When your business has grown past the point where "IT handles security", a Virtual CISO gives you the senior judgement of a Chief Information Security Officer for a few days a month. Whatever platforms you run on, and whatever your customers and the new Cyber Security and Resilience Bill start asking of you.
📅 Book a Short CallA Virtual CISO is an experienced information security leader who works with your business part-time, rather than as a full-time hire.
Large organisations employ a Chief Information Security Officer to decide what needs protecting, how much risk the business is prepared to carry, and what gets fixed first. That judgement is just as valuable at 30 staff as it is at 3,000. The salary is not.
So you engage the expertise, not the employee. A few days a month, scaled to what your organisation actually needs, with the option to increase during a certification push or an incident and dial back afterwards.
Chief Information Security Officer. The senior person accountable for keeping a company's information, systems and people secure. Different from an IT manager, whose job is keeping things running. The CISO decides what "secure enough" means for your business, then makes sure it happens.
The most common term. Ongoing, part-time security leadership retained by the month, with an agreed number of days and a clear set of objectives.
Ongoing retainerThe same arrangement, described by the fraction of a full-time role you are buying. Popular with finance and professional services firms.
Same thing, different labelThe service-led framing: security leadership delivered as a defined service with agreed outputs, reporting and review cycles rather than a job title.
Defined deliverablesAll of them. These are three names for one arrangement, and the industry uses them interchangeably. We will not charge you extra for preferring one label over another.
No jargon, or jargon explainedNot a report and an invoice. A named senior person who owns the security agenda, works through it with you, and reports on it in language your board can act on.
We start by establishing what your business actually depends on, what would hurt most if it failed or leaked, and where the genuine exposure sits. That becomes a prioritised roadmap with realistic timescales and costs, written for directors rather than engineers.
The point is to stop security being a series of reactions and start it being a plan you can budget for.
Most breaches begin with weak configuration or human error rather than sophisticated attacks. We review how your environment is actually set up and harden it to recognised standards, whether that is Microsoft 365, Google Workspace, Azure, on-premises servers, or the hybrid mixture most growing businesses end up with.
Security controls that get in the way get switched off. We aim for protection your staff can live with.
Cyber Essentials and Cyber Essentials Plus, supported end to end: gap analysis, remediation and submission. Where UK GDPR obligations, ISO 27001 ambitions or sector requirements apply, we translate them into a practical set of actions rather than a policy library nobody reads.
This now includes the Cyber Security and Resilience Bill. We work out whether it reaches you directly or through your customers, then prepare the evidence you will be asked for.
A written, rehearsed plan for the day something goes wrong: who decides, who calls whom, what gets isolated, what gets communicated to customers and regulators, and in what order. Tested with a tabletop exercise so the first time you use it is not during a real incident.
Reporting deadlines are tightening. The Cyber Security and Resilience Bill proposes initial notification within 24 hours of becoming aware of a significant incident, with a full report inside 72. A plan that only exists in someone's head will not meet that.
Straightforward updates for your leadership team showing what has changed, what it cost and what remains. Just as importantly, credible answers to the security questionnaires that customers, insurers and prospects increasingly send before they will sign.
For many SMEs this is the point where security stops being a cost and starts winning contracts.
Practical training that helps your people recognise the attacks they will actually see, without lecturing them. Plus a sensible view of the third parties who hold your data or connect to your systems, because your security is only as strong as the suppliers you have given access to.
Supply chain assurance is becoming a legal duty rather than good practice. Under the Cyber Security and Resilience Bill, regulated organisations must actively manage supplier risk, and those requirements pass down the chain through contracts.
The biggest change to UK cyber security law in nearly a decade is currently going through Parliament. Most SMEs are not directly regulated by it. Almost all of them will feel it anyway.
The Cyber Security and Resilience (Network and Information Systems) Bill updates the NIS Regulations 2018 and widens who is legally accountable for cyber resilience in the UK.
It was introduced to the Commons on 12 November 2025, cleared all its Commons stages, and passed to the House of Lords on 17 June 2026. It is expected to receive Royal Assent during 2026, with obligations phased in over the following period. Because it is still before Parliament, the detail can change, and we will keep this page current as it does.
As drafted, the Bill brings larger managed service providers, data centres and designated critical suppliers directly into scope for the first time. Micro and small enterprises are excluded from the managed service provider category, and the Government estimates the change captures somewhere between 900 and 1,100 providers nationally. The Bill also introduces a two-stage incident reporting duty, places supply chain risk management on a statutory footing, and replaces the old flat penalty cap with turnover-linked fines.
The Network and Information Systems Regulations 2018 are the UK rules that require operators of essential services, such as energy, water, health and transport, to manage cyber risk and report serious incidents. The new Bill updates and extends them rather than replacing them.
"If your business is not in scope, your customers may well be. Their obligations become your contract terms."
Operators of essential services, relevant digital service providers, larger managed service providers, designated critical suppliers, large data centres and large load controllers. Micro and small enterprises are generally excluded, so most businesses of 10 to 100 staff are not on this list.
