Virtual CISO · CISO as a Service · London & Home Counties

Security Leadership,
Without the Full-Time Salary

When your business has grown past the point where "IT handles security", a Virtual CISO gives you the senior judgement of a Chief Information Security Officer for a few days a month. Whatever platforms you run on, and whatever your customers and the new Cyber Security and Resilience Bill start asking of you.

📅 Book a Short Call

What you get:

CISSP Certified Lead Consultant
25 Years' Security & Design Experience
Built for 10 to 100 Staff
Platform Independent
Cyber Resilience Bill Ready
Plain English, Always

Senior Security Expertise, Sized to Your Business

A Virtual CISO is an experienced information security leader who works with your business part-time, rather than as a full-time hire.

Large organisations employ a Chief Information Security Officer to decide what needs protecting, how much risk the business is prepared to carry, and what gets fixed first. That judgement is just as valuable at 30 staff as it is at 3,000. The salary is not.

So you engage the expertise, not the employee. A few days a month, scaled to what your organisation actually needs, with the option to increase during a certification push or an incident and dial back afterwards.

Jargon Explained: CISO

Chief Information Security Officer. The senior person accountable for keeping a company's information, systems and people secure. Different from an IT manager, whose job is keeping things running. The CISO decides what "secure enough" means for your business, then makes sure it happens.

Virtual CISO (vCISO)

The most common term. Ongoing, part-time security leadership retained by the month, with an agreed number of days and a clear set of objectives.

Ongoing retainer

Fractional CISO

The same arrangement, described by the fraction of a full-time role you are buying. Popular with finance and professional services firms.

Same thing, different label

CISO as a Service (CISOaaS)

The service-led framing: security leadership delivered as a defined service with agreed outputs, reporting and review cycles rather than a job title.

Defined deliverables

Which do we offer?

All of them. These are three names for one arrangement, and the industry uses them interchangeably. We will not charge you extra for preferring one label over another.

No jargon, or jargon explained

What Your Virtual CISO Actually Does

Not a report and an invoice. A named senior person who owns the security agenda, works through it with you, and reports on it in language your board can act on.

01

Security Strategy & Risk Assessment

We start by establishing what your business actually depends on, what would hurt most if it failed or leaked, and where the genuine exposure sits. That becomes a prioritised roadmap with realistic timescales and costs, written for directors rather than engineers.

The point is to stop security being a series of reactions and start it being a plan you can budget for.

Risk register Prioritised roadmap Budget planning
02

Platform & Cloud Security Review

Most breaches begin with weak configuration or human error rather than sophisticated attacks. We review how your environment is actually set up and harden it to recognised standards, whether that is Microsoft 365, Google Workspace, Azure, on-premises servers, or the hybrid mixture most growing businesses end up with.

Security controls that get in the way get switched off. We aim for protection your staff can live with.

Microsoft 365 Google Workspace Azure On-premises Hybrid
03

Certification & Regulatory Readiness

Cyber Essentials and Cyber Essentials Plus, supported end to end: gap analysis, remediation and submission. Where UK GDPR obligations, ISO 27001 ambitions or sector requirements apply, we translate them into a practical set of actions rather than a policy library nobody reads.

This now includes the Cyber Security and Resilience Bill. We work out whether it reaches you directly or through your customers, then prepare the evidence you will be asked for.

Cyber Essentials Cyber Essentials Plus Cyber Resilience Bill NCSC CAF UK GDPR ISO 27001 readiness
04

Incident Response Planning

A written, rehearsed plan for the day something goes wrong: who decides, who calls whom, what gets isolated, what gets communicated to customers and regulators, and in what order. Tested with a tabletop exercise so the first time you use it is not during a real incident.

Reporting deadlines are tightening. The Cyber Security and Resilience Bill proposes initial notification within 24 hours of becoming aware of a significant incident, with a full report inside 72. A plan that only exists in someone's head will not meet that.

