Home » Strategic IT » vCISO

Strategic IT — vCISO

Fractional CISO (vCISO) services for New York businesses.

Ownership of the security program — policy, risk, reporting, and the regulator-facing CISO function — from a senior security engineer, at a fraction of what the title commands on a payroll.

A security program is decisions plus evidence

Tools detect. A program decides: which risks are accepted and by whom, what the policies actually require, what gets remediated first with a finite budget, and what leadership is told in writing. Most firms under a few hundred seats own security tools and no program — which is precisely the gap examiners, auditors, and underwriters are trained to find.

A Stedholm vCISO owns that program: writes and maintains a policy set mapped to what you actually run, keeps the risk register, sets the remediation agenda, and reports to your leadership on a fixed cadence. The role rides on whatever operations exist underneath — our security operations, your internal team, or another provider’s stack.

The NYDFS CISO function

23 NYCRR 500 requires every covered entity to designate a CISO responsible for the cybersecurity program, reporting in writing to the board at least annually — and the regulation explicitly permits that function to come from a third-party service provider, provided the firm retains responsibility and designates a senior person to oversee the arrangement. Our vCISO engagements are structured to fit that provision as written.

The work follows the regulation’s calendar: the risk assessment, the April 15 annual certification, the 72-hour incident-notice clock, and the MFA requirements that broadened in November 2025. We prepare and operate controls; we are not a law firm, and the designation itself is a decision to confirm with counsel.

What’s included

  • Security program ownership

    A policy set written for your environment, maintained as it changes, and mapped to the controls that actually exist.

  • Risk register and acceptance

    Risks named, owners assigned, and acceptances signed by the business — not implied by silence.

  • Board and management reporting

    Written, on a cadence, in language a non-engineer can challenge — the NYDFS annual report to the board included.

  • NYDFS Part 500 support

    Certification preparation, control evidence, and the CISO reporting duties — see our Part 500 page for the regime in full.

  • Insurer interface

    Applications and renewals answered from operated controls and dated evidence, not optimism — wrong answers can resurface as coverage disputes.

  • Auditor and questionnaire interface

    SOC 2 readiness, client security questionnaires, and outside-counsel guideline responses, owned by one accountable person.

  • Incident response ownership

    The plan, the tabletop exercises, and the post-incident report — coordinated with business continuity so recovery is rehearsed, not improvised.

The insurer and auditor interface

Security questionnaires are now a revenue function: deals stall on them, renewals reprice on them, and insurance applications can operate as warranties. Answering them accurately takes someone who both knows the controls and is accountable for the answers.

The vCISO answers as the owner of the program — from the risk register, the restore-test reports, and the operated controls. And where the honest answer is no, we say no and propose the remediation, because a euphemism on an application is a liability with a delay on it.

  • Interfaces we staff

  • Cyber-insurance applications and renewals

  • NYDFS certification and examination support

  • SOC 2 readiness and audit fieldwork

  • HIPAA risk analysis reviews

  • Client and outside-counsel questionnaires

  • Due diligence in fundraising or M&A

Common questions

Can Stedholm serve as our NYDFS CISO?

Part 500 permits the CISO function to be filled by a third-party service provider, with your firm retaining responsibility and designating a senior person to oversee it. We structure engagements to fit that provision, including the written board reporting. Confirm the designation with counsel — we are not a law firm, and we will not play one on your filing.

We already have an MSP we like. Does this work alongside them?

Yes — the vCISO function is deliberately separable from day-to-day IT, and some independence between the two has real value: the program owner should be able to assess the operator’s work honestly, including when the operator is us. See how the strategic layer fits.

Is a vCISO enough, or do we also need monitoring?

A program without operations is paperwork; operations without a program is noise. The vCISO sets direction and answers for it — detection and response still have to run somewhere, whether that is our MDR service, your internal team, or an existing stack we assess and keep.

How is this different from a compliance consultant?

A consultant produces a gap assessment and leaves; the gaps become your homework. A vCISO owns closing them — and then answers for the program at the next renewal, the next audit, and the next board meeting. The difference is a name attached to outcomes over time, not a deliverable.

Give the security program an accountable owner.

Talk through your obligations with the engineer who would own the program — before the next certification, renewal, or questionnaire is due.