Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →A vCISO, or virtual or fractional Chief Information Security Officer, is an experienced security executive who runs your security program on a part-time or contract basis instead of as a full-time hire. The vCISO owns policies, controls, risk decisions, audits, and board reporting. It gives a company executive security leadership without a six-figure salary.
A vCISO is the named person on customer security questionnaires, in regulator correspondence, and in the board deck. That accountability is often the actual deliverable buyers and auditors care about.
The model fits companies that have outgrown ad hoc security but cannot justify a full-time CISO yet. The vCISO sets the program direction and cadence, then hands day-to-day execution to internal staff or specialist partners.
traztech delivers fractional CISO leadership for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.
A vCISO usually enters at one of three moments: an enterprise deal has stalled on security questions, an investor has asked who owns security, or an incident has made the absence of an owner obvious.
The work in the first ninety days is rarely technical. It is establishing what you actually have, deciding what the next two quarters should cover, and putting a name against every control so that things run on a schedule rather than when somebody remembers.
A consultant delivers a piece of work and leaves. A vCISO holds the role: they are accountable for the programme, attend the buyer calls, own the roadmap and answer for it over time.
For most companies below a hundred people, a few days a month is enough to hold the programme together, with more during an audit or after an incident.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
Before you go
Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.