Virtual CISO Advisory Services | Cyber Risk | Kroll (2024)

Cyber Governance and Strategy

Kroll’s Virtual CISO (vCISO) services help executives, security and technology teams safeguard information assets while supporting business operations with augmented cyber expertise to reduce business risk, signal commitment to data security and enhance overall security posture.

Contact Us

Explore Cyber Risk

  • Threat Exposure and Validation
  • Cyber Risk Assessments
  • Cloud Security Services
  • Incident Response and Litigation Support
  • Incident Response Tabletop Exercises
  • Kroll Responder
  • Cyber Risk Retainer

Irrespective of regulatory scrutiny in your industry or organization, too much is at stake to not have a CISO. A security leader has the specialized technical knowledge and corporate governance experience to help build a strong cyber security foundation and the agility to prevent, detect and mitigate evolving threats while enhancing the “security IQ” of your entire organization.

Kroll’s team of experts includes seasoned former CISOs from a variety of industries who can strengthen your existing staff, set strategic objectives to support business-critical technology demands and balance IT administration, as well as establish clear communication with the board of directors, investors and government agencies.

Whether you are looking for an interim CISO, a resource to support your CISO or a longer-term arrangement, Kroll’s Virtual CISO Advisory Services provide the leadership you need, when you need it.

    You can rely on a vCISO from Kroll to have the technical expertise, business acumen and communication skills to make an immediate difference. Our experts have served in a broad range of industries for companies of various sizes and will know how to align information security strategies with your company’s unique needs and challenges.Services and offerings include:

    • Setting or directing privacy and security policies, standards, procedures and guidelines
    • Managing and directing information security teams
    • Engaging with executive management
    • Running risk assessments on operational security
    • Providing threat intelligence and managing enterprise security
    • Crisis management

    Kroll’s Virtual CISO Advisory Services Help You Prepare, Protect and Strengthen Defenses

    Our vCISO Advisory Services are tailored to your specific situation and information security needs. While you have a number of options when it comes to the scope and length of services, there are four areas where most organizations benefit from the experience of a vCISO:

    Strategy Definition

    Guiding executives across business function and IT, Kroll’s vCISO helps identify business threats, provides a baseline for your current security program and defines security strategy in line with business objectives and technology strategies.

    Our phased approach helps ensure an effective and efficient strategy that leverages NIST 800-53 and can be mapped to multiple cyber regulations (e.g., PCI, HIPAA, GDPR, FINRA, NYDFS).

    Virtual CISO Advisory Services | Cyber Risk | Kroll (2)

    Assessment

    Evaluating culture, processes and technologies from a security governance perspective, Kroll’s vCISO develops prioritized actions to help effectively manage your information security strategy and program. Assessments can include:

    • Interviews with stakeholders across the technical, business and executive teams as well as gathering documentation
    • Robust reviews of a variety of areas, including information asset management, acceptable use policies, data classification, threat and vulnerability management and third-party management

      Oversight

      Based on the assessment findings, Kroll’s vCISO can provide various types and levels of ongoing support, including:

      • Developing policies and procedures to close gaps in documentation
      • Developing a remediation plan with actionable, prioritized recommendations
      • Implementing the remediation plan
      • Providing ongoing strategic guidance that is less intensive, but assists the organization in maintaining long-term goals

      Training

      Security awareness is an important part of maintaining a robust program. Your vCISO can recommend and help implement training on topics for every level of user group within your organization. This can range from the highly technical (e.g., secure coding practices) to general data handling education to combating business email compromise. The vCISO can also oversee controlled phishing campaigns, conducted by Kroll,to gauge employee security awareness.

      IT Environment Security Design

      For organizations looking to build from the ground up, Kroll’s vCISO can provide your team with necessary system hardening configuration guides and network designs. This will also include multiple security protections and incident monitoring controls.

      Virtual CISOs Bring Experience, Expertise, Leadership

      Kroll’s vCISO Advisory Services are drawn on the experience of former CISOs from a variety of industries—from professional services firms to multinational conglomerates—and bring a valuable blend of technical, executive and organizational experience. They are among the most accomplished technical experts practicing today, with special insight into evolving threats and solutions from their work at the front lines of cyber security. Kroll’s vCISOs are supported by our global, multidisciplinary team that includes former FBI, Interpol and U.S. Secret Service agents; former information technology and security executives; digital forensic scientists; intelligence analysts; and regulatory specialists from a wide variety of industries. This high-caliber team will help put your entire information security program on the maturity fast track.

      Finding an experienced, well-qualified CISO in today’s competitive information security job market can be challenging, time-consuming and expensive. If you need a CISO now, then this is the perfect time to consider Kroll’s Virtual CISO Advisory Services.

