Virtual CISO services, without the full-time hire
A virtual CISO (vCISO) is the executive-level security leader your business needs but cannot justify hiring full-time. Strategy, governance, framework selection, board reporting and incident leadership, set independently of the people executing the work.
The vCISO role on your engagement is held by Aegis Cybersecurity , an independent Brisbane cybersecurity practice founded by Luke Irwin. Aegis sets the strategy, defines the frameworks and writes the business and security requirements. Real Bytes executes against those requirements as your managed IT and cybersecurity provider.
We deliberately separate the two roles. The advisor setting the standard should not be the team marking their own homework. You get an independent voice on what good looks like, and an experienced operator delivering it.
$400k+
Annual cost of a full-time CISO in Australia
40%
Of mid-market enterprises now use a vCISO model
6 to 12 months
Realistic ISO 27001 path with senior leadership
20+ years
Senior cyber leadership held independently by Aegis
vCISO held by Aegis Cybersecurity
An independent Brisbane practice. They set the requirements. Real Bytes executes. Two separate roles, on purpose.
The advisor and the operator should not be the same team
Aegis sets the standard. Real Bytes executes against it. Two distinct roles, kept independent on purpose so the assurance work is real, not internal.
Aegis Cybersecurity
Independent vCISO
Sets the strategy, picks the frameworks, writes the business and security requirements. Reports independently to your board. Founded by Luke Irwin with 20+ years in IT and cyber.
Owns
- Risk assessment and posture baseline
- Framework selection and roadmap
- Business and security requirements
- Independent assurance and board reporting
- Tabletop exercises and incident leadership
Real Bytes
Managed IT and Cyber Operator
Delivers against the requirements Aegis sets. Runs the technical environment day to day. Reports progress and evidence back into the vCISO programme for independent review.
Executes
- Managed Microsoft 365 and identity
- 24/7 EDR/MDR and SOC
- Backup, patch and vulnerability management
- Control implementation and evidence collection
- Day-to-day helpdesk and operations
Why this matters. A lot of MSPs offer "vCISO services" delivered by their own team. The same people picking the controls, deploying them, and assuring them. That is not independence. With this model, Aegis writes the standard you are held to, Real Bytes does the work, and the assurance loop sits with the advisor, not the operator. You get honest answers, not internal marking.
What vCISO services actually include
A vCISO is not a security product. It is a senior leader on retainer, focused on the outcomes that matter to the board, the customers, the auditors and the insurers.
A security strategy that survives the boardroom
Risk-based prioritisation, written in language your board, auditors and insurers actually use. No jargon, no scare-selling, no shopping list of products.
Confident answers to supplier questionnaires
When enterprise customers ask about your security posture, ISMS, Essential Eight maturity or breach history, you have documented answers ready. No more lost deals over due diligence.
Lower cyber insurance premiums and broader cover
Insurers reward demonstrable maturity. A vCISO programme produces the evidence that moves you from declined or excluded to fully covered at competitive premium.
Audit and certification readiness
Whether you are pursuing ISO/IEC 27001, SMB1001 Diamond, or a major customer audit, a vCISO drives the programme rather than scrambling at the last minute.
A senior voice for your leadership team
Your CEO, CFO and operations leads need someone they can call when a question lands. Not a ticket queue, not a sales rep. A trusted advisor who knows your environment.
Real readiness for the worst day
Tested incident response plans, exec briefings, regulator notification protocols, insurer relationships established before they are needed.
A typical engagement
vCISO is a recurring relationship, not a project. Here is what the rhythm looks like across the first year and beyond.
Discovery and posture baseline
Full review of current state across governance, technical controls, supplier risk, identity, data and incident readiness. Output is a written security posture report and prioritised risk register.
Strategy and roadmap
Develop a 12 to 24 month security roadmap mapped to your business objectives, regulatory obligations and customer requirements. Roadmap is owned at board level, not IT.
Monthly steering and quarterly board reporting
Monthly working session with leadership and IT. Quarterly written report for the board covering risk posture, programme progress, incidents, and emerging threats relevant to the business.
Incident leadership and crisis support
When an incident occurs, the vCISO leads communication with executives, insurers, OAIC and ACSC where applicable, and external counsel. You are not making these calls alone.
Programme review and reset
Formal review of the security programme against business change, threat landscape evolution, and updated obligations. Roadmap refreshed for the year ahead.
Programme delivery against the frameworks that matter
Most Australian businesses do not need every framework. A vCISO sequences the right ones for your customers, regulators and risk profile. We then drive the programme to certification, not just to a report.
