Cybersecurity Questions, Answered

Straight answers on vCISO services, security frameworks, assessments, and what it looks like to work with Globally Secure IT

Virtual CISO & Engagement Questions

Common questions about what a vCISO does, who needs one, and how engagements work.

What is a vCISO and does my company need one?

A virtual CISO (vCISO) is a fractional Chief Information Security Officer who provides the same executive-level security leadership as a full-time CISO at a fraction of the cost. Companies that benefit most are those in the 50–2,000 employee range that face real compliance or security challenges — regulatory requirements, cyber insurance mandates, board reporting needs, or a recent incident — but don't have the budget or need for a $300,000+ full-time hire. A vCISO can own your security strategy, manage your program, report to your board, and lead your team without the overhead of a full-time executive. Not sure if a vCISO is right for you? Click here to start a conversation.

What is the difference between a vCISO and a cybersecurity consultant?

A cybersecurity consultant typically delivers a defined project — an assessment, a policy, a penetration test — and then moves on. A vCISO is an ongoing leadership relationship. The vCISO owns the security program, sets strategy, reports to the executive team and board, manages vendors, and drives continuous improvement. Think of a consultant as a specialist you bring in for a specific procedure, and a vCISO as your ongoing physician who knows your full history and is accountable for your long-term security health. Click here to discuss which model fits your needs.

How much does a vCISO cost compared to a full-time CISO?

A full-time CISO at a mid-market company typically costs $250,000–$350,000 per year in salary alone, before benefits, bonus, and equity. A vCISO engagement delivers the same executive-level leadership scaled to your actual needs — starting with the First 90 Days engagement, then moving into a monthly retainer tier.

Four ongoing tiers are available after the 90-day onboarding: Sentinel at 8 hours/month (~½ day) for light-touch advisory and roadmap maintenance — ideal for organizations with a capable internal owner and limited budget; Guardian at 20 hours/month (~1 day/week) for active risk management, compliance programs, and monthly board-ready reporting; Defender at 40 hours/month (~2 days/week) for full embedded security leadership across 5–6 domains simultaneously; and Vanguard at 80 hours/month (~4 days/week) for near-CISO presence covering all nine security domains, including board presentations and regulatory liaison. Click here to discuss which tier fits your organization's needs and budget.

What does a cybersecurity engagement look like from start to finish?

Every engagement begins with a structured First 90 Days — approximately 228 hours over 12 weeks — that moves through four phases: Baseline Understanding (weeks 1–2, documentation review, asset inventory, executive alignment); Deep-Dive Assessment (weeks 3–5, technical interviews, gap identification, risk prioritization); Strategic Roadmap (weeks 6–8, a 12–24 month security and modernization roadmap, presented and refined with leadership); and Initial Execution (weeks 9–12, implementing quick wins, establishing KPIs and KRIs, and setting the executive reporting cadence).

After the 90-day engagement, ongoing vCISO services continue through a monthly retainer tier selected based on your organization's size, pace, and program maturity. Domain focus at every tier is driven by your roadmap and risk priorities — reviewed each quarter. Click here to discuss the right scope for your organization.

What deliverables will I receive at the end of an assessment?

A standard assessment delivers: a weekly status report showing accomplishments and next steps; an executive summary with key findings; a detailed technical findings matrix with risk severity, systems impacted, business risk summary, and remediation recommendations; a prioritized remediation roadmap; a CMMI maturity rating; and a management presentation for your executive team or board. For compliance-specific engagements, deliverables also include policy documentation, control catalogs, and gap-to-certification roadmaps. Click here to discuss deliverables specific to your engagement.

Our IT team already handles security. Do we still need a vCISO?