      Talk to a Kroll Expert

      Kroll is ready to help, 24x7. Use the links on this page to explore our services further or speak to a Kroll expert today via our 24x7 cyber hotlines or our contact page.

      Cyber Hotlines

      Frequently Asked Questions

      A virtual chief information security officer (“virtual CISO” or “vCISO”) is a specialist information security professional that organizations can call on for support with planning and executing an effective cybersecurity strategy. Virtual CISOs provide vital security experience, expertise and leadership to companies as and when they need it.

      Connect With Us
      John deCraenJohn deCraenAssociate Managing DirectorCyber RiskDallas
      +1 973 775 8303PhoneJohn deCraen
      Ira LevyIra LevyAssociate Managing DirectorCyber RiskWashington DC
      +1 2024491854Phone
      Walmir FreitasWalmir FreitasRegional Managing Director, LATAM Cyber RiskSao Paulo
      +55 11 3897 0916PhoneWalmir Freitas
      Stay Ahead with Kroll

      Application Security Services

      Kroll’s product security experts upscale your AppSec program with strategic application security services catered to your team’s culture and needs, merging engineering and security into a nimble unit.

      Application Security Services

      Optimized Third-Party Cyber Risk Management Programs

      Manage risk, not spreadsheets. Identify and remediate cybersecurity risks inherent in third-party relationships, helping achieve compliance with regulations such as NYDFS, FARS, GDPR, etc.

      Optimized Third-Party Cyber Risk Management Programs

      Third Party Cyber Audits and Reviews

      Ensure that your third parties are handling sensitive data according to regulatory guidelines and industry standards with our cyber audits and reviews.

      Third Party Cyber Audits and Reviews

      CFIUS Compliance and Review

      Helping organizations manage CFIUS, Team Telecom and FOCI requirements.

      CFIUS Compliance and Review

      Incident Response Tabletop Exercises

      Kroll’s field-proven incident response tabletop exercise scenarios are customized to test all aspects of your response plan and mature your program.

      Incident Response Tabletop Exercises
      Explore Insights
      CyberCyberPasskeyScanner: A Kroll BurpSuite Extension for PasskeysApril 23, 2024by Alex CowperthwaiteThreat IntelligenceThreat IntelligenceQ4 2023 Cyber Threat Landscape Report: Threat Actors Breach the Outer LimitsFebruary 21, 2024by Laurie Iacono, Keith Wojcieszek, George Glass
      Events
      CyberCyberKroll at RSA Conference 2024May 6 - 9, 2024|ConferenceJoin Kroll experts at the RSA Conference in San Francisco May 6-9, 2024. Stop by booth 2239 in the South Expo Hall to meet our team.Threat IntelligenceThreat IntelligenceQ1 2024 Cyber Threat Landscape Virtual BriefingMay 29, 2024|OnlineJoin the Q1 2024 Cyber Threat Landscape Virtual Briefing as Kroll’s cyber threat analysts outline notable trends and insights from our incident response intelligence.Threat IntelligenceThreat IntelligenceKroll at Infosecurity Europe 2024June 4 - 6, 2024|ConferenceJoin our cyber risk experts at Infosecurity Europe in London, June 4–6, Stand C35. Get the latest threat intel, win prizes, and more.
      News
      Press ReleasePress ReleaseKroll named as Major Player in IDC’s Worldwide Cybersecurity Consulting Services 2024 Vendor AssessmentApril 25, 2024Press ReleasePress ReleaseKroll Appoints Dave Burg as Global Head of Cyber Risk to Bolster World-Leading Business March 12, 2024Press ReleasePress ReleaseKroll Expands Cyber Partner Program with MSP SpecializationOctober 17, 2023Press ReleasePress ReleaseKroll Responder Named as Overall Leader in The KuppingerCole Leadership Compass for Managed Detection and Response ServicesAugust 16, 2023
      Virtual CISO Advisory Services | Cyber Risk | Kroll (2024)
      Top Articles
      Latest Posts
      Article information

      Author: Prof. Nancy Dach

      Last Updated:

      Views: 5259

      Rating: 4.7 / 5 (57 voted)

      Reviews: 80% of readers found this page helpful

      Author information

      Name: Prof. Nancy Dach

      Birthday: 1993-08-23

      Address: 569 Waelchi Ports, South Blainebury, LA 11589

      Phone: +9958996486049

      Job: Sales Manager

      Hobby: Web surfing, Scuba diving, Mountaineering, Writing, Sailing, Dance, Blacksmithing

      Introduction: My name is Prof. Nancy Dach, I am a lively, joyous, courageous, lovely, tender, charming, open person who loves writing and wants to share my knowledge and understanding with you.