What do I need to know if I want to be a virtual CISO?

3.5k views2 Upvotes12 Comments
Sort By:
Oldest
Director, Information Security Engineering and Operations in Manufacturing2 years ago
Plenty on the topic online: https://www.reddit.com/r/cybersecurity/comments/m1y256/ama_series_ask_a_ciso_anything/
1
CIO in Software2 years ago
Lot of literature in it. I was part of a team recently to hire CISO. Key things we agreed to look for was solid understanding of technology, common social engg / devOps/ developer laxity gap plug knowhow, general understanding of devsecOps and general passion for keeping things secure. Few thing we detested were managers in architecture role, or worse a misplaced sales guy
CIO/CISO in Healthcare and Biotech2 years ago
You should be able to structure your work product and schedule just like a consultant, as you will be handling multiple organizations' needs.
lock icon

Please join or sign in to view more content.

By joining the Peer Community, you'll get:

  • Peer Discussions and Polls
  • One-Minute Insights
  • Connect with like-minded individuals
CIO in Education2 years ago
A virtual CISO is very much operating in the same fashion as any consultant.  They need to be extremely well organized and technical to be capable of  bouncing between different organizations. Unlike a consultant there is a lot riding on the decisions and oversight  so each client would need to be as top of mind as if  it were your only customer. 
CIO in Services (non-Government)2 years ago
It's very much a consultant-like position.  You have to be extraordinarily organized, make sure you know what resources are available to you at each of your vCISO clients (oe jut at whichever single client you are working for presently.)  You will need a broad range of tested and well researched tools, such as for penetration testing, vulnerability scanning and whatever other areas you are selling your expertise in.  You need to become expert in each of those tools and be able to produce concise, actionable reports for your client, with tiered recommendations as to which actions need to be implemented first.

I suggest you look at the profiles of other vCISOs to see what their areas of expertise and specializations are, and try to connect with them, to have one on one conversations with them if possible.  Network and learn.

Content you might like

Audio19%

Video70%

No preference8%

It depends (please explain in the comments)1%

View Results
3.7k views2 Comments
CEO in Services (non-Government)a month ago
I have simply asked them in 1:1 how do they perceive me, what would they recommend me for, what one word will better define me.
1
Read More Comments
1.5k views3 Comments

Very satisfied8%

Satisfied63%

Neither satisfied nor dissatisfied17%

Dissatisfied9%

Very dissatisfied1%

View Results
3.2k views2 Upvotes