Virtual CISO

Virtual CISO services for businesses without a security lead

A virtual CISO, or vCISO, is a senior security lead who works with your business part time. They own your cyber risk: what could go wrong, what you are doing about it and how you report it to your board, insurers and clients. You get the leadership of a chief information security officer for a monthly fee, backed by the team that runs 24/7 security for our clients.

Your price in two minutes. No email needed.

Austin Technology senior engineer thinking through a client security plan in the Subiaco office
Security leadershipPart time, fully accountable
  • $288,850Median base salary of a Perth CISO, before super (Robert Half, 2026)
  • 24/7Security operations centre on every SecureShield plan
  • ISO27001 certified, audited every year
  • Top 50MSP in Australia, 2024 to 2026

01Who it suits

When cyber risk needs an owner

Most businesses of 10 to 500 staff do not need a full time security executive. They do need someone senior who owns the risk. These are the moments that usually bring that home.

  1. Your board is asking about cyber risk

    Directors are expected to understand and oversee cyber risk, and nobody can give them a straight answer about where the business stands.

    FixA risk register and a regular board report in plain English, with the decisions the board needs to make.

  2. Security questionnaires slow down sales

    Clients, tenders and insurers send long security questionnaires, and answering them pulls your best people off their real work.

    FixOne owner for the answers and the evidence behind them, kept in a library you can reuse.

  3. A compliance target lands on your desk

    A contract, insurer or regulator wants the Essential Eight, SMB1001 or stronger privacy controls, and nobody owns the plan to get there.

    FixA roadmap that says what gets done, by whom and when, with progress you can show.

  4. Your IT team is stretched

    Your IT manager or provider keeps systems running, but security strategy keeps losing out to the urgent work of the day.

    FixA security lead who sets the direction while your IT team or provider does the work.

02What you get

What a vCISO does for your business

The same responsibilities as a chief information security officer, scoped to the size of your business and the obligations you carry.

/01

Risk assessment and register

We assess your risks, rate them and keep a register that says who owns each one and what is being done about it.

/02

Security strategy and roadmap

A plan for the year ahead, tied to your business, your budget and the frameworks you need to meet.

/03

Policies your staff can follow

Security policies written for how your business works, rather than copied from a template and left in a folder.

/04

Board and executive reporting

Regular reports in plain English on risk, progress and incidents, with the decisions that need to be made.

/05

Clients, suppliers and insurers

Security questionnaires, tender responses and insurance renewals answered, and your own suppliers' security checked.

/06

Ready for an incident

An incident response plan tested with your leadership team, so everyone knows who does what and which reporting clocks start. See cyber incident response.

03Which service you need

vCISO, vCIO or managed security

Three services that are easy to confuse. Each answers a different question, and many businesses use more than one.

A virtual CISO compared with a virtual CIO and managed security services
ServiceThe question it answersWhat you get
Virtual CISOAre we managing our cyber risk, and can we prove it?Risk register, security roadmap, policies, board reporting and compliance evidence
Virtual CIOIs our technology helping the business, and what should we invest in next?IT roadmap, budget, project priorities and supplier decisions
Managed security servicesWho stops an attack at 2am?A 24/7 security operations centre that detects and contains threats, with monthly reporting from Control

Swipe the table sideways to see every column.

04How it works

How your vCISO works with you

A clear starting point, a plan everyone agrees to and a rhythm that keeps it moving.

  1. Assess

    Understand your risk

    A review of your systems, data, suppliers, contracts and obligations, plus the questions your board and clients are asking.

  2. Plan

    Agree the roadmap

    The risks ranked, the fixes agreed and an owner named for each, in a plan that fits your budget.

  3. Lead

    Drive the work

    Working sessions on an agreed rhythm with your team or IT provider, so the plan turns into finished work.

  4. Report

    Tell the board

    Progress, open risks and the decisions that need making, in reports your leadership team can act on.

  5. Test

    Exercise and improve

    Incident exercises and a yearly review of the plan, so it keeps up with your business and the threats.

05Two ways to get one

A vCISO on its own or inside SecureShield

Start with the leadership, or get it together with the security tools and the 24/7 security operations centre that do the work.

On its own

vCISO retainer

Security leadership, scoped to you

A monthly retainer for businesses that need a security lead, whatever tools and IT support they have today. We agree the scope, the rhythm and the reporting before we start.

