Strategic Cyber Leadership

Virtual CISO services, without the full-time hire

A virtual CISO (vCISO) is the executive-level security leader your business needs but cannot justify hiring full-time. Strategy, governance, framework selection, board reporting and incident leadership, set independently of the people executing the work.

The vCISO role on your engagement is held by Aegis Cybersecurity , an independent Brisbane cybersecurity practice founded by Luke Irwin. Aegis sets the strategy, defines the frameworks and writes the business and security requirements. Real Bytes executes against those requirements as your managed IT and cybersecurity provider.

We deliberately separate the two roles. The advisor setting the standard should not be the team marking their own homework. You get an independent voice on what good looks like, and an experienced operator delivering it.

Independent advisor
No marking our own homework
Australian-owned
Mid-market focus
Separation of Duties

The advisor and the operator should not be the same team

Aegis sets the standard. Real Bytes executes against it. Two distinct roles, kept independent on purpose so the assurance work is real, not internal.

Aegis Cybersecurity

Independent vCISO

Sets the strategy, picks the frameworks, writes the business and security requirements. Reports independently to your board. Founded by Luke Irwin with 20+ years in IT and cyber.

Owns

  • Risk assessment and posture baseline
  • Framework selection and roadmap
  • Business and security requirements
  • Independent assurance and board reporting
  • Tabletop exercises and incident leadership
aegiscyber.com.au

Real Bytes

Managed IT and Cyber Operator

Delivers against the requirements Aegis sets. Runs the technical environment day to day. Reports progress and evidence back into the vCISO programme for independent review.

Executes

  • Managed Microsoft 365 and identity
  • 24/7 EDR/MDR and SOC
  • Backup, patch and vulnerability management
  • Control implementation and evidence collection
  • Day-to-day helpdesk and operations

Why this matters. A lot of MSPs offer "vCISO services" delivered by their own team. The same people picking the controls, deploying them, and assuring them. That is not independence. With this model, Aegis writes the standard you are held to, Real Bytes does the work, and the assurance loop sits with the advisor, not the operator. You get honest answers, not internal marking.

Business Outcomes

What vCISO services actually include

A vCISO is not a security product. It is a senior leader on retainer, focused on the outcomes that matter to the board, the customers, the auditors and the insurers.

A security strategy that survives the boardroom

Risk-based prioritisation, written in language your board, auditors and insurers actually use. No jargon, no scare-selling, no shopping list of products.

Confident answers to supplier questionnaires

When enterprise customers ask about your security posture, ISMS, Essential Eight maturity or breach history, you have documented answers ready. No more lost deals over due diligence.

Lower cyber insurance premiums and broader cover

Insurers reward demonstrable maturity. A vCISO programme produces the evidence that moves you from declined or excluded to fully covered at competitive premium.

Audit and certification readiness

Whether you are pursuing ISO/IEC 27001, SMB1001 Diamond, or a major customer audit, a vCISO drives the programme rather than scrambling at the last minute.

A senior voice for your leadership team

Your CEO, CFO and operations leads need someone they can call when a question lands. Not a ticket queue, not a sales rep. A trusted advisor who knows your environment.

Real readiness for the worst day

Tested incident response plans, exec briefings, regulator notification protocols, insurer relationships established before they are needed.

Engagement Cadence

A typical engagement

vCISO is a recurring relationship, not a project. Here is what the rhythm looks like across the first year and beyond.

Month 1

Discovery and posture baseline

Full review of current state across governance, technical controls, supplier risk, identity, data and incident readiness. Output is a written security posture report and prioritised risk register.

Months 2 to 3

Strategy and roadmap

Develop a 12 to 24 month security roadmap mapped to your business objectives, regulatory obligations and customer requirements. Roadmap is owned at board level, not IT.

Ongoing

Monthly steering and quarterly board reporting

Monthly working session with leadership and IT. Quarterly written report for the board covering risk posture, programme progress, incidents, and emerging threats relevant to the business.

As required

Incident leadership and crisis support

When an incident occurs, the vCISO leads communication with executives, insurers, OAIC and ACSC where applicable, and external counsel. You are not making these calls alone.

Annually

Programme review and reset

Formal review of the security programme against business change, threat landscape evolution, and updated obligations. Roadmap refreshed for the year ahead.

Frameworks & Compliance

Programme delivery against the frameworks that matter

Most Australian businesses do not need every framework. A vCISO sequences the right ones for your customers, regulators and risk profile. We then drive the programme to certification, not just to a report.

