Skip to main content
Service / vCISO

Senior security leadership, on retainer.

Fractional CISO engagements for founders, boards, and growth-stage teams. Our vCISO practice puts a senior security executive in the room before you need one on the payroll — running your program, owning the audit, and translating risk for the people who need to hear it.

Practice
Lorikeet Security vCISO
Engagement
Retainer, fractional hours
Frameworks
SOC 2, ISO 27001, PCI DSS
Starts in
2 weeks or less
01 The practice

Senior judgment, on the calendar you actually need it.

Lorikeet Security's vCISO practice pairs every engagement with senior security leadership — people who have run programs, sat across the table from auditors, and answered the hard questions on customer calls. We do not ship a junior analyst with a CISO title. You get the room, the roadmap, and a named executive.

P/01

Senior practitioners, not generalists

Our vCISO leads have run real security programs at companies that had to ship, audit, and grow at the same time. Strategy from people who have lived it — not template recyclers.

P/02

Direct access, no layers

You talk to the person running your program. No account manager firewall, no offshore handoff. A standing weekly slot and a phone line your team can use.

P/03

Backed by the full Lorikeet Security bench

Your vCISO sits on top of our pentest, ASM, GRC, and incident response teams. Findings flow straight into your roadmap — one vendor, one timeline, one accountable owner.

P/04

Executive presence when it matters

Customer due diligence, board meetings, acquirer questionnaires, regulator calls. A named executive who can answer security questions without checking the script.

02 Who this is for

Companies that need CISO-grade judgment without the CISO-grade headcount.

Founders & operators

Your first security hire

You are closing enterprise deals that keep asking for a SOC 2 report, a security questionnaire, and a named executive in the room. You need a real answer, not a template.

Boards & PE

Portfolio oversight

You need a trusted security executive who can sit across multiple companies, run the program, and translate risk into numbers your LPs understand.

Engineering leaders

Cover for the gap

Your CISO left, your VP Eng is covering security on top of a day job, or you need interim leadership while you run a proper executive search.

03 What you get

A security program, owned end to end.

i/01

Security strategy & roadmap

A baseline assessment, a prioritized 12-month roadmap, and quarterly reviews tied to your business objectives.

i/02

Compliance program leadership

SOC 2 Type I and II, ISO 27001, PCI DSS, HIPAA. Auditor liaison, evidence ownership, and clean audit outcomes.

i/03

Board & investor reporting

Board decks, security questionnaire support, and the hard conversations with investors and enterprise procurement teams.

i/04

Policy & procedure

A full policy set, built to your context and not copy-pasted from a template. Reviewed annually, updated on exception.

i/05

Third-party & vendor risk

Vendor inventory, tiering, and an approval workflow that does not grind procurement to a halt.

i/06

Incident response leadership

An IR plan your team will actually follow, tabletop exercises, and executive-level coordination when something real happens.

i/07

Security team coaching

Mentorship for your first security hires. We raise their ceiling instead of replacing them.

i/08

Offensive testing oversight

Direct pipeline into Lorikeet Security's pentest and ASM practices. Findings route straight into your roadmap.

i/09

On-demand executive presence

Customer calls, sales cycles, due diligence, acquisition paths. A named executive answering the security questions.

04 Engagement tiers

Three ways to bring us in.

Advisor
Strategic oversight, light touch.
~16 to 24 hours / month
  • Monthly strategy session
  • Quarterly board-ready reporting
  • Security questionnaire support
  • Slack / email access, business hours
  • Roadmap review & prioritization
Discuss scope
Interim
Dedicated cover, fixed term.
Full-time embedded · 3 to 6 months
  • Acting CISO, named on the org chart
  • Daily presence with engineering & legal
  • Runs the audit end to end
  • Hires your permanent CISO
  • Clean handoff documentation
Discuss scope
05 How it unfolds

From kickoff to owning your program, in weeks not quarters.

01 / Discovery

Scope & fit call

A 45 minute working session. We leave with a shared picture of where you are, what is on fire, and what the next 90 days look like.

Week 0
02 / Baseline

Security posture review

Controls review, architecture walkthrough, policy audit, and a prioritized gap analysis. You get the document. Your auditor does not.

Weeks 1 to 3
03 / Roadmap

Program design

A 12 month security roadmap, scoped to your compliance obligations, customer contracts, and engineering capacity.

Weeks 3 to 4
04 / Operate

Run the program

Weekly execution, monthly reporting, quarterly board updates. The roadmap becomes the calendar.

Week 5 onward
Start here

Put a real security executive in the room. This week.

Tell us what is in front of you. Audit in 60 days. Enterprise deal stuck on a questionnaire. Board asking hard questions. We will tell you honestly whether a vCISO is the right shape of help — and if it is, we will put a senior practitioner on the call.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!