Strategy & Governance

Managed Security

Cyber Defense

Governance, Risk & Compliance

Operations & People

Talk to us

Strategy & Governance

A virtual CISO: the accountability, without the headcount.

Virtual CISO services in India exist because of a specific gap. You have outgrown "the IT manager also handles security" (enterprise customers are sending questionnaires, an auditor is asking who owns the risk register) but a full-time chief information security officer is a senior salary you cannot yet justify.

A vCISO fills the role rather than advising it. Someone owns the security strategy, chairs the governance, signs off on risk, prepares the audit, answers the customer questionnaire, runs the incident when there is one, and presents to your board, on an agreed number of days per month, at a fraction of the cost of the position.

The engagement works because the role is largely judgement and accountability rather than volume of hours. Where it needs to become a full-time internal role, we say so and help you recruit into it. Where you need the plan before the accountability, start with cybersecurity strategy and governance.

Why you need it

01 / 06

When a vCISO is the right answer.

01

Enterprise deals are stalling at security review.

Procurement questionnaires, architecture reviews and a demand for SOC 2 or ISO 27001:2022 have become the last gate before signature. Answering them credibly needs someone who owns the security programme and can speak to it, and every week of delay is a week of deferred revenue.

02

Nobody currently owns the risk.

Security is distributed across an IT manager, a compliance officer and whoever last dealt with an incident, which means no one is accountable for the whole and nothing joins up. Auditors, insurers and boards all ask the same question: who owns this?

03

A full-time CISO is not yet justifiable.

The market rate for an experienced security leader is a substantial fixed cost, the recruitment cycle is long, and a strong candidate will not join an organisation with no programme to lead. A vCISO gets the capability now and makes the eventual role attractive.

04

You have a plan and no one to execute it.

The most common reason a strategy engagement produces nothing is that the roadmap has no owner once the consultants leave. A vCISO is that owner, with the authority and the calendar to make it happen.

Instrument

02 / 06

Where you are, before the first conversation.

Ten questions, answered honestly, give an indicative posture and the gaps a vCISO would work first.

What we deliver

03 / 06

What the role covers.

01

Security strategy

Owning the security roadmap and keeping it current: risk prioritisation, the sequence of what gets done, the investment case, and the honest conversation about what is being accepted rather than fixed this year. The plan is maintained continuously rather than produced once.

02

Compliance management

Running the certification and audit programme end to end: ISO 27001:2022, SOC 2, DPDP Act, GDPR and sector obligations, including policy creation, evidence readiness, auditor liaison and the customer security questionnaires that arrive without warning.

03

Incident readiness and response coordination

Breach planning before the fact: incident response plan, roles, escalation and tabletop exercises. During an incident, the vCISO coordinates the response, manages communication with customers, regulators and insurers, and makes the calls that need someone accountable to make them.

04

Executive and board advisory

Leadership reporting that translates technical risk into business terms, board and audit committee attendance, security input on product and commercial decisions, and the security half of due diligence when you are raising, acquiring or being acquired.

05

Team leadership and vendor oversight

Line-of-sight management for your internal security staff, technical direction where you have none, and oversight of the security vendors and managed services you buy, including whether they are delivering what the contract says.

06

Transition to a permanent hire

When the role justifies a full-time appointment, the vCISO writes the specification, sits on the interviews, and hands over a programme rather than a backlog. Planning for that exit from the start is a feature of the engagement, not a concession.

How we run it

04 / 06

How the engagement runs.

  1. 01

    Scoping and match

    Your obligations, your pressures and your existing capability, so that the engagement is sized to what actually needs doing, typically two to eight days per month, and you meet the person who will hold the role before committing.

    Week 0
  2. 02

    Onboarding and assessment

    A rapid current-state review, an inherited-risk picture, and the first ninety-day plan. The early weeks are deliberately weighted toward the commercial blockers (a stalled deal, an imminent audit) because that is what pays for the engagement.

    Month 1
  3. 03

    Establishing governance

    A security steering group with a real remit, a risk register with named owners, a policy framework, a reporting cadence to leadership and the board, and the decision rights that let the programme move without escalation for every item.

    Months 1-2
  4. 04

    Executing the roadmap

    Working the priorities in sequence, coordinating internal teams and external providers, running the certification programme, handling questionnaires and audits, and reporting on movement rather than activity.

    Months 2-12
  5. 05

    Review and evolution

    Formal reassessment of priorities against what has changed in the business and the threat picture, an honest review of what the engagement has delivered, and a direct recommendation on whether the days per month should go up, down, or convert to a permanent hire.

    Quarterly

Key benefits

05 / 06

What changes after.