SuitsBusinesses with their own IT team or provider that need someone to own security.

Included

SecureShield Command

Leadership plus the full security stack

Everything in SecureShield Control, plus an ongoing vCISO, controls maintained at Essential Eight Maturity Level Two, SMB1001 Diamond alignment and quarterly security reviews. See SecureShield plans.

SuitsRegulated sectors, Defence supply chains and businesses with enterprise clients.

06Hire or retain

A full time CISO or a virtual one

A full time chief information security officer makes sense for large organisations with complex, regulated risk. For most others, this is how the two compare.

A full time chief information security officer compared with a virtual CISO
CompareFull time CISOVirtual CISO
CostA median base salary of $288,850, plus super and recruitment (Robert Half, 2026)A monthly fee, scoped to your size and obligations
Getting startedA recruitment process before any work beginsStarts with an assessment of where you stand
Experience behind themOne person's backgroundA security lead backed by our engineers and security operations centre
Leave and turnoverWork stops when they are away or leaveA team behind your vCISO, so cover does not depend on one person
Best forLarge organisations with a security budget and complex, regulated riskBusinesses of 10 to 500 staff that need the leadership, not the headcount

Swipe the table sideways to see every column.

07Frameworks

The standards we work to

Your vCISO works to the frameworks your clients, insurers and regulators recognise. They pick the ones that fit your business rather than all of them at once.

ASD is evolving the Essential Eight into a new Essentials series over the next two years, and the work you do now carries across. Our explainer covers what is replacing the Essential Eight. For a quick view of where you stand today, download the Essential Eight checklist.

We run our own ISO 27001 certified information security management system, audited every year, so we know what an auditor asks for and what good evidence looks like.

Frameworks your vCISO covers

  • ASD Essential Eight, and the move to Essentials
  • SMB1001, from Bronze to Diamond
  • ISO 27001 aligned controls
  • The AICD cyber security governance principles
  • The Privacy Act and Notifiable Data Breaches scheme
  • Ransomware payment reporting to ASD

08Recognised and certified

A top 50 MSP in Australia, three years running

Cloudtango named Austin Technology in its top 50 managed service providers in Australia in 2024, 2025 and 2026. We are also certified to ISO 27001 and ISO 9001, so the way we protect your data and run your service is checked by an independent auditor every year.

Cloudtango Top 50 MSP in Australia 2026, 2025 and 2024
Top 50 MSP in Australia Cloudtango, 2024, 2025 and 2026. Assessed on client satisfaction, growth and the depth of our security, support and infrastructure services. Read our client reviews on Cloudtango
Austin Technology engineers at work on the service desk in Subiaco
ISO 27001 certified by Compass Assurance Services

ISO 27001

Information security

Our information security management system covers how we handle client data, credentials and access to your systems, certified by Compass Assurance Services and audited every year.

How we protect your data
ISO 9001 certified by Compass Assurance Services

ISO 9001

Quality management

Support tickets, projects and onboarding follow documented processes, so you get the same standard of work whichever engineer picks up your job. Ask us for our certificates when you run a supplier review or tender.

09Questions

Virtual CISO questions

What owners, directors and IT managers ask before they bring in a vCISO. Anything else, call 1300 787 429.

01

What is a virtual CISO?

A virtual chief information security officer, or vCISO, is a senior security lead who works with your business part time. They own your cyber risk: they work out what could go wrong, agree what to do about it, make sure it gets done and report on it to your leadership team, board, insurers and clients.

02

How is a vCISO different from a vCIO?

A virtual CIO looks after technology strategy: what you run, what it costs and what comes next. A virtual CISO looks after security risk and governance: what could go wrong, what you are doing about it and how you prove it. Many businesses need both, and we provide both. See virtual CIO services.

03

How much does a virtual CISO cost?

A vCISO retainer is a monthly fee, quoted after a first conversation, based on your size, your obligations and how often you need your vCISO. It costs a fraction of a full time hire: the median base salary for a CISO in Perth is $288,850 before super (Robert Half, 2026). A vCISO is also included in SecureShield Command.

04

Do we need a vCISO if we already have an IT provider?

Your IT provider keeps your systems running. A vCISO sets the security direction, checks the work is done and reports on it. If we are your IT provider, your vCISO works with the same team. Our vCISO can also work alongside your internal IT team or another IT provider, with the split agreed up front.

