Cyber security · Virtual CISO
Virtual CISO services that include running your security
A named security lead, board reporting and a compliance programme, plus day-to-day management of your Microsoft 365 or Google Workspace security. The same team gives the advice and does the work.
What the retainer includes
- Security strategy and roadmapOwned by a named lead and reviewed quarterly
- Risk register and policy setWritten for your business, kept current, signed off by you
- Monthly report and quarterly board paperProgress against the roadmap, open risks and the cost to close them
- Compliance programmeEssential Eight, ISO 27001, APRA CPS 234 or SOCI, whichever you are held to
- Incident response plan and reportingA tested plan, the regulator contacts and someone on call to run it
- Your environment, run securelyIdentity and MFA, conditional access, email security, device management, backups, logging and patching
- CISO-led practicePractitioners hold CISM and OSCP
- Advice that gets implementedWe run the controls we recommend, to a written scope
- You keep ownershipThe tenant, the licences and the data stay yours, and you sign off every accepted risk
- Microsoft 365 and Google WorkspaceMixed environments included
Why this shape
Advice without control rarely gets done
The problem
Findings nobody owns
A vCISO who hands over a strategy document and comes back next quarter leaves the work with an IT team that is already busy. One industry dataset found that fewer than half of penetration test findings are ever resolved. The advice was fine; nobody had time to act on it.
Our answer
One team, two jobs
Your vCISO sets the priorities and reports to the board. The same team runs the identity, email, device, backup and logging controls that those priorities depend on, and keeps the evidence. If something has not been done, you call us, and we are the ones who were supposed to do it.
The fair objection is that we are marking our own homework. So the operations scope is written and fixed, you own the tenant and the licences, every accepted risk is signed by you, and you can commission an independent assessment of our work whenever you like. If you already have a strong internal team or provider, we will say so and quote advisory only.
When organisations engage a vCISO
What is being asked of you, in the regulators' own words
APRA CPS 234
Regulated entities
"The Board of an APRA-regulated entity is ultimately responsible for the information security of the entity." Roles and responsibilities must be clearly defined; material incidents reported within 72 hours. The retainer gives the Board a named owner and the evidence trail.
Cyber Security Act 2024
Any business over A$3m turnover
Ransomware and cyber extortion payments must be reported to the Australian Signals Directorate within 72 hours. The education-first period ended on 31 December 2025. The retainer includes the reporting procedure and the people to run it.
Customers and insurers
Questionnaires and renewals
Enterprise and government buyers ask who your CISO is and for your Essential Eight or ISO 27001 position. Insurers ask for MFA everywhere, endpoint detection and tested backups. A named lead with evidence answers both.
Also on the list: SOCI responsible entities whose annual risk management report must be approved by the board, organisations working toward ISO 27001 who need an owner for the management system, and boards that want one number after a near miss. The Privacy Act now includes a statutory tort for serious invasions of privacy, and reasonable steps to protect personal information expressly include technical and organisational measures.
How it runs
First 90 days, then a steady rhythm
Assess
Where you stand against the framework you are held to, what the environment looks like in practice, and the risks that matter in the first month.
Fix the foundations
MFA and conditional access, email security, device management, backups and logging brought to a defensible state in your tenant, with evidence kept.
Govern
Risk register, policies, incident plan and reporting duties set up and signed off. First board paper delivered.
Operate and report
Monthly report, quarterly board paper, the compliance programme worked through, and the environment kept where the board was told it is.
Book the call
Choose a time
Tell Ben what prompted the search, for example a board question, an APRA letter, a customer questionnaire or an insurance renewal form. He will confirm your obligations, look at the environment with you and tell you whether the full retainer or advisory alone is the right fit.
You will have a written scope and a fixed monthly fee the next business day.
- No sales pitch. If you have a strong internal team or provider, Ben will say so and quote advisory only.
- Your details are used to set up the call and send the scope, nothing else.
Prefer email or phone? Send a note or call +61 2 7200 2554.
Who does the work
Who does the work
The practice
CISO-led
Our cyber security practice is led by our Chief Information Security Officer and run by Ben. The same team runs Essential Eight assessments, penetration testing and incident response.
The leads
CISM and OSCP
Our security leads hold CISM and OSCP and have led cyber consulting practices and advised boards in government and the private sector. The person writing your board paper has presented one before.
The firm
Australian since 2010
Coder Trove has worked with mid-sized and enterprise organisations across Australia since 2010.
Common questions
Virtual CISO questions, answered
What does a vCISO cost in Australia?
Does APRA or ISO 27001 require us to have a CISO?
Why bundle the vCISO with managing our environment?
Is that a conflict of interest?
What do we have to report, and how fast?
Can the vCISO present to our board?
Will this help with cyber insurance?
Do we need to be on Microsoft 365?
What happens on the 30-minute call?
Related: Essential Eight assessment · Penetration testing · What a vCISO does with a few days a month · Incident response tabletop exercises
Start here
Book the first call
Thirty minutes with Ben, then a written scope and a fixed monthly fee the next business day.
