Skip to content
Services · Security Development

Security Manager Service

vCISO: an outsourced security manager

€3,000 / month (excl. VAT)Minimum 6-month commitmentFor SMEs without their own security manager
Service path

Where does the Security Manager service fit?

The Security Manager service is the final, ongoing stage of Braveson’s ISO 27001 service path: maintaining and developing the ISMS after the internal audit.

Why this service?

Continuity at a fraction of a full-time cost

Leading information security requires continuity, but a full-time security manager costs €80,000 – 120,000 a year including salary costs. An outsourced security manager (vCISO) brings the same expertise at a fraction of the cost, without the risk of hiring, and available immediately.

The service is designed especially for organizations that are ISO 27001 certified or aiming for it: an ISMS needs active maintenance to keep working, and the certificate requires ongoing annual effort.

What does the service cover?

Monthly

ISMS maintenance
Keeping documents current, managing changes, tracking nonconformities
Risk management
Maintaining the risk register, assessing new risks
Management reporting
A monthly security status update for management
Incident management
Coordinating and documenting security incidents

Quarterly

  • Security awareness training for staff
  • Audit planning and preparation
  • Vendor and partner assessments as needed

Annually

  • Internal audit
  • Management review (facilitation and reporting)
  • Updating the security policy and processes
  • Certification audit preparation

What do you get, concretely?

Monthly report for management

Frequency: monthly

Updated risk register

Frequency: quarterly

Staff training

Frequency: quarterly

Internal audit report

Frequency: annually

Management review minutes

Frequency: annually

Updated security policy

Frequency: as needed

Who is this service for?

Ideal customer

  • An ISO 27001 certified organization that needs continuity
  • Pursuing certification, the vCISO takes the project to completion and maintains it
  • An organization where an IT lead handles security alongside other work, without enough time for it

Not a fit if

  • The organization already has its own full-time security manager
  • A one-off project is needed, see the ISO 27001 Starter or the Current-State Assessment

How does the collaboration start?

Week 1–2

Current-state assessment: ISMS status, documents, open risks

Week 2–3

A prioritized action plan for the first quarter

Month 1+

Ongoing service underway

Price and terms

Monthly price
€3,000 (excl. VAT)
Commitment
At least 6 months
Notice period
1 month after the commitment period
Billing
Monthly, in advance
Delivery
Mostly remote, on-site as agreed
Language
Finnish or English

Next step

Get in touch and we’ll schedule a free 30-minute scoping call.

Book a scoping call