Skip to content
Macksofy Technologies
Fractional CISO · India + GCC · Board-Ready

Virtual CISO Services in India & UAE.

An experienced CISO embedded in your leadership team on a fractional basis — 1, 2 or 4 days a week. Sets policy, owns risk register, presents to the board, manages regulators, mentors your in-house team and stays accountable to outcomes, not hours billed.

15–22 yrs
vCISO experience
1 · 2 · 4
days per week
12 mo
minimum engagement
48h
proposal after discovery
In short

What is a vCISO?

A vCISO (virtual CISO) is an on-demand senior security leader who sets strategy, owns your risk and compliance posture, and reports to the board — without a full-time hire. Macksofy provides CISSP/CISM-certified vCISOs who satisfy the RBI and SEBI requirement for a named, independent security head.

Engagement shapes

Fractional is the day count. Not the seniority.

Every Macksofy vCISO has held an in-house CISO or Deputy CISO role at a regulated firm. You meet the named individual before you sign, and they report into your CEO or COO — not back into us.

1 day / week
Governance floor

Seed to Series-B, first enterprise deals, first certification.

  • Policy stack drafted and owned
  • Risk register established and maintained
  • Board or investor