ISO/IEC 27001

Full ISMS scoping, risk methodology, Statement of Applicability, internal audit programme, and Stage 1/2 readiness. We work alongside your accredited certification body so the audit is a formality, not a fire drill.

SMB1001:2026 (Levels 4 and 5)

Independently audited tiers including digital trust programme with suppliers, penetration testing, MDR, and police vetting. We map existing controls and close the gaps to certification standard.

ACSC Essential Eight (ML1 to ML3)

Maturity uplift aligned to the ACSC Essential Eight Maturity Model and Evidence Guide. Practical implementation roadmap, not a tick-box exercise.

APRA CPS 234

Information security capability proportional to size, complexity and risk profile. Board-level reporting, ongoing testing programme, supplier obligations and incident notification protocols.

Privacy Act and Notifiable Data Breaches

Privacy impact assessments, data classification, breach response playbooks aligned to OAIC guidance, and reasonable steps documentation under Australian Privacy Principles.

Sector-specific obligations

SOCI Act and CIRMP for critical infrastructure. AESCSF for energy. My Health Records Act for healthcare. We sequence the right controls for your industry.

Not sure which framework you actually need? Our guide on ISO 27001 vs SMB1001 vs Essential Eight compares the three frameworks Australian businesses are most often asked about.

Who This Is For

When a vCISO is the right call

vCISO is not for every business. The model fits when security has become a board-level concern but a full-time CISO is not yet justifiable.

Mid-market businesses (50 to 500 staff)

Too large to ignore security, too small to hire a $400k full-time CISO.

Government and enterprise suppliers

You are losing or risking deals because customers ask security questions you cannot answer with confidence.

Regulated industries

Financial services, health, critical infrastructure, professional services with statutory obligations.

Pre-IPO or pre-acquisition

You need a credible security posture and ISMS in place for due diligence within 6 to 12 months.

Post-incident organisations

Following a breach, near-miss, or insurer mandate. You need senior security leadership now, not in six months.

Honest Disclosure

What a vCISO is not

We are direct about scope. The vCISO is senior leadership on retainer, held by Aegis as your independent advisor. It is not a substitute for the operational work below, which Real Bytes delivers as your managed IT and cybersecurity provider.

Not a 24/7 SOC analyst

You still need monitoring. Real Bytes provides this through Huntress MDR and our SOC partnerships.

Not a help desk

Day-to-day technical support sits with Real Bytes managed IT.

Not a one-off audit

A point-in-time audit is useful but cannot replace ongoing governance. The vCISO drives improvement, not just measurement.

Not a substitute for technical staff

You still need engineers to implement controls. Aegis directs the work and validates the outcomes Real Bytes delivers.

Cost and Models

What it costs, and what you are comparing it to

Most boards weigh three options when security becomes their problem. Here is an honest read on each, including where the vCISO model is the wrong answer.

Full-time CISO

$300k to $450k+ per year

Large enterprise, complex regulatory load, in-house security team to lead.

  • Full-time attention
  • Deep internal knowledge
  • Hard to justify under 500 staff
  • Long recruitment in a tight market
  • Single point of failure on leave

vCISO on retainer

A fraction of a full-time salary, set by scope and cadence

Mid-market businesses of roughly 50 to 500 staff carrying board-level security risk.

  • Senior experience from month one
  • Independent of the team doing the work
  • Scope moves up or down as the programme matures
  • Not full-time attention
  • Needs an operator to execute the work

One-off consultant report

Fixed project fee

A specific question: an audit, a gap assessment, a single certification push.

  • Clear scope and price
  • Useful snapshot
  • Goes stale quickly
  • Nobody owns the follow-through
  • No board reporting rhythm

How pricing is set. The retainer is scoped on your size, the frameworks you are held to, and the reporting cadence your board needs. A business chasing ISO/IEC 27001 certification inside twelve months needs more time than one holding a steady Essential Eight maturity level. We quote it plainly, in writing, before any work starts.

Common Questions

vCISO questions we get asked

What does a vCISO actually do?

A vCISO holds the senior security leadership role in your business on a retainer instead of a salary. That means setting the security strategy, choosing which frameworks you work to, writing the business and security requirements, reporting risk to the board in language it can act on, and leading the response when something goes wrong.

How is a vCISO different from a managed IT provider?

The vCISO decides what good looks like. The managed IT provider builds and runs it. On our engagements Aegis Cybersecurity holds the vCISO role independently and Real Bytes executes against the requirements they set, so the team being assessed is not the team doing the assessing.

What does a vCISO cost in Australia?