05

What does a vCISO deliver first?

A review of your risks and obligations, a risk register that names an owner for each risk, a roadmap for the year ahead and a first report for your leadership team or board. From there, your vCISO drives the plan on an agreed rhythm.

06

Can a vCISO help with the Essential Eight and SMB1001?

Yes. Your vCISO plans the work, tracks progress and keeps the evidence an assessor or certifier will ask for. ASD is evolving the Essential Eight into a new Essentials series, and the work you do now carries across. Read what is replacing the Essential Eight and see SMB1001 certification.

07

Who will our vCISO be?

A senior member of our security team, who you meet before you start. They are backed by our engineers and by the security operations centre that watches our clients' systems around the clock.

08

Is a vCISO included in SecureShield?

Yes, in SecureShield Command, alongside controls maintained at Essential Eight Maturity Level Two, SMB1001 Diamond alignment and quarterly security reviews. Businesses on Core or Control, or with no SecureShield plan, can add a vCISO on its own. See SecureShield plans.

Client feedback

What our clients say

800+ reviews from the people who call our Perth service desk every day.

  • Simplesat700+
  • Cloudtango30+
  • Google70+
01 / 09
  • “Turns every IT problem into a non-issue”

    Arthur turns every IT problem into a non-issue and does it with real patience and professionalism. He explains things in a way that makes the process easy and always leaves us feeling supported. We appreciate the way he handles every request.

    Bronte J.Indian Ocean Hotel
  • “Patient, capable and a genuine listener”

    The support was outstanding. Patient, capable and a genuine listener, which is rare in support calls. He took the time to understand the issue and work through it with care. You are fortunate to have him on your team and the level of service was impressive.

    Peter MidgleyPowertech
  • “Steady, thoughtful and stress free”

    Jamie put in a great deal of effort to resolve the problem and it showed in the result. His approach was steady and thoughtful and the support was appreciated. It made the whole experience smooth and stress free.

    Jason CavallaroCallidus Process Solutions
  • “Resolved the issue within minutes”

    The consultant knew exactly what to do and resolved the issue within minutes. He talked through each step so I understood what was happening and made the process simple. The clear communication and fast resolution made a real difference.

    Kirk LentonPilbara Construction
  • “The extra guidance made it more valuable”

    Brady tracked down an email I could not locate and took the time to show us how to search more effectively in the future. The extra guidance was helpful and made the experience more valuable. His support was straightforward and appreciated.

    Tony YoungOptimus Real Estate
  • “Resolved quickly, with none of my work lost”

    They resolved my issue quickly and efficiently, which meant I didn’t lose any of the work I had done today. The support was clear and straightforward, and the outcome made a real difference to my day. Thank you.

    Warner PriestInterContinental Energy
  • “Calm, patient and always willing to help”

    Dev Sandhu is outstanding in his knowledge and support. He has a calm and patient way of working through any IT issue and is always willing to help at short notice. His positive attitude makes the whole experience easier and more reassuring. Thank you to Dev and the team at Austin for the consistent support.

    Peter AlexanderKoch Solutions
  • “A calm and methodical engineer”

    Chris Wade is a great engineer and I have a lot of respect for his professionalism. He approaches every issue with a calm and methodical attitude and communicates clearly so I always understand what is happening. His steady approach and reliability make a real difference to our team, and his support is always appreciated.

    Paul GreenGlobal Cardiology
  • “Refreshing after two unreliable IT providers”

    After dealing with two unreliable IT providers in recent years, it has been refreshing to place my trust in Greg and the team at Austin. They have been professional and highly competent, even under pressure. Their support has made a real difference. Thank you, and keep it up.

    Mark HutchisonLifewood
Trusted by 300+ organisations
Thyssenkrupp FLSmidth InterContinental Energy Global Cardiology Koch Solutions Callidus Process Solutions Carers WA Powertech Acclaim Visagio Roshana OGS Global Genus Lifewood

10Virtual CISO

Give cyber risk
an owner.

Book a vCISO call. We talk through your risks, your obligations and what your board, clients and insurers are asking for, then send you a scope and a price in writing.

Or call 1300 787 429

Level 2, 541 Hay Street, Subiaco WA 6008 Onsite across the Perth metro area. Remote support across regional WA and Australia.
Scroll to Top