Response plan Tabletop exercise 24 & 72 hour reporting Breach notification
05

Board Reporting & Customer Assurance

Straightforward updates for your leadership team showing what has changed, what it cost and what remains. Just as importantly, credible answers to the security questionnaires that customers, insurers and prospects increasingly send before they will sign.

For many SMEs this is the point where security stops being a cost and starts winning contracts.

Board packs Supplier questionnaires Insurer evidence Due diligence
06

Staff Awareness & Supplier Risk

Practical training that helps your people recognise the attacks they will actually see, without lecturing them. Plus a sensible view of the third parties who hold your data or connect to your systems, because your security is only as strong as the suppliers you have given access to.

Supply chain assurance is becoming a legal duty rather than good practice. Under the Cyber Security and Resilience Bill, regulated organisations must actively manage supplier risk, and those requirements pass down the chain through contracts.

Phishing awareness Policy that people read Third-party risk Supply chain assurance

The Cyber Security and Resilience Bill

The biggest change to UK cyber security law in nearly a decade is currently going through Parliament. Most SMEs are not directly regulated by it. Almost all of them will feel it anyway.

The Cyber Security and Resilience (Network and Information Systems) Bill updates the NIS Regulations 2018 and widens who is legally accountable for cyber resilience in the UK.

It was introduced to the Commons on 12 November 2025, cleared all its Commons stages, and passed to the House of Lords on 17 June 2026. It is expected to receive Royal Assent during 2026, with obligations phased in over the following period. Because it is still before Parliament, the detail can change, and we will keep this page current as it does.

As drafted, the Bill brings larger managed service providers, data centres and designated critical suppliers directly into scope for the first time. Micro and small enterprises are excluded from the managed service provider category, and the Government estimates the change captures somewhere between 900 and 1,100 providers nationally. The Bill also introduces a two-stage incident reporting duty, places supply chain risk management on a statutory footing, and replaces the old flat penalty cap with turnover-linked fines.

Jargon Explained: The NIS Regulations

The Network and Information Systems Regulations 2018 are the UK rules that require operators of essential services, such as energy, water, health and transport, to manage cyber risk and report serious incidents. The new Bill updates and extends them rather than replacing them.

"If your business is not in scope, your customers may well be. Their obligations become your contract terms."

Who is directly in scope

Operators of essential services, relevant digital service providers, larger managed service providers, designated critical suppliers, large data centres and large load controllers. Micro and small enterprises are generally excluded, so most businesses of 10 to 100 staff are not on this list.

Directly regulated

Who feels it indirectly

Everyone who supplies, or is supplied by, someone in scope. Regulated organisations must actively manage supply chain risk, which means tighter contract clauses, deeper due diligence and more detailed security questionnaires flowing down to their suppliers.

Most UK SMEs

The exception worth knowing

Size is a baseline, not a permanent exemption. Regulators would gain powers to designate any supplier as critical, regardless of how small it is, where disruption to that supplier could significantly affect an essential or digital service. A very small business in the wrong supply chain can still be pulled in.

Critical supplier designation

What changes in practice

A two-stage incident reporting duty, initial notification within 24 hours and a full report within 72. Proactive risk management aligned to the NCSC Cyber Assessment Framework. Duties to inform customers where an incident is likely to affect them.

New duties

Where we sit, plainly

Gibberish is a micro MSP, and the Bill's definition of a regulated managed service provider excludes micro and small enterprises. So we are not directly in scope, and we will not pretend otherwise in order to sell you something.

We work to the standard anyway. When your regulated customers run supply chain due diligence, they look at your IT provider as well as at you, and we would rather answer those questions than dodge them.

Honest about our own position

A note on proportion, and on scare tactics

You will see a great deal of marketing quoting the headline penalties in this Bill, which run to the greater of £17 million or 4% of worldwide turnover for the most serious failures. Those figures are real, but they apply to regulated organisations, and micro and small enterprises are generally excluded from the categories that are regulated. We would rather tell you plainly where you actually stand than sell you compliance you do not need. If the Bill genuinely does not reach you, we will say so, as we have about ourselves above.

