOaaS offers flexibility. It is designed to align seamlessly with the specific needs and budget of your organisation. Whether you require our expertise for a short term project or a long term partnership, the choice is yours. You can leverage our experience as per your requirements.

2. Baseline Assessment

Our service entails a thorough and meticulously documented assessment of your existing information security practices. This evaluation is conducted against Razorthorn’s tailored and bespoke security framework. It ensures a comprehensive analysis of your organisation’s current security baseline.

3. Ongoing Advisory and Governance

We provide a comprehensive list of relevant information security controls. These are specifically customised to suit the unique needs and context of your organisation. This approach ensures that the identified controls effectively reduce your risk profile to an acceptable level. It mitigates potential threats and vulnerabilities that your organisation may face.

4. Review and Refresh

Our service includes the development of a robust remediation plan which is based on the output of the risk assessment. The plan is specifically designed to bridge the gap between your organisation’s current security posture and the desired levels of security. It provides a clear roadmap for improvement.

How much does CISO as a Service cost?

Small Business

Small Business

Security Leadership Without the Overhead

Best for: 10 to 100 staff with no dedicated security leader

£2,495 per month (under 50 staff)

£3,495 per month (51 to 100 staff)

What’s included:

Monthly security leadership meeting (onsite or remote).

Annual cyber risk assessment. Security roadmap and priority plan.

Policy and procedure governance review.

Third party and supplier security guidance.

Basic incident response advice.

Defence in Depth review.

Cyber Essentials, ISO 27001 and PCI DSS consulting.

Quarterly management security summary.

Medium Business

Medium Business

Ongoing Security Oversight and Governance

Best for: 100 to 750 staff with growing compliance or client pressure

£4,495 per month (101 to 375 staff)

£8,495 per month (376 to 750 staff)

What’s included:

Everything in Small Business, plus:

Fortnightly CISO advisory sessions (hybrid onsite and remote).

Quarterly board level security report.

Security strategy and budget planning.

Security and resilience risk register ownership and review.

Incident response planning and tabletop exercise.

Third party risk management support.

Annual penetration testing programme oversight.

Defence in Depth review and strategy.

Large Business

Large Business

Board Level Cyber Risk Leadership

Best for: 750+ staff, regulated businesses or complex estates

Contact us for pricing.

What’s included:

Everything in Medium Business, plus:

Weekly CISO leadership sessions (hybrid onsite and remote).

Board and executive cyber risk briefings.

Security operating model design.

Security governance committee participation.

Cyber risk quantification and business impact reporting.

M&A, supplier and regulatory security advisory.

Crisis and breach response leadership support.

CTEM and continuous assurance programme oversight.

Frequently asked questions about CISO as a Service

What is CISO as a Service?

CISO as a Service (CISOaaS) is an outsourced security leadership model where an experienced security professional provides strategic guidance, risk management and governance oversight on a retained or flexible basis. It gives organisations access to senior security leadership without the cost of a full time hire. It is also known as virtual CISO, fractional CISO or outsourced CISO.

How much does CISO as a Service cost?

Razorthorn offers three retainer packages starting from £2,495 per month for organisations with under 50 staff. The Medium Business package starts at £4,495 per month and the Large Business package is priced on application. Bespoke arrangements outside the retainer model are also available. Contact us for a free consultation.

What is the difference between CISO as a Service and a virtual CISO?

They are the same thing. CISO as a Service, virtual CISO (vCISO), fractional CISO and outsourced CISO all describe a model where an external security professional provides CISO level guidance on a part time or retained basis. The terminology varies by provider but the service is the same.

How is CISO as a Service different from a managed security service?

Managed security services like SIEM monitoring, vulnerability scanning and phishing protection are operational. They monitor and protect your environment day to day. CISO as a Service is strategic. Your consultant sets the security direction, manages risk at a business level, reports to the board and makes sure the right operational services are in place. The two are complementary but serve different purposes.

Do I get the same consultant each time?

Yes. Every engagement is delivered by a named consultant who builds knowledge of your organisation over time. This is not a shared helpdesk or a rotating team. Your consultant learns your environment, your risks and your people, which means they get more effective the longer the engagement runs.

Can I start with a one-off engagement and move to a retainer later?

Yes. Many organisations start with a one-off security review or a short advisory engagement and then move to a structured retainer as their needs develop. You are not locked into a package from day one.

Can I change package as my organisation grows?

Yes. Packages can be adjusted at any point. Many organisations start with the Small Business package and move to Medium or Large Business as their security maturity develops, their headcount grows or their compliance requirements increase.

Does CISO as a Service help with ISO 27001 or Cyber Essentials?

Yes. All three retainer packages include compliance consulting for Cyber Essentials, ISO 27001 and PCI DSS. Your consultant can guide you through certification, manage gap analysis, oversee remediation and prepare you for audit. If you need dedicated compliance project work beyond the retainer scope, that is available as a separate engagement.

What size organisation is CISO as a Service right for?

The retainer packages cover organisations from 10 to 750+ staff. The Small Business package suits organisations with no dedicated security role. The Medium Business package is for organisations facing growing compliance or client pressure. The Large Business package is for regulated businesses, complex estates or organisations that need board level cyber risk leadership. Bespoke engagements can be scoped for any size of organisation.

Can the consultant attend board meetings?

Yes. The Medium Business package includes quarterly board level security reports. The Large Business package includes board and executive cyber risk briefings, governance committee participation and weekly leadership sessions. Your consultant can present to the board, contribute to risk committees and brief executive teams on cyber risk in business terms.

Looking for related services?

CISOaaS works alongside several of our other services to build a complete security programme:

ISO 27001
Penetration Testing
PCI DSS Consultancy
Cybersecurity Review

Follow Us