Directly regulatedEveryone who supplies, or is supplied by, someone in scope. Regulated organisations must actively manage supply chain risk, which means tighter contract clauses, deeper due diligence and more detailed security questionnaires flowing down to their suppliers.
Most UK SMEsSize is a baseline, not a permanent exemption. Regulators would gain powers to designate any supplier as critical, regardless of how small it is, where disruption to that supplier could significantly affect an essential or digital service. A very small business in the wrong supply chain can still be pulled in.
Critical supplier designationA two-stage incident reporting duty, initial notification within 24 hours and a full report within 72. Proactive risk management aligned to the NCSC Cyber Assessment Framework. Duties to inform customers where an incident is likely to affect them.
New dutiesGibberish is a micro MSP, and the Bill's definition of a regulated managed service provider excludes micro and small enterprises. So we are not directly in scope, and we will not pretend otherwise in order to sell you something.
We work to the standard anyway. When your regulated customers run supply chain due diligence, they look at your IT provider as well as at you, and we would rather answer those questions than dodge them.
Honest about our own positionYou will see a great deal of marketing quoting the headline penalties in this Bill, which run to the greater of £17 million or 4% of worldwide turnover for the most serious failures. Those figures are real, but they apply to regulated organisations, and micro and small enterprises are generally excluded from the categories that are regulated. We would rather tell you plainly where you actually stand than sell you compliance you do not need. If the Bill genuinely does not reach you, we will say so, as we have about ourselves above.
We are deliberately small. That is not a limitation we are apologising for, it is the reason our clients get senior attention. Here is the honest case, including where it does not apply.
In a tiered support model, first-line staff are generalists working from scripts and predefined troubleshooting steps, and they handle roughly 70 to 80% of all tickets. Specialists are reached by escalation.
That model is efficient at scale. It also means most of your contact is with someone who has never seen your systems before. With us, the person who answers already knows your environment, because they built it.
CISSP is awarded to individuals by ISC2, not to companies. A large firm cannot hold one. It employs people who do, and you may or may not get access to them.
Cyber Essentials works the same way. It is one NCSC scheme with one set of controls, assessed identically whoever guides you through it. Buying it from a bigger provider does not buy a better certificate.
A large provider's price carries a sales team, account management, marketing, offices, middle management, and where the firm is investor-backed, a required rate of return.
None of that reaches your network. We are not claiming to be the cheapest hourly rate on the market, because senior time is not cheap. We are saying a larger share of what you pay buys actual work.
One of the most common complaints about managed providers is not slow response, it is problems that keep coming back. Ticket volume and time pressure push technicians towards the quickest fix that closes the ticket, which is efficient today and creates a fragile environment over time.
Carrying fewer clients is what makes root cause analysis affordable for us. It is why our clients tend to raise fewer tickets over time, not more.
The managed services sector is in the middle of the most active consolidation cycle in its history. Around 466 MSP acquisitions closed across North America in 2025, up roughly 20% on the previous year, with private equity involved in about 69% of disclosed deals. The UK market is following the same pattern, with investor-backed buy-and-build strategies actively rolling up smaller providers.
For clients, that often means a long-standing account manager replaced by a central service desk, and a bespoke arrangement migrated onto a standard tier. We are owner-run and not for sale.
A large share of successful attacks on SMEs rely on impersonation: a convincing email or call requesting a password reset, a payment change, or access for a new starter.
A provider who knows your voice, your staff and your normal way of working is a genuine control against that, and one no tooling replicates. At a large provider, whoever picks up the phone is meeting you for the first time.
We would rather tell you this now than six months into a contract that was never going to fit. A larger provider is genuinely the better choice if you need a staffed 24/7 security operations centre with eyes on screens overnight, if you are running several hundred users across multiple countries and time zones, if you need a large team mobilised for a fixed-date migration, or if your procurement rules require a supplier of a certain size or turnover.
Our service is built for organisations of roughly 10 to 100 staff who want senior expertise and a named individual who knows them. If that is not you, we will say so and, where we can, point you somewhere better suited.
Sector figures above are drawn from published 2025 and 2026 managed services M&A analysis, including Drake Star and Omdia deal tracking, and UK market commentary from Moore Kingston Smith and HMT. Support tier proportions reflect widely published industry service desk benchmarks.
Our Virtual CISO service is led by Gibberish's Lead Consultant, a CISSP with 25 years of security and design experience. You deal with that person directly. They learn your business, sit in your meetings, and are accountable for the advice they give you.
Behind them sits the wider Gibberish team, so strategy and hands-on delivery come from the same place. When the roadmap says something needs configuring, migrating or remediating, we do it rather than handing you a list.
Certified Information Systems Security Professional. The most widely recognised senior security qualification in the world, awarded by (ISC)². It requires several years of proven, hands-on experience in multiple security domains, an endorsement from an existing holder, and ongoing education to retain. It is not a weekend course.
There is an awkward middle stage where a business is too big to leave security to chance and too small to justify a security hire. That is exactly who this service is for. It tends to be a good fit if you recognise several of these:
A full-time CISO in the UK commands a six-figure salary before you add employer's National Insurance, pension, recruitment fees and the months it takes to fill the role. For a business of 40 people, that is rarely proportionate to the risk being managed.
