A CISO for businesses
that don't have one.

Most small and mid-sized businesses can't justify a full-time Chief Information Security Officer - but they still carry the risk one would manage. The virtual CISO service builds your security strategy from the ground up: governance and risk first, then policy, then technical defence, then ongoing uplift. Australian-based, working globally.

It's the same four-stage method as the free SMB security guide - the guide teaches it; this is me doing it with you.

Straight about where this is. UMBRASEC is a new, independent practice run by one practitioner with years in defensive security. There's no inflated client list or team-of-fifty pitch here, because that would be a lie. What there is: published, sourced work you can evaluate today, a strictly defensive scope, and engagements scoped honestly to what one experienced person can do well.

Strategy from scratch,
in four stages.

A real security program isn't a product you buy - it's built in a sequence. The vCISO engagement follows the same arc as the free guide, but delivered with you: governance and risk first (so every technical decision has a reason), then policy, then defence, then the ongoing climb.

STAGE 01 · ASSESS
Where you actually are
An honest baseline of your current posture against the Essential Eight maturity model and ISO 27001 / NIST CSF 2.0 - what's in place, what's missing, and what your real risks are. You finish with a clear picture and a prioritised plan, not a fear pitch.
OUTPUT · current-state assessment + prioritised roadmap
STAGE 02 · STRATEGISE
Governance, risk & policy
The GRC foundation that makes everything else defensible: a risk register the board can read, security policies that fit your business (not a 90-page template), and alignment to NIST CSF 2.0's Govern function and ISO 27001:2022. This is where strategy is set, before a dollar is spent on tooling.
OUTPUT · risk register · policy set · strategy & governance model
STAGE 03 · IMPLEMENT
Identity & technical defence
Turning strategy into controls: identity and access, the Essential Eight technical mitigations, and the honest build-vs-buy calls on detection and response. Delivered directly or run alongside the individual engagements below - whichever fits your team.
OUTPUT · hardened identity & controls · detection/response decision
STAGE 04 · RUN & UPLIFT
Fractional CISO, ongoing
The part-time CISO seat your business needs but can't justify full-time: regular reviews, a steady climb up the maturity ladder, audit and certification readiness, and board reporting that translates security into business terms. Structured as an ongoing retainer, scoped and quoted before it starts.
OUTPUT · ongoing reviews · maturity uplift · board & audit reporting
WHY GOVERNANCE COMES FIRST

In Australia, cyber security is now a board and legal accountability issue, not just an IT one. ASIC has taken licensees to court over security failures - the Federal Court found against RI Advice in 2022 for inadequate cyber risk management, and ASIC has since pursued FIIG Securities over similar failings like unpatched systems and weak access controls. Add the Privacy Act's Notifiable Data Breaches scheme and the Cyber Security Act 2024, and the question directors face isn't "did we get hacked" but "can we show we took reasonable steps." A vCISO engagement is how you manage that accountability deliberately - with documented governance, not good intentions.

What it actually
looks like, working together.

You stay in control the whole time. I bring the structure, the frameworks, and the experience - you make the decisions and own the outcomes.

No big-consultancy process, no being handed off to a junior - it's the same person on every call. Here's how an engagement usually flows, from the first conversation to the ongoing seat, and what each side actually does at every step.

PHASE 00 · DISCOVERY
The first call
A no-obligation conversation, not a sales pitch. We talk about what the business does, what's forcing the issue - a customer questionnaire, an insurer, a near-miss, a board question - and what's already in place (IT team, MSP, or nobody).
YOU DO
Show up and talk straight. No prep, no NDA needed yet.
I DO
Listen, ask the sharp questions, and tell you honestly if I'm not the right fit.
OUTPUT · an honest read on fit and rough scope - no commitment
PHASE 01 · ONBOARD & ASSESS
Current-state baseline
We map what matters before touching anything: your crown jewels (the data and systems the business can't lose), what's actually in place today, and where the real exposure is - baselined against the Essential Eight, ISO 27001, and NIST CSF 2.0.
YOU DO
Point me at the right people and systems, and answer the questions honestly.
I DO
Run the assessment, build the first risk register, and surface the quick wins.
OUTPUT · current-state assessment · risk register v1 · quick-win list
PHASE 02 · STRATEGY & ROADMAP
A plan tied to the business
The assessment becomes a prioritised roadmap tied to your goals, risk tolerance, and budget - not a generic best-practice dump. Everything is sorted into quick wins, medium-term, and long-term, with a real business reason behind each step.
YOU DO
Tell me what the business is aiming at and what you can resource, then approve the plan.
I DO
Sequence the work, attach the business case to each step, and lay it out on one timeline.
OUTPUT · prioritised roadmap · quick-win / medium / long-term timeline
PHASE 03 · IMPLEMENT & EXECUTE
Turning the plan into controls
The roadmap gets built: tailored policies, the GRC foundation, technical controls (MFA, EDR, backups, logging - vendor-neutral), awareness training, and an incident-response plan you've actually rehearsed.
YOU DO
Your team or MSP owns the hands-on changes - who does what is agreed up front, in writing.
I DO
Own the strategy, the documentation, and the oversight, working right alongside you.
OUTPUT · policy set · GRC foundation · controls live · IR plan + tabletop
PHASE 04 · RUN & OPTIMISE
The ongoing CISO seat
The fractional CISO seat, on a cadence that fits: regular reviews, a steady climb up the maturity ladder, vendor-risk oversight, and audit or certification support when it's time. The risk register and roadmap stay living documents.
YOU DO
Keep making the calls, and put the plain-English reporting in front of your board and customers.
I DO
Hold the seat, keep the program moving, and prep you for whatever audit comes next.
OUTPUT · retainer cadence · board reporting · continuous uplift · audit support