A full-time CISO in Australia typically costs $300,000 to $450,000 or more a year once salary, on-costs and recruitment are counted. A vCISO retainer is a fraction of that and is scoped on your size, the frameworks you are held to and the reporting cadence your board needs. We quote it in writing before work starts.

When is a business ready for a vCISO?

Usually when security has become a board-level or customer-level issue but a full-time hire cannot be justified yet. Common triggers are a lost or at-risk deal over a security questionnaire, a cyber insurance renewal that is being questioned, an ISO/IEC 27001 or SMB1001 requirement from a customer, a merger or investment process, or a recent incident.

Can a vCISO help us get ISO/IEC 27001 certified?

Yes. The vCISO scopes the information security management system, sets the risk methodology, builds the Statement of Applicability and runs the internal audit programme, then works alongside your accredited certification body through Stage 1 and Stage 2. A realistic path for a prepared mid-market business is six to twelve months.

Will a vCISO help with cyber insurance renewals?

Yes. Insurers price on demonstrable maturity, so the programme produces the evidence they ask for: multi-factor authentication coverage, endpoint detection and response, tested backups, patching cadence, privileged access controls and a documented incident response plan. The vCISO also handles the questionnaire and the broker conversation.

Who does the vCISO report to?

The board or the executive team, not the IT function. That reporting line is the point of the role. Monthly working sessions run with leadership and IT, and a written report goes to the board each quarter covering risk posture, programme progress, incidents and any emerging threats relevant to the business.

What happens if we have an incident?

The vCISO leads the executive side of the response: briefing the leadership team, coordinating with your insurer and external counsel, and handling notification obligations to the OAIC under the Notifiable Data Breaches scheme and reports to the ACSC where they apply. Real Bytes runs the technical containment and recovery work alongside that.

The deliverable

What a quarterly vCISO board paper actually contains.

The output of the vCISO programme is not a slide deck. It is a written board paper a director can read in twenty minutes and an engineer can deliver from. Six sections, every quarter, same shape. Below is the section structure and an excerpt from a recent paper, sanitised for confidentiality.

Quarterly cadence

Length

12 to 18 pages

Audience

Board and audit

Prepared by

Aegis (vCISO)

Evidence by

Real Bytes

01

Executive summary

Half-page director-readable summary covering posture direction, top three risks, programme progress and any escalation items. Written in business language, not engineering language.

02

Risk register movement

The top five to seven technology risks named, owned, rated and trended quarter on quarter. Tied back to specific operational scenarios, not abstract categories.

03

Security posture against the framework

Quarter-on-quarter movement against the published framework selected for the business: Essential Eight, SMB1001, ISO 27001 or NIST CSF. Controls that moved, controls deferred and the reasoning behind each.

04

Programme delivery and roadmap

What was delivered this quarter, what is in flight, what is planned for the next two quarters. Each item linked back to a risk, a strategic objective or a regulatory obligation.

05

Incidents and lessons

All incidents this quarter, including minor ones, with severity classification, mean time to detect, mean time to recover, and the specific lessons fed into the roadmap.

06

Forward signals

Emerging threats and regulatory changes relevant to the business in the next 90 days. Names the decisions the board will need to make at the next sitting.

Excerpt: Q3 quarterly summary

Sanitised
Book a strategic discovery session

First paper lands at the end of month three of the engagement.

What the 2026 breach data shows

The numbers a board actually needs to see

Cyber insurance renewals and board questions both circle the same data points. A fractional CISO programme exists to translate those numbers into a decision the board can defend, with the controls and reporting cadence that match. The Verizon 2026 DBIR sets the baseline.

Read the Verizon 2026 DBIR

48%

48% of breaches involved a third party globally, up from 15% two years ago

Your supplier list is now part of your attack surface.

62%

62% of breaches still involved a human element across all sectors

Identity, awareness and process discipline remain the controllable variables.

Trending up

Ransomware impact remains one of the most disruptive breach types and continues to climb

Premium calculators and underwriting questionnaires reflect this in 2026 renewals.

26%

26% of critical known-exploited vulnerabilities were fully remediated in 2025, down from 38% the year before

Patch programmes are slipping while attacker tooling speeds up. The gap widens every quarter.

Source: Verizon 2026 Data Breach Investigations Report. Dataset window Oct 2024 to Nov 2025. 31,000+ incidents and 22,000+ confirmed breaches across 145 countries.

Book a strategic discovery session

A no-obligation 60-minute conversation with Aegis as your independent vCISO and Real Bytes as your operator. We discuss your business, your customers, your obligations and where the programme would have the most impact.

No deck. No pitch. Just a direct conversation about whether the model fits. Available nationwide including Hobart and Tasmania.