IT and security are related but distinct disciplines. IT teams keep systems running; security programs manage risk, govern access, respond to threats, and satisfy regulatory requirements. When the same team is responsible for both, security priorities consistently lose to operational ones — not because the team is failing, but because uptime is visible and immediate while risk is invisible until it isn't. A vCISO provides the executive ownership, board-level reporting, and strategic accountability that an IT team is not positioned to deliver, while working alongside that team rather than replacing it. Click here to discuss what a vCISO partnership would look like alongside your existing team.

What makes Globally Secure IT different from a large consulting firm?

When you engage Globally Secure IT, you work directly with Fred Hazan — a practitioner with 30+ years of experience across Fortune 500 companies, federal agencies, and mid-market organizations. Fred Hazan is your engagement partner on every project — your direct point of contact, trusted advisor, and accountable principal from start to finish. Large firms sell a brand and a methodology; this practice delivers an experienced principal who has managed $30M federal security budgets, built enterprise-scale IAM programs, and helped organizations reduce quantified breach risk by $830,000 for a single client. Click here to schedule a direct conversation.

Frameworks, Compliance & Assessments

Questions about NIST, CMMC, HIPAA, ISO 27001, and choosing the right framework for your organization.

How long does a NIST CSF 2.0 assessment take?

It depends on the depth of assessment and the size of your organization. A Level 1 Basic Readiness assessment — a self-led survey with IT leads — typically runs 2–4 weeks and produces an initial gap analysis and scorecard. A Level 2 Standard Readiness assessment, which involves consultative interviews with department heads, runs 4–8 weeks and delivers a prioritized action plan and readiness roadmap. A full Tier 2 (Risk-Informed) Assessment with formal documentation takes 2–3 months. For most 100–500 person companies, a Level 2 engagement is the right starting point. Click here to discuss which level fits your situation.

Which cybersecurity framework is right for my company?

The right framework depends on your industry, regulatory environment, and who you sell to. NIST CSF 2.0 is the most widely applicable starting point for any U.S. company. If you sell to the DoD, CMMC 2.0 is mandatory. Healthcare organizations handling patient data need HIPAA compliance. Companies processing credit cards need PCI DSS. Financial institutions typically work within the CRI Profile or FFIEC framework. ISO 27001 is right when global partners require internationally recognized certification. Many companies must satisfy multiple frameworks simultaneously — a well-designed security program addresses them with overlapping controls. Not sure where to start? Click here for a framework selection consultation.

A customer just asked us to prove our security posture. Where do I start?

This is one of the most common triggers for a first security engagement. The fastest path is a NIST CSF 2.0 Level 1 or Level 2 readiness assessment, which produces a documented current-state gap analysis and prioritized action plan in 2–8 weeks. That gives you something concrete to show the customer and a clear roadmap to close the gaps. If the customer requires formal attestation such as SOC 2 or ISO 27001, the timeline is longer — typically 3–6 months to build and document the controls, followed by the formal audit — but the readiness assessment is still the right first step. Click here to start the process.

How do I know if my company is required to comply with CMMC?

CMMC 2.0 applies to any company in the Defense Industrial Base (DIB) that handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). If your company has a DoD contract, or is a subcontractor to a prime that does, review your contract for references to DFARS 252.204-7012 or CUI handling requirements. Non-compliance risks contract loss and legal liability under the False Claims Act.

CMMC Level 1 covers 15 basic safeguarding practices for companies handling FCI. A Level 1 readiness assessment typically runs 2–3 weeks and produces a gap analysis and self-assessment scorecard. Level 1 allows annual self-attestation — no third-party assessment required.

CMMC Level 2 covers 110 practices aligned to NIST SP 800-171 Rev.3 for companies handling CUI. A Level 2 readiness assessment typically runs 4–8 weeks for gap analysis, with 3–9 months for full remediation build depending on current maturity. Level 2 requires a third-party assessment (C3PAO) for most contracts. Globally Secure IT supports Level 1 and Level 2 engagements. Click here to assess your CMMC posture.

What is included in a full NIST CSF 2.0 assessment at Globally Secure IT?