The artifacts you keep.

Tailored to your business, not pulled from a template folder. Everything here is yours - documented, handed over, and built so your team can maintain it after the engagement ends.

Policies & procedures

A practical policy suite that fits how you actually work - access, data handling, acceptable use, vendor management - not a 90-page document nobody reads.

GRC foundation

A risk register the board can read, a POA&M (plan of action and milestones) for tracking gaps, a governance model, and the evidence processes auditors expect.

Technical oversight

Vendor-neutral recommendations and oversight for the controls that matter - MFA, EDR, backups, logging, hardening - chosen on fit and budget, not vendor relationships.

Training & IR readiness

Awareness training that sticks, an incident-response plan written for your environment, and tabletop exercises so the plan has been tested before you ever need it.

Vendor risk management

A repeatable way to assess the third parties holding your data or plugged into your systems - because their breach becomes your breach, and your customers will ask.

Board & exec reporting

Security translated into business terms - risk reduced, obligations met, money well spent - so leadership can make decisions without needing to read a SIEM.

As much, or as little, as you need.

The difference between these is how involved I am, not what you get charged for a box. Most engagements start light and deepen as the work does. None of them are packages off a shelf - the actual scope and cadence get agreed and quoted in writing before anything begins.

LIGHT STRUCTURE & DIRECTION
You drive, I navigate

You've got a team or an MSP and some momentum - what's missing is direction. I set the strategy and the roadmap, then check in to keep you pointed the right way.

  • Assessment, risk register & roadmap
  • Periodic direction-setting check-ins
  • A sounding board when decisions come up
ACTIVE PROGRAM BUILDING
We build it together

We're building the program side by side, on a regular cadence. I stay close to the work, keep the documentation current, and report as controls go live.

  • Everything in Light, ongoing
  • Implementation oversight & vendor risk
  • Regular board / exec reporting
FULL FRACTIONAL LEADERSHIP
The CISO seat, held properly

Deeper, more frequent involvement for businesses chasing a certification, under regulatory weight, or carrying enough risk to need a steady hand on the program.

  • Everything in Active, deeper cadence
  • SOC 2 / ISO 27001 audit readiness
  • Continuous improvement & assurance

On pricing: fixed scope, quoted in writing before work starts - no hourly creep, and month-to-month so you're never locked into a seat you've outgrown. A vCISO exists to give a smaller business the strategic security function of a full-time CISO at a fraction of the cost and commitment. What that costs you depends on the shape above and your environment, so the number comes after the scoping call, not before.

ILLUSTRATIVE ONLY - NOT A REAL CLIENT

What changes for a business like this.

UMBRASEC is a new practice, so this is a composite picture, not a case study. Imagine a 30-person professional services firm: a major client sends a security questionnaire, and there's nothing formal to point at - just a busy founder and good intentions. A few months into an engagement like this, the founder isn't the one fielding security questions anymore; there's a risk register and a roadmap that answer them. The questionnaire stops being a deal-blocker and becomes something the sales team can handle on its own. Leadership can finally see, in plain terms, where the real risk sits and what's being done about it. None of that is a tool you buy - it's the structure and the habit the engagement leaves behind.

FRAMEWORKS & APPROACH

We start with a framework that earns its keep for an SMB - NIST CSF 2.0, CIS Controls, or the Essential Eight here in Australia - and build against that. From there the same controls map to whatever you actually need to prove: SOC 2, ISO 27001, and the like. One foundation, many obligations - so you're not starting over every time a customer or regulator asks.

Or a single piece of the work.

Not every business needs the full vCISO arc on day one. These are the hands-on pieces - available standalone, or as the delivery muscle inside a vCISO engagement's Implement stage.

