Security Manager Service
vCISO: an outsourced security manager
Where does the Security Manager service fit?
The Security Manager service is the final, ongoing stage of Braveson’s ISO 27001 service path: maintaining and developing the ISMS after the internal audit.
Kick-off
ISO 27001 Starter
€2,500 (excl. VAT)2Maturity assessment
ISO 27001 GAP Analysis
€5,850 (excl. VAT)3Internal audit
ISO 27001 Internal Audit
€4,000 – 7,000 (excl. VAT)Ongoing support
Security Manager service
€3,000 / month (excl. VAT)Continuity at a fraction of a full-time cost
Leading information security requires continuity, but a full-time security manager costs €80,000 – 120,000 a year including salary costs. An outsourced security manager (vCISO) brings the same expertise at a fraction of the cost, without the risk of hiring, and available immediately.
The service is designed especially for organizations that are ISO 27001 certified or aiming for it: an ISMS needs active maintenance to keep working, and the certificate requires ongoing annual effort.
What does the service cover?
Monthly
- ISMS maintenance
- Keeping documents current, managing changes, tracking nonconformities
- Risk management
- Maintaining the risk register, assessing new risks
- Management reporting
- A monthly security status update for management
- Incident management
- Coordinating and documenting security incidents
Quarterly
- Security awareness training for staff
- Audit planning and preparation
- Vendor and partner assessments as needed
Annually
- Internal audit
- Management review (facilitation and reporting)
- Updating the security policy and processes
- Certification audit preparation
What do you get, concretely?
Monthly report for management
Frequency: monthly
Updated risk register
Frequency: quarterly
Staff training
Frequency: quarterly
Internal audit report
Frequency: annually
Management review minutes
Frequency: annually
Updated security policy
Frequency: as needed
Who is this service for?
Ideal customer
- An ISO 27001 certified organization that needs continuity
- Pursuing certification, the vCISO takes the project to completion and maintains it
- An organization where an IT lead handles security alongside other work, without enough time for it
Not a fit if
- The organization already has its own full-time security manager
- A one-off project is needed, see the ISO 27001 Starter or the Current-State Assessment
How does the collaboration start?
Week 1–2
Current-state assessment: ISMS status, documents, open risks
Week 2–3
A prioritized action plan for the first quarter
Month 1+
Ongoing service underway
Price and terms
- Monthly price
- €3,000 (excl. VAT)
- Commitment
- At least 6 months
- Notice period
- 1 month after the commitment period
- Billing
- Monthly, in advance
- Delivery
- Mostly remote, on-site as agreed
- Language
- Finnish or English
Next step
Get in touch and we’ll schedule a free 30-minute scoping call.