Skip to content
Foxx Cyberfoxxcyber/docs

What it can help with

The kinds of questions vCISO is built for, the positions it holds on common advice, and what it will not do.

The comparison your vCISO works to is not "you versus a security team." It is "you versus nothing at all," which is what most small businesses have. The aim of every conversation is that you finish it knowing something useful you can act on.

Everyday questions

Bring it whatever is worrying you, in your own words. For example:

  • "I got an email asking me to change a supplier's bank details."
  • "A customer is asking if we are secure. What do I tell them?"
  • "Our insurer sent a security questionnaire. How do I answer it?"
  • "Do we even need any of this?"
  • "Could we survive ransomware?"
  • "A new hire starts Monday. What should they get access to?"

Every recommendation comes with its reasoning: the risk it deals with, how likely and how bad that risk is for your business, and what the fix costs in money and disruption. You are making a trade-off, and you cannot make it without the arithmetic.

It will also tell you when something is not worth doing. "This is a real risk and you should accept it" is advice it gives when it is true.

Building your security program

The records build themselves out of your conversations. As you talk, your vCISO:

  • Works out what is worth protecting, by asking how long you could run without each system and what a day without it would cost.
  • Tracks what could go wrong on your risk register, scored by how likely and how bad.
  • Drafts policies in language a new employee could follow.
  • Records decisions, including decisions to leave something alone. Those are the ones people forget they made.
  • Judges where each of the six areas stands.

The six areas are the way it organises a security program:

AreaIn plain words
GovernDeciding who owns this and how much risk you'll carry
IdentifyKnowing what you have and what matters
ProtectKeeping the important things safe
DetectNoticing when something goes wrong
RespondHandling it when it does
RecoverGetting back on your feet

Govern is the one most owners have never thought about, and it is often where your vCISO starts: who owns security decisions, how much risk the business is willing to carry, what contracts or law require of it, and which suppliers can reach its data.

Whether these records are written straight away or wait for your approval is up to you. See You decide.

Positions it holds

Some advice comes up for almost every small business, and your vCISO gives it the same way every time:

  • Passwords for business accounts belong in a business password manager that the business owns, with shared vaults and an admin who can recover access when someone leaves or loses a phone. It names options and what they cost. A browser's built-in password manager is offered only as a fallback, and it will tell you why it is second best.
  • Two-step sign-in goes first on the accounts that move money or hold customer data: email, then accounting and banking, then everything else. Codes from an app or a prompt on your phone beat text messages.
  • Cheap and right beats free and fiddly. When a proper tool costs less than a day of your time and removes a real risk, it recommends the proper tool.

Plain words, with the working one click away

Your vCISO talks without security jargon. You will not be asked to learn a framework to follow its advice.

When your vCISO looks something up in its reference material before writing to your records, it keeps the passages it read. Open What is this based on? under a proposal or a policy to see them, and argue with them if they do not say what it claimed. See You decide.

What it will not do

  • Tell you that you are secure, compliant, or certified. It says what is on file, what is missing, and what it recommends. Compliance and certification are decided by assessors, regulators, and your customers.
  • Give legal advice. It can explain what the question is and what to bring to a lawyer. Whether you must notify anyone after an incident, what a contract requires, or what a regulator expects are questions for that lawyer.
  • Act in your systems. It has no access to your computers, email, or accounts. You, or whoever runs your IT, carry out what you decide.
  • Be your incident response. See In an incident.
  • Help with anything against someone else's systems. Use it for your own business's security only. Do not use it to probe systems you do not own or have permission to test, or to write malicious code or deceptive messages.

If you hold a Department of Defense contract that requires CMMC Level 2, that work has its own home: Bedrock CMMC, built by Foxx Cyber for exactly that. Keep controlled unclassified information out of vCISO.

Last updated September 30, 2026