Detection engineering

Build and tune detections that actually fire on real techniques - Sigma, KQL (Sentinel / Defender), and Splunk - mapped to MITRE ATT&CK, with documented false-positive profiles so they survive contact with your environment.

  • New rule development against priority techniques
  • Tuning & false-positive reduction for noisy alerts
  • Detection coverage gap analysis (ATT&CK-mapped)
M365 & cloud hardening reviews

A focused review of your Microsoft 365 / Entra ID and cloud posture - the high-leverage settings that quietly decide whether an attacker walks in. Concrete, prioritized findings, not a 200-page PDF nobody reads.

  • Entra ID consent, conditional access & admin-role review
  • Logging & audit coverage gaps for detection
  • Prioritized remediation you can actually action
Threat-informed advisory

For teams with no in-house security lead: ongoing, plain-English advisory. What's actually relevant to your stack, what to prioritize next, and a sane detection roadmap - available as a light retainer.

  • Threat briefings tailored to your environment
  • Detection & hardening roadmap
  • "Ask the security person" retainer hours
Incident-response support

Suspected compromise and need a calm, experienced second pair of eyes? Triage, scoping, log analysis, and guided containment/recovery for cloud and identity incidents.

  • Triage & scoping of identity / M365 incidents
  • Log analysis & attacker-activity reconstruction
  • Guided containment, recovery & lessons-learned

Note: solo practice - for guaranteed 24/7 retained IR, a larger firm is the right call. Honest about that.

NOT SURE WHERE TO START? START HERE

M365 Security Review - a fixed-scope first engagement

The lowest-friction way to work together: a defined review of your Microsoft 365 / Entra ID tenant with a written quote before any work starts and concrete deliverables you keep. No retainers, no open-ended hours - if it surfaces bigger problems, you'll get an honest recommendation, even when that recommendation isn't me.

WHAT YOU GET
  • Consent, conditional-access & admin-role posture review
  • Logging & audit gap check, mapped to real detections
  • Prioritized findings document - yours to keep
  • Walkthrough call so your team owns the fixes
Get a written quote
CONSTRUCTION & TRADES

Two things bite this sector hardest: invoice and payment-mandate fraud - where an attacker quietly redirects a supplier payment - and head contractors who now require a baseline of security maturity before you can win or keep a tender. Getting your Essential Eight posture in order does double duty: it closes the fraud gap and it unlocks work you'd otherwise be screened out of.

REGULATED SECTORS

If you fall under SOCI (critical infrastructure) or APRA CPS 234 (financial services), the governance and reporting obligations are heavier and specific. Those engagements are scoped against the actual regulatory requirement - happy to talk through whether your obligations apply before you commit to anything.

Simple, scoped, honest.

01
Scope

A short call to understand the problem and whether I'm genuinely the right fit. If I'm not, I'll say so.

02
Quote

A written, fixed scope with clear deliverables and a price for that work. No surprise hourly creep.

03
Deliver

Work delivered with artifacts you keep - rules, findings, runbooks - and a walkthrough so your team can own it.

PRICING

Scoped per engagement - every problem is a different size, so pricing follows the agreed scope rather than a sticker on the wall. You'll always have the number in writing before any work starts.

SCOPE

Defensive only - detection, hardening, analysis, and response. No offensive engagements, no red-team or exploit work. That boundary is deliberate and it doesn't move.

Questions you should be asking.

Who am I actually hiring?

The research here is published under a handle, which is normal in this field - but clients don't hire a handle. You'll know exactly who you're working with - full identity and background - at the scoping call, before any engagement or access. NDAs welcome.

Isn't a vCISO just for big companies?

The opposite. Large companies hire a full-time CISO. The virtual CISO model exists precisely so a smaller business gets the same strategic function - governance, risk, board reporting - at a fraction of the time and cost, sized to what you actually need.

What does it cost?

Every engagement gets a written, fixed quote for a defined scope before work starts - no hourly creep. The M365 Security Review above is the defined entry point if you want a known shape first.

Will you do offensive work?

No. Detection, hardening, analysis, and response only - no red-team, exploit, or social-engineering engagements. That boundary is deliberate and it doesn't move.

What happens after I email?

A short reply, then a scoping call to understand the problem and whether I'm genuinely the right fit. If I'm not, I'll say so and point you somewhere better. If I am, you get the scope and quote in writing.

Let's talk.

Tell me what you're dealing with - a noisy SIEM, an M365 tenant nobody's reviewed, a roadmap you need a second opinion on, or an incident in progress. Book a free scoping call and pick a time that works, or send a pre-structured email if you'd rather write first.

Prefer to read the work first? See everything on GitHub →