The base NIST CSF 2.0 engagement runs 80 hours across six phases: Discovery (scope confirmation, prior assessment retrieval, document request); Data Gathering and Interview Preparation (evidence collection, framework crosswalk, interview guide development — the largest phase at 19 hours because pre-interview quality determines outcome quality); Interviews (stakeholder sessions across CISO, IT risk, IAM, network, application security, SOC, and BCDR functions); Gap Analysis (all subcategories scored 1–5, year-over-year delta analysis); Remediation Planning and Reporting (executive summary, detailed findings, prioritized roadmap); and Review, Finalize and Conclude (draft review, final delivery, closeout).

The maturity scale is locked at engagement initiation and held constant across annual cycles — this preserves year-over-year comparability and gives regulators and boards a consistent benchmark. Up to 11 supplemental contextual observation tracks can be added for organizations with specific regulatory or technical environments, bringing the maximum engagement to 144 hours. Click here to discuss the right scope for your organization.

What are supplemental contextual observation tracks and do I need them?

Supplemental tracks are structured observation frameworks that run alongside a NIST CSF 2.0 assessment for organizations with specific regulatory obligations or technical environments. Each track adds focused hours distributed across the data gathering, interview, and gap analysis phases, and produces a dedicated findings section in the final report alongside — but clearly separated from — the NIST CSF results.

Eleven tracks are available: NYDFS Part 500 (8 hrs) for NY-chartered or licensed institutions; GLBA Safeguards Rule (6 hrs) for US-regulated financial institutions; CRI / FFIEC (6 hrs) for organizations with FFIEC examination history; SDLC (8 hrs) for organizations that build or customize software; API Security (8 hrs) for organizations operating APIs; TPRM (6 hrs) for organizations with third-party vendor relationships; Cloud Security (6 hrs) for cloud infrastructure environments; GDPR / Data Residency (6 hrs) for organizations handling EU personal data; SWIFT / Payment Controls (4 hrs) for SWIFT participants; Mainframe Security (6 hrs) for mainframe workloads; and AI / ML Security (6 hrs) for organizations using AI or ML operationally.

Important: Supplemental tracks produce contextual observations only. They are not assessments, audits, or compliance determinations against any named framework. A NYDFS track observation is not a NYDFS compliance opinion. A GDPR track observation is not a GDPR audit. This boundary is deliberate — it protects the integrity of the NIST CSF scores and limits liability on both sides. Click here to discuss which tracks apply to your organization.

What is the Program Jumpstart and how does it accelerate security maturity?

The Program Jumpstart bundles a NIST CSF 2.0 assessment with a complete set of foundational security documentation — delivered together in a single coordinated engagement. The bundle includes: a full NIST CSF 2.0 maturity assessment with scored gap analysis and prioritized roadmap; a complete NIST-aligned policy library; standard operating procedures (SOPs); an Incident Response plan; a Business Continuity and Disaster Recovery (BCDR) plan; and a risk register.

The reason this works: most organizations complete a NIST assessment and receive a gap report showing that their documentation is missing or incomplete — policies aren't written, IR plans don't exist, risk registers are informal. The remediation roadmap then says "write the policies" as a future task. The Program Jumpstart delivers the assessment and the documentation simultaneously, so the organization exits the engagement with the artifacts already in place. A client who completes the Program Jumpstart typically enters their ongoing vCISO retainer at a maturity level 3 baseline rather than starting from scratch — compressing what would otherwise be 12–18 months of program build into a single engagement.

The Program Jumpstart is particularly well suited to organizations that are preparing for a compliance audit, responding to a cyber insurance renewal, or onboarding a new vCISO engagement and want to establish a credible, documented security posture quickly. Click here to discuss whether the Program Jumpstart is right for your organization.

Identity, Incidents & Security Architecture

Questions about Zero Trust, PAM, ransomware, incident response, and protecting your most critical assets.

What is Zero Trust and does my organization need it?