ISO/IEC 27001
Full ISMS scoping, risk methodology, Statement of Applicability, internal audit programme, and Stage 1/2 readiness. We work alongside your accredited certification body so the audit is a formality, not a fire drill.
SMB1001:2026 (Levels 4 and 5)
Independently audited tiers including digital trust programme with suppliers, penetration testing, MDR, and police vetting. We map existing controls and close the gaps to certification standard.
ACSC Essential Eight (ML1 to ML3)
Maturity uplift aligned to the ACSC Essential Eight Maturity Model and Evidence Guide. Practical implementation roadmap, not a tick-box exercise.
APRA CPS 234
Information security capability proportional to size, complexity and risk profile. Board-level reporting, ongoing testing programme, supplier obligations and incident notification protocols.
Privacy Act and Notifiable Data Breaches
Privacy impact assessments, data classification, breach response playbooks aligned to OAIC guidance, and reasonable steps documentation under Australian Privacy Principles.
Sector-specific obligations
SOCI Act and CIRMP for critical infrastructure. AESCSF for energy. My Health Records Act for healthcare. We sequence the right controls for your industry.
Not sure which framework you actually need? Our guide on ISO 27001 vs SMB1001 vs Essential Eight compares the three frameworks Australian businesses are most often asked about.
When a vCISO is the right call
vCISO is not for every business. The model fits when security has become a board-level concern but a full-time CISO is not yet justifiable.
Mid-market businesses (50 to 500 staff)
Too large to ignore security, too small to hire a $400k full-time CISO.
Government and enterprise suppliers
You are losing or risking deals because customers ask security questions you cannot answer with confidence.
Regulated industries
Financial services, health, critical infrastructure, professional services with statutory obligations.
Pre-IPO or pre-acquisition
You need a credible security posture and ISMS in place for due diligence within 6 to 12 months.
Post-incident organisations
Following a breach, near-miss, or insurer mandate. You need senior security leadership now, not in six months.
What a vCISO is not
We are direct about scope. The vCISO is senior leadership on retainer, held by Aegis as your independent advisor. It is not a substitute for the operational work below, which Real Bytes delivers as your managed IT and cybersecurity provider.
Not a 24/7 SOC analyst
You still need monitoring. Real Bytes provides this through Huntress MDR and our SOC partnerships.
Not a help desk
Day-to-day technical support sits with Real Bytes managed IT.
Not a one-off audit
A point-in-time audit is useful but cannot replace ongoing governance. The vCISO drives improvement, not just measurement.
Not a substitute for technical staff
You still need engineers to implement controls. Aegis directs the work and validates the outcomes Real Bytes delivers.
What it costs, and what you are comparing it to
Most boards weigh three options when security becomes their problem. Here is an honest read on each, including where the vCISO model is the wrong answer.
Full-time CISO
$300k to $450k+ per year
Large enterprise, complex regulatory load, in-house security team to lead.
- Full-time attention
- Deep internal knowledge
- Hard to justify under 500 staff
- Long recruitment in a tight market
- Single point of failure on leave
vCISO on retainer
A fraction of a full-time salary, set by scope and cadence
Mid-market businesses of roughly 50 to 500 staff carrying board-level security risk.
- Senior experience from month one
- Independent of the team doing the work
- Scope moves up or down as the programme matures
- Not full-time attention
- Needs an operator to execute the work
One-off consultant report
Fixed project fee
A specific question: an audit, a gap assessment, a single certification push.
- Clear scope and price
- Useful snapshot
- Goes stale quickly
- Nobody owns the follow-through
- No board reporting rhythm
How pricing is set. The retainer is scoped on your size, the frameworks you are held to, and the reporting cadence your board needs. A business chasing ISO/IEC 27001 certification inside twelve months needs more time than one holding a steady Essential Eight maturity level. We quote it plainly, in writing, before any work starts.
vCISO questions we get asked
What does a vCISO actually do?
A vCISO holds the senior security leadership role in your business on a retainer instead of a salary. That means setting the security strategy, choosing which frameworks you work to, writing the business and security requirements, reporting risk to the board in language it can act on, and leading the response when something goes wrong.
How is a vCISO different from a managed IT provider?
The vCISO decides what good looks like. The managed IT provider builds and runs it. On our engagements Aegis Cybersecurity holds the vCISO role independently and Real Bytes executes against the requirements they set, so the team being assessed is not the team doing the assessing.
What does a vCISO cost in Australia?