A Virtual CISO gives you the same seniority for an agreed number of days a month. You can increase it during a certification push or an incident, and reduce it once things are steady.
"You are buying judgement and accountability, not headcount. The right question is not 'can we afford a CISO', it is 'what does an unmanaged breach cost us'."
The same principle as every Gibberish engagement: we assess before we advise, and we deliver rather than just recommend.
The questions we are asked most often before a first conversation.
In practice, very little. Virtual CISO, vCISO, fractional CISO, outsourced CISO and CISO as a Service all describe the same arrangement: experienced security leadership delivered part-time rather than as a full-time employee.
Different providers prefer different labels, and some attach slightly different packaging to each. We offer the arrangement, whichever name you arrived with.
They are different jobs. IT support keeps systems running and fixes what breaks. A CISO decides what needs protecting, how much risk the business is willing to carry, which controls are worth the money, and what gets done first.
Plenty of businesses have perfectly good IT support and nobody holding the security strategy. That gap tends to show up the first time a large customer sends a security questionnaire.
It depends on the number of days a month and what you need delivered, so we scope it properly rather than quoting a headline figure. What we can say is that it is a small fraction of a full-time CISO, who in the UK commands a six-figure salary before employer's National Insurance, pension and recruitment costs.
Engagements typically start with a fixed-price baseline assessment so you can see the scale of the work before committing to a retainer.
No. The role is platform independent. We work across Microsoft 365, Google Workspace, Azure, on-premises servers, and the hybrid environments most growing businesses actually have.
We are experienced Microsoft specialists, so if you are a Microsoft business you will find that depth useful. But the security strategy comes first and the platform follows, not the other way round.
Quickly. Supplier assurance questionnaires are one of the most common reasons businesses first contact us, usually with a deadline attached.
We can normally help you answer one honestly and credibly within days, then use the gaps it exposes as the starting point for a longer term plan. Answering it accurately matters more than answering it well: overstating your controls in writing to a customer creates a much bigger problem later.
Probably not directly, if you are a typical business of 10 to 100 staff. As drafted, the Bill regulates operators of essential services, relevant digital service providers, larger managed service providers, designated critical suppliers, large data centres and large load controllers. Micro and small enterprises are generally excluded from these categories.
The more likely route is indirect. Regulated organisations have to manage risk across their supply chains, so if you sell to, or depend on, anyone in scope, their obligations will reach you through contract clauses and due diligence questionnaires. That is how most SMEs will first encounter this Bill.
There is one exception worth knowing. Regulators would be able to designate any supplier as critical, whatever its size, where disruption to it could significantly affect an essential or digital service. Being small is a baseline exemption rather than a guarantee.
Working out which of those applies to you is a short piece of work, and worth doing before a customer asks.
It is not law yet. The Bill was introduced on 12 November 2025, completed its Commons stages, and moved to the House of Lords on 17 June 2026. Royal Assent is widely expected during 2026, with duties phased in afterwards as regulators publish sector guidance.
Because it is still before Parliament, the detail can change. We would treat anyone quoting fixed compliance deadlines today with some caution. What is not in doubt is the direction of travel, which is why preparation is sensible now even though the deadline is not fixed.
Establish honestly whether you are in scope, directly or through your customers. Then work on the things that are useful regardless of the answer: Cyber Essentials certification, an incident response plan that could realistically meet a 24 hour notification clock, a current picture of who your suppliers are and what access they hold, and evidence you can hand to a customer without rewriting it each time.
None of that is wasted effort even if the Bill never touches you directly. It is the same work that wins contracts and satisfies insurers.
It is a fair question, and the honest answer depends on what you need. If you require a staffed 24/7 security operations centre, or support for several hundred users across multiple time zones, a larger provider is the better fit and we will tell you so.
For an organisation of 10 to 100 staff, being small is usually the advantage. CISSP is held by individuals rather than firms, so the qualification is the same wherever it sits. Cyber Essentials is one NCSC scheme assessed identically whoever guides you through it. What differs is who actually turns up: at a larger provider, first-line staff handle most tickets from scripts, and specialists are reached by escalation.
There is also a stability argument. The managed services sector is consolidating rapidly, with private equity backed groups acquiring smaller providers and migrating their clients onto standard service tiers. We are owner-run and not for sale.
No. We would rather you stayed because the work is worth it. Engagements are reviewed regularly and the number of days can go up during a certification push or an incident and back down when things are steady.
We are based in London and work with businesses across London and the Home Counties, including Surrey, Kent, Essex, Hertfordshire and Berkshire. A Virtual CISO engagement usually mixes on-site days for workshops, board sessions and assessments with remote work for everything else.
A Virtual CISO sets the direction. These are the services that most often deliver against it.
A short call costs nothing and gives you an honest view of your security position, including whether the Cyber Security and Resilience Bill is likely to reach you. Whether or not a Virtual CISO turns out to be the right answer for you.
📅 Book a Short Call Email Us Cyber Essentials