Zero Trust is a security architecture built on the principle of "never trust, always verify" — meaning no user, device, or system is automatically trusted just because it's inside your network. Traditional perimeter-based security assumes anything inside the firewall is safe; Zero Trust assumes breach and requires continuous verification of every access request. For most organizations, Zero Trust is not a single product to buy but a journey — starting with strong identity controls (MFA, least-privilege access), then network segmentation, then continuous monitoring. The question is not whether you need Zero Trust, but how far along that journey your current architecture is. Click here to assess your Zero Trust maturity.

We already have identity products. Do we still have an IAM problem?

Probably. Most organizations acquire identity tools reactively — MFA for cyber insurance, PAM because an auditor flagged it, IGA because a vendor recommended it. The result is a collection of products that don't form a coherent program. No one owns the full picture. Access reviews don't happen. Privileged accounts accumulate. Joiners, movers, and leavers aren't managed consistently.

An IAM strategy engagement doesn't touch your products — it assesses what you have, identifies what's missing, and produces a prioritized roadmap. The output answers the question your auditor, insurer, or board is actually asking: do you know who has access to what, and is that access appropriate?

Common triggers: a cyber insurance renewal asking about PAM and MFA coverage; an audit finding that access reviews aren't being performed; a Copilot deployment that exposed over-permissioned accounts; a merger requiring two identity environments to be rationalized; or a Zero Trust initiative that stalled because no one mapped identity first.

If you already have the products and still can't answer those questions, the gap isn't tools — it's governance. Click here to discuss an IAM assessment.

What is a PAM assessment and why does my cyber insurance require it?

Privileged Access Management (PAM) covers the security controls around your most powerful accounts — system administrators, database admins, service accounts, and anyone with elevated permissions. These accounts are the primary target in ransomware and breach scenarios because they allow attackers to move laterally and escalate privileges. Cyber insurers now routinely require evidence of PAM controls — credential vaulting, session monitoring, Just-in-Time access — as a condition of coverage. A PAM readiness assessment evaluates your current controls, identifies gaps, and produces a roadmap to meet both insurance requirements and security best practices. For a mid-size organization, this assessment typically runs 3–5 weeks. Click here to begin your PAM assessment.

We had a security incident. What should we do first?

Immediate priorities are containment and communication — isolate affected systems, preserve evidence, and notify your legal counsel and cyber insurance carrier before making public statements. If you don't have a documented incident response plan, this is the moment when its absence becomes costly. Post-incident, a structured IR plan review and tabletop exercise ensures your team is prepared before the next event. The data is stark: 94% of ransomware attackers target backups, and 66% succeed in corrupting or destroying them. An untested backup and recovery process is not a recovery plan. Click here to build or stress-test your incident response program.

How do I justify a security investment to my CFO or board?

The answer is to stop framing security as cost avoidance and start framing it as a business enabler. There are five ROI engines that move executives: Revenue Acceleration — security eliminates late-stage sales objections and shortens enterprise buying cycles; Market Access — compliance with SOC 2, HIPAA, ISO 27001, or CMMC unlocks markets that are otherwise legally or commercially inaccessible; Operational Velocity — automated identity and access systems free employees for higher-value work; Enterprise Value — security maturity influences valuation during M&A, fundraising, and partnerships, and buyers discount companies with unmanaged cyber risk; and Revenue Protection — reducing the financial impact of incidents that cause direct loss or disruption.

Security framed as "we need to prevent bad things" loses the budget war. "We unlock markets, shorten sales cycles, and protect valuation" wins it. Anchor every investment to a business objective and tie progress to metrics leadership already tracks — average contract value, pipeline eligibility, mean time to detect, and patch latency on critical vulnerabilities. Click here to build your security business case.

Have a Question That Isn't Here?

Every security situation is different. If you're trying to figure out where to start, what you're required to do, or whether a specific service is right for your organization — let's talk directly.