A full-time CISO in Australia typically costs $300,000 to $450,000 or more a year once salary, on-costs and recruitment are counted. A vCISO retainer is a fraction of that and is scoped on your size, the frameworks you are held to and the reporting cadence your board needs. We quote it in writing before work starts.
When is a business ready for a vCISO?
Usually when security has become a board-level or customer-level issue but a full-time hire cannot be justified yet. Common triggers are a lost or at-risk deal over a security questionnaire, a cyber insurance renewal that is being questioned, an ISO/IEC 27001 or SMB1001 requirement from a customer, a merger or investment process, or a recent incident.
Can a vCISO help us get ISO/IEC 27001 certified?
Yes. The vCISO scopes the information security management system, sets the risk methodology, builds the Statement of Applicability and runs the internal audit programme, then works alongside your accredited certification body through Stage 1 and Stage 2. A realistic path for a prepared mid-market business is six to twelve months.
Will a vCISO help with cyber insurance renewals?
Yes. Insurers price on demonstrable maturity, so the programme produces the evidence they ask for: multi-factor authentication coverage, endpoint detection and response, tested backups, patching cadence, privileged access controls and a documented incident response plan. The vCISO also handles the questionnaire and the broker conversation.
Who does the vCISO report to?
The board or the executive team, not the IT function. That reporting line is the point of the role. Monthly working sessions run with leadership and IT, and a written report goes to the board each quarter covering risk posture, programme progress, incidents and any emerging threats relevant to the business.
What happens if we have an incident?
The vCISO leads the executive side of the response: briefing the leadership team, coordinating with your insurer and external counsel, and handling notification obligations to the OAIC under the Notifiable Data Breaches scheme and reports to the ACSC where they apply. Real Bytes runs the technical containment and recovery work alongside that.
What a quarterly vCISO board paper actually contains.
The output of the vCISO programme is not a slide deck. It is a written board paper a director can read in twenty minutes and an engineer can deliver from. Six sections, every quarter, same shape. Below is the section structure and an excerpt from a recent paper, sanitised for confidentiality.
Quarterly cadence
Length
12 to 18 pages
Audience
Board and audit
Prepared by
Aegis (vCISO)
Evidence by
Real Bytes
Executive summary
Half-page director-readable summary covering posture direction, top three risks, programme progress and any escalation items. Written in business language, not engineering language.
Risk register movement
The top five to seven technology risks named, owned, rated and trended quarter on quarter. Tied back to specific operational scenarios, not abstract categories.
Security posture against the framework
Quarter-on-quarter movement against the published framework selected for the business: Essential Eight, SMB1001, ISO 27001 or NIST CSF. Controls that moved, controls deferred and the reasoning behind each.
Programme delivery and roadmap
What was delivered this quarter, what is in flight, what is planned for the next two quarters. Each item linked back to a risk, a strategic objective or a regulatory obligation.
Incidents and lessons
All incidents this quarter, including minor ones, with severity classification, mean time to detect, mean time to recover, and the specific lessons fed into the roadmap.
Forward signals
Emerging threats and regulatory changes relevant to the business in the next 90 days. Names the decisions the board will need to make at the next sitting.
Excerpt: Q3 quarterly summary
SanitisedFirst paper lands at the end of month three of the engagement.
The numbers a board actually needs to see
Cyber insurance renewals and board questions both circle the same data points. A fractional CISO programme exists to translate those numbers into a decision the board can defend, with the controls and reporting cadence that match. The Verizon 2026 DBIR sets the baseline.
Read the Verizon 2026 DBIR48%
48% of breaches involved a third party globally, up from 15% two years ago
Your supplier list is now part of your attack surface.
62%
62% of breaches still involved a human element across all sectors
Identity, awareness and process discipline remain the controllable variables.
Trending up
Ransomware impact remains one of the most disruptive breach types and continues to climb
Premium calculators and underwriting questionnaires reflect this in 2026 renewals.
26%
26% of critical known-exploited vulnerabilities were fully remediated in 2025, down from 38% the year before
Patch programmes are slipping while attacker tooling speeds up. The gap widens every quarter.
Source: Verizon 2026 Data Breach Investigations Report. Dataset window Oct 2024 to Nov 2025. 31,000+ incidents and 22,000+ confirmed breaches across 145 countries.
Book a strategic discovery session
A no-obligation 60-minute conversation with Aegis as your independent vCISO and Real Bytes as your operator. We discuss your business, your customers, your obligations and where the programme would have the most impact.
No deck. No pitch. Just a direct conversation about whether the model fits. Available nationwide including Hobart and Tasmania.

Remote Support