What a Virtual CISO does about it

  • Establishes honestly whether the Bill reaches your organisation directly, through the critical supplier route, or through your customers and contracts
  • Maps your position against the NCSC Cyber Assessment Framework, the reference point regulators are expected to use
  • Builds the evidence base that customer due diligence and contract clauses will increasingly demand
  • Puts a two-stage incident reporting process in place that can genuinely meet a 24 hour clock, and rehearses it
  • Reviews your own supply chain, because the same duties that reach you will reach the suppliers you depend on
  • Uses Cyber Essentials as the practical first step, since its controls map closely onto what the Bill expects
  • Reports the position to your board in terms they can act on, ahead of the deadline rather than after it

Why a Micro MSP, Not a Large One

We are deliberately small. That is not a limitation we are apologising for, it is the reason our clients get senior attention. Here is the honest case, including where it does not apply.

👤

A person, not a queue

In a tiered support model, first-line staff are generalists working from scripts and predefined troubleshooting steps, and they handle roughly 70 to 80% of all tickets. Specialists are reached by escalation.

That model is efficient at scale. It also means most of your contact is with someone who has never seen your systems before. With us, the person who answers already knows your environment, because they built it.

🎓

The same qualifications

CISSP is awarded to individuals by ISC2, not to companies. A large firm cannot hold one. It employs people who do, and you may or may not get access to them.

Cyber Essentials works the same way. It is one NCSC scheme with one set of controls, assessed identically whoever guides you through it. Buying it from a bigger provider does not buy a better certificate.

💰

Fewer layers between your fee and the work

A large provider's price carries a sales team, account management, marketing, offices, middle management, and where the firm is investor-backed, a required rate of return.

None of that reaches your network. We are not claiming to be the cheapest hourly rate on the market, because senior time is not cheap. We are saying a larger share of what you pay buys actual work.

🔍

Time to find the cause

One of the most common complaints about managed providers is not slow response, it is problems that keep coming back. Ticket volume and time pressure push technicians towards the quickest fix that closes the ticket, which is efficient today and creates a fragile environment over time.

Carrying fewer clients is what makes root cause analysis affordable for us. It is why our clients tend to raise fewer tickets over time, not more.

🏢

We are not being acquired

The managed services sector is in the middle of the most active consolidation cycle in its history. Around 466 MSP acquisitions closed across North America in 2025, up roughly 20% on the previous year, with private equity involved in about 69% of disclosed deals. The UK market is following the same pattern, with investor-backed buy-and-build strategies actively rolling up smaller providers.

For clients, that often means a long-standing account manager replaced by a central service desk, and a bespoke arrangement migrated onto a standard tier. We are owner-run and not for sale.

🔒

Familiarity is a security control

A large share of successful attacks on SMEs rely on impersonation: a convincing email or call requesting a password reset, a payment change, or access for a new starter.

A provider who knows your voice, your staff and your normal way of working is a genuine control against that, and one no tooling replicates. At a large provider, whoever picks up the phone is meeting you for the first time.

When a larger provider is the better answer

We would rather tell you this now than six months into a contract that was never going to fit. A larger provider is genuinely the better choice if you need a staffed 24/7 security operations centre with eyes on screens overnight, if you are running several hundred users across multiple countries and time zones, if you need a large team mobilised for a fixed-date migration, or if your procurement rules require a supplier of a certain size or turnover.

Our service is built for organisations of roughly 10 to 100 staff who want senior expertise and a named individual who knows them. If that is not you, we will say so and, where we can, point you somewhere better suited.

Sector figures above are drawn from published 2025 and 2026 managed services M&A analysis, including Drake Star and Omdia deal tracking, and UK market commentary from Moore Kingston Smith and HMT. Support tier proportions reflect widely published industry service desk benchmarks.

CISSP
Certified lead consultant
25
Years of security & design experience
10–100
Staff: the size we are built for
20+
Years supporting UK small businesses

A Named Individual, Not an Account Number

Our Virtual CISO service is led by Gibberish's Lead Consultant, a CISSP with 25 years of security and design experience. You deal with that person directly. They learn your business, sit in your meetings, and are accountable for the advice they give you.