Someone is accountable

A named security leader who owns the risk register, chairs the governance and answers to the board, which is the specific thing auditors, insurers and enterprise customers are checking for.

Security stops blocking sales

Questionnaires, architecture reviews and certification requirements are handled by someone who does this weekly, so the security gate stops being the reason a deal slips a quarter.

You get the capability at the cost you can carry

Senior judgement on an agreed cadence, scaling up during an audit or an incident and down when things are quiet, with a defined path to a permanent hire when the role earns it.

Tools we use

06 / 06

Named, and used on your engagement.

No “latest tech tools”. These are the ones your report will cite, alongside the manual work that a tool cannot do for you.

Governance frameworks

  • ISO 27001:2022
  • NIST Cybersecurity Framework 2.0
  • CIS Critical Security Controls v8

Compliance

  • SOC 2 Trust Services Criteria
  • DPDP Act, 2023
  • GDPR
  • PCI DSS

Risk and reporting

  • ISO 27005
  • Risk register and treatment plan
  • Board reporting pack

Response readiness

  • NIST SP 800-61
  • Tabletop exercise library
  • Incident response plan

Assessment

  • SIG questionnaires
  • CAIQ
  • Customer security questionnaire library

Why Aphelion

Shared

Four things you can check.

01

The work is done by people with names.

Darshap Nayak, formerly of KPMG, holds a master’s degree in cybersecurity and more than seven years in security operations. Jaimin Somani brings fifteen-plus years of academic and hands-on VAPT. Hemang Desai is an ICT network specialist from Australia. You will meet them, not a logo.

Meet the team
02

Evidence, not adjectives.

Every finding arrives with the reproduction steps, the affected asset and the fix, ranked by what it actually reaches in your environment, not by a CVSS number copied from a scanner. You get the report and the raw output, not a summary of a summary.

See how we test
03

Two offices, one practice.

Ahmedabad and Sharjah, working the same methodology on the same tooling. Indian data-residency requirements and UAE delivery are both ordinary here, and the AphelioNYX AD Pen-Test module runs entirely inside your perimeter when regulation says it must.

The platform
04

What we will not do.

Invent a statistic to make a slide land. Publish your name as a client without written permission. Print an award badge nobody awarded. Founded in 2024. We say so, and we attribute experience to the people who have it.

Ask us anything

100+ organizations secured

Across the globe, and across eight industries. We name a client only with their written permission.

  • Finance & Banking
  • Healthcare
  • Retail & E-commerce
  • Technology
  • SaaS
  • Hospitality
  • Manufacturing
  • Pharmaceuticals

AphelioNYX is SOC 2, ISO and GDPR compliant; attestations are available on request under NDA. We would rather hand you the report than print a badge.

Questions

FAQ

What clients ask about a vCISO.

How many days a month do we actually need?
Most engagements run between two and eight days a month. Two to three suits an organisation with an existing IT function that mainly needs governance, risk ownership and questionnaire support. Six to eight suits one driving a certification, building a security function or under active customer pressure. The load is not flat: an audit month or an incident consumes far more than a quiet one, so we build flex into the arrangement rather than pretending demand is even.
Is the vCISO a real named person or a rotating team?
A named individual who holds the role, attends your governance meetings and is known to your leadership, because accountability that rotates is not accountability. They draw on the wider team for specialist work (testing, forensics, compliance execution) which is one of the advantages over a single in-house hire, but the person accountable to your board does not change without your agreement.
Will a vCISO satisfy our auditors and our customers?
Yes, provided the role is genuinely exercised rather than nominal. Auditors and enterprise customers are checking that security has an accountable owner with defined authority, that governance meets and produces records, and that risk decisions are documented and signed. A vCISO who chairs the steering group, owns the register and signs the risk acceptances meets that expectation. One who is a name on an org chart does not, and assessors can tell the difference quickly.
What happens during a major incident?
The vCISO coordinates it, which is the situation the arrangement is most valuable in. They convene the response, make or escalate the containment decisions, manage communication with customers, regulators, insurers and the board, and direct the technical work, including bringing in our incident response team. Availability during an incident is written into the engagement rather than left to the monthly day allocation.
When should we hire a full-time CISO instead?
When the security function grows past a handful of people needing daily management, when regulatory obligations demand a full-time accountable officer, or when security decisions have become continuous rather than periodic. We will tell you when we think you have crossed that line, and then write the role specification, sit on the interviews and hand over a running programme. A vCISO engagement that quietly continues past its usefulness is a failure of advice.

Forty-five minutes. Your environment, not a slide deck.

A personalised walkthrough and a free readiness assessment against the frameworks you are actually being asked for. Pick a time that suits you, or write to us. We reply within one business day.