Cyber security · Virtual CISO

Virtual CISO services that include running your security

A named security lead, board reporting and a compliance programme, plus day-to-day management of your Microsoft 365 or Google Workspace security. The same team gives the advice and does the work.

From A$7,000 a monthFor a 5 to 10 person organisation, including management of your Microsoft 365 or Google Workspace security. Scales with users and scope. Fixed monthly fee in writing after a 30-minute call. Prices exclude GST.
Book a 30-minute call With Ben Jones, our cyber security practice lead. He will send a short agenda beforehand.

What the retainer includes

  • Security strategy and roadmapOwned by a named lead and reviewed quarterly
  • Risk register and policy setWritten for your business, kept current, signed off by you
  • Monthly report and quarterly board paperProgress against the roadmap, open risks and the cost to close them
  • Compliance programmeEssential Eight, ISO 27001, APRA CPS 234 or SOCI, whichever you are held to
  • Incident response plan and reportingA tested plan, the regulator contacts and someone on call to run it
  • Your environment, run securelyIdentity and MFA, conditional access, email security, device management, backups, logging and patching
  • CISO-led practicePractitioners hold CISM and OSCP
  • Advice that gets implementedWe run the controls we recommend, to a written scope
  • You keep ownershipThe tenant, the licences and the data stay yours, and you sign off every accepted risk
  • Microsoft 365 and Google WorkspaceMixed environments included

Why this shape

Advice without control rarely gets done

The problem

Findings nobody owns

A vCISO who hands over a strategy document and comes back next quarter leaves the work with an IT team that is already busy. One industry dataset found that fewer than half of penetration test findings are ever resolved. The advice was fine; nobody had time to act on it.

Our answer

One team, two jobs

Your vCISO sets the priorities and reports to the board. The same team runs the identity, email, device, backup and logging controls that those priorities depend on, and keeps the evidence. If something has not been done, you call us, and we are the ones who were supposed to do it.

The fair objection is that we are marking our own homework. So the operations scope is written and fixed, you own the tenant and the licences, every accepted risk is signed by you, and you can commission an independent assessment of our work whenever you like. If you already have a strong internal team or provider, we will say so and quote advisory only.

When organisations engage a vCISO

What is being asked of you, in the regulators' own words

APRA CPS 234

Regulated entities

"The Board of an APRA-regulated entity is ultimately responsible for the information security of the entity." Roles and responsibilities must be clearly defined; material incidents reported within 72 hours. The retainer gives the Board a named owner and the evidence trail.

Cyber Security Act 2024

Any business over A$3m turnover

Ransomware and cyber extortion payments must be reported to the Australian Signals Directorate within 72 hours. The education-first period ended on 31 December 2025. The retainer includes the reporting procedure and the people to run it.

Customers and insurers

Questionnaires and renewals

Enterprise and government buyers ask who your CISO is and for your Essential Eight or ISO 27001 position. Insurers ask for MFA everywhere, endpoint detection and tested backups. A named lead with evidence answers both.

Also on the list: SOCI responsible entities whose annual risk management report must be approved by the board, organisations working toward ISO 27001 who need an owner for the management system, and boards that want one number after a near miss. The Privacy Act now includes a statutory tort for serious invasions of privacy, and reasonable steps to protect personal information expressly include technical and organisational measures.

How it runs

First 90 days, then a steady rhythm

Assess

Where you stand against the framework you are held to, what the environment looks like in practice, and the risks that matter in the first month.

Fix the foundations

MFA and conditional access, email security, device management, backups and logging brought to a defensible state in your tenant, with evidence kept.

Govern

Risk register, policies, incident plan and reporting duties set up and signed off. First board paper delivered.

Operate and report

Monthly report, quarterly board paper, the compliance programme worked through, and the environment kept where the board was told it is.

Book the call

Choose a time

Ben Jones
Ben JonesCyber Security Practice Lead, Coder Trove

Tell Ben what prompted the search, for example a board question, an APRA letter, a customer questionnaire or an insurance renewal form. He will confirm your obligations, look at the environment with you and tell you whether the full retainer or advisory alone is the right fit.

You will have a written scope and a fixed monthly fee the next business day.

  • No sales pitch. If you have a strong internal team or provider, Ben will say so and quote advisory only.
  • Your details are used to set up the call and send the scope, nothing else.

Prefer email or phone? Send a note or call +61 2 7200 2554.

Who does the work

Who does the work

The practice

CISO-led

Our cyber security practice is led by our Chief Information Security Officer and run by Ben. The same team runs Essential Eight assessments, penetration testing and incident response.

The leads

CISM and OSCP

Our security leads hold CISM and OSCP and have led cyber consulting practices and advised boards in government and the private sector. The person writing your board paper has presented one before.

The firm

Australian since 2010

Coder Trove has worked with mid-sized and enterprise organisations across Australia since 2010.

Common questions

Virtual CISO questions, answered

What does a vCISO cost in Australia?
Published advisory-only retainers run from about A$2,500 to A$15,000 a month. Ours starts at about A$7,000 a month for a 5 to 10 person organisation and includes running the security of your Microsoft 365 or Google Workspace environment, so compare it with advisory plus managed security, not advisory alone. The fee scales with users and scope and is fixed in writing after the first call. Prices exclude GST.
Does APRA or ISO 27001 require us to have a CISO?
No. CPS 234 makes the Board responsible for information security and requires the entity to clearly define security roles and responsibilities. ISO 27001 requires responsibilities to be assigned. Neither requires an employee or a full-time role, which is why a named external lead satisfies both.
Why bundle the vCISO with managing our environment?
Because findings that nobody owns do not get fixed. One global dataset found fewer than half of penetration test findings are ever resolved. When the person setting the priorities also runs the identity, email, device and backup controls, the advice is implemented and the evidence is kept for whoever asks.
Is that a conflict of interest?
It can be, so we put controls around it. The operations scope is written and fixed. You own the tenant, the licences and the data. Every accepted risk is signed by you, not us. And you can commission an independent assessment of our work at any time; we will hand over the evidence.
What do we have to report, and how fast?
If your turnover is A$3 million or more, a ransomware or extortion payment must be reported to the Australian Signals Directorate within 72 hours. APRA-regulated entities report material incidents within 72 hours and material control weaknesses within 10 business days. Critical infrastructure entities report within 12 or 72 hours depending on impact. Eligible data breaches go to the OAIC as soon as practicable. The retainer includes the plan, the regulator contacts and someone on call to run the response.
Can the vCISO present to our board?
Yes. You get a monthly risk and progress report and a quarterly board paper, presented by your vCISO when you want them in the room.
Will this help with cyber insurance?
Insurers now expect MFA on all remote access and email, endpoint detection with monitoring, and tested immutable backups. Those are the controls the managed service puts in place and keeps evidence for. We do not promise lower premiums. We do make sure you can answer yes to those questions with evidence.
Do we need to be on Microsoft 365?
No. Microsoft 365, Google Workspace and mixed environments are all supported. The tooling differs; the governance and the reporting do not.
What happens on the 30-minute call?
Ben sends an agenda beforehand. The call covers your obligations, your environment and whether the retainer fits. A written scope and a fixed monthly fee follow the next business day.

Related: Essential Eight assessment · Penetration testing · What a vCISO does with a few days a month · Incident response tabletop exercises

Start here

Book the first call

Thirty minutes with Ben, then a written scope and a fixed monthly fee the next business day.

© 2026 Coder Trove Pty Ltd · ABN 87 138 515 821 · Australia