Behind them sits the wider Gibberish team, so strategy and hands-on delivery come from the same place. When the roadmap says something needs configuring, migrating or remediating, we do it rather than handing you a list.

CISSP
Certified
25
Years' experience
1
Point of contact

Jargon Explained: CISSP

Certified Information Systems Security Professional. The most widely recognised senior security qualification in the world, awarded by (ISC)². It requires several years of proven, hands-on experience in multiple security domains, an endorsement from an existing holder, and ongoing education to retain. It is not a weekend course.

Senior security consultant meeting with a small business leadership team in London

Built for Businesses of 10 to 100 Staff

There is an awkward middle stage where a business is too big to leave security to chance and too small to justify a security hire. That is exactly who this service is for. It tends to be a good fit if you recognise several of these:

  • Customers, insurers or prospects are sending security questionnaires you cannot confidently complete
  • You need Cyber Essentials or Cyber Essentials Plus to win or retain contracts
  • Your systems have grown organically and nobody has stood back to check they are set up securely
  • You know you should have an incident response plan, but nothing is written down
  • Your board has started asking about cyber risk and nobody owns the answer
  • You have good IT support, but no one holding the security strategy
  • You have read about the Cyber Security and Resilience Bill and cannot tell whether it applies to you
  • A full-time security hire cannot be justified, but having nobody no longer can either

What Hiring Instead Looks Like

A full-time CISO in the UK commands a six-figure salary before you add employer's National Insurance, pension, recruitment fees and the months it takes to fill the role. For a business of 40 people, that is rarely proportionate to the risk being managed.

A Virtual CISO gives you the same seniority for an agreed number of days a month. You can increase it during a certification push or an incident, and reduce it once things are steady.

"You are buying judgement and accountability, not headcount. The right question is not 'can we afford a CISO', it is 'what does an unmanaged breach cost us'."

📅 Book a Short Call

Assess. Prioritise. Deliver.

The same principle as every Gibberish engagement: we assess before we advise, and we deliver rather than just recommend.

01

Baseline Assessment

A structured review of your systems, data, suppliers and regulatory obligations, including a Cyber Essentials gap analysis and a view on whether the Cyber Security and Resilience Bill reaches you. Both sides get an honest picture before anyone commits to a programme of work.

02

Agreed Roadmap

A prioritised plan with owners, timescales and costs, signed off by your leadership team. You decide the pace. Nothing happens because a framework said so.

03

Ongoing Leadership

Regular days on your business: driving the roadmap, answering questionnaires, reporting to the board, and adjusting as your business and the threat landscape change.

See Our Full Onboarding Process

Virtual CISO Questions, Answered

The questions we are asked most often before a first conversation.

What is the difference between a Virtual CISO, a fractional CISO and CISO as a Service?

+

In practice, very little. Virtual CISO, vCISO, fractional CISO, outsourced CISO and CISO as a Service all describe the same arrangement: experienced security leadership delivered part-time rather than as a full-time employee.

Different providers prefer different labels, and some attach slightly different packaging to each. We offer the arrangement, whichever name you arrived with.

We already have IT support. Do we need this as well?

+

They are different jobs. IT support keeps systems running and fixes what breaks. A CISO decides what needs protecting, how much risk the business is willing to carry, which controls are worth the money, and what gets done first.

Plenty of businesses have perfectly good IT support and nobody holding the security strategy. That gap tends to show up the first time a large customer sends a security questionnaire.

How much does a Virtual CISO cost?

+

It depends on the number of days a month and what you need delivered, so we scope it properly rather than quoting a headline figure. What we can say is that it is a small fraction of a full-time CISO, who in the UK commands a six-figure salary before employer's National Insurance, pension and recruitment costs.

Engagements typically start with a fixed-price baseline assessment so you can see the scale of the work before committing to a retainer.

Does this only work if we run Microsoft 365?

+

No. The role is platform independent. We work across Microsoft 365, Google Workspace, Azure, on-premises servers, and the hybrid environments most growing businesses actually have.

We are experienced Microsoft specialists, so if you are a Microsoft business you will find that depth useful. But the security strategy comes first and the platform follows, not the other way round.

How quickly can you help with a customer security questionnaire?

+

Quickly. Supplier assurance questionnaires are one of the most common reasons businesses first contact us, usually with a deadline attached.

We can normally help you answer one honestly and credibly within days, then use the gaps it exposes as the starting point for a longer term plan. Answering it accurately matters more than answering it well: overstating your controls in writing to a customer creates a much bigger problem later.

Does the Cyber Security and Resilience Bill apply to my business?

+

Probably not directly, if you are a typical business of 10 to 100 staff. As drafted, the Bill regulates operators of essential services, relevant digital service providers, larger managed service providers, designated critical suppliers, large data centres and large load controllers. Micro and small enterprises are generally excluded from these categories.

The more likely route is indirect. Regulated organisations have to manage risk across their supply chains, so if you sell to, or depend on, anyone in scope, their obligations will reach you through contract clauses and due diligence questionnaires. That is how most SMEs will first encounter this Bill.

There is one exception worth knowing. Regulators would be able to designate any supplier as critical, whatever its size, where disruption to it could significantly affect an essential or digital service. Being small is a baseline exemption rather than a guarantee.

Working out which of those applies to you is a short piece of work, and worth doing before a customer asks.

When does the Bill actually come into force?

+

It is not law yet. The Bill was introduced on 12 November 2025, completed its Commons stages, and moved to the House of Lords on 17 June 2026. Royal Assent is widely expected during 2026, with duties phased in afterwards as regulators publish sector guidance.

Because it is still before Parliament, the detail can change. We would treat anyone quoting fixed compliance deadlines today with some caution. What is not in doubt is the direction of travel, which is why preparation is sensible now even though the deadline is not fixed.

What should we do about it first?

+

Establish honestly whether you are in scope, directly or through your customers. Then work on the things that are useful regardless of the answer: Cyber Essentials certification, an incident response plan that could realistically meet a 24 hour notification clock, a current picture of who your suppliers are and what access they hold, and evidence you can hand to a customer without rewriting it each time.

None of that is wasted effort even if the Bill never touches you directly. It is the same work that wins contracts and satisfies insurers.

Aren't you too small to look after us?

+

It is a fair question, and the honest answer depends on what you need. If you require a staffed 24/7 security operations centre, or support for several hundred users across multiple time zones, a larger provider is the better fit and we will tell you so.

For an organisation of 10 to 100 staff, being small is usually the advantage. CISSP is held by individuals rather than firms, so the qualification is the same wherever it sits. Cyber Essentials is one NCSC scheme assessed identically whoever guides you through it. What differs is who actually turns up: at a larger provider, first-line staff handle most tickets from scripts, and specialists are reached by escalation.

There is also a stability argument. The managed services sector is consolidating rapidly, with private equity backed groups acquiring smaller providers and migrating their clients onto standard service tiers. We are owner-run and not for sale.

Is there a long contract?

+

No. We would rather you stayed because the work is worth it. Engagements are reviewed regularly and the number of days can go up during a certification push or an incident and back down when things are steady.

Where are you based and do you work on site?

+

We are based in London and work with businesses across London and the Home Counties, including Surrey, Kent, Essex, Hertfordshire and Berkshire. A Virtual CISO engagement usually mixes on-site days for workshops, board sessions and assessments with remote work for everything else.

Works Well Alongside

A Virtual CISO sets the direction. These are the services that most often deliver against it.

Get Started

Find Out Where You Actually Stand

A short call costs nothing and gives you an honest view of your security position, including whether the Cyber Security and Resilience Bill is likely to reach you. Whether or not a Virtual CISO turns out to be the right answer for you.

📅 Book a Short Call Email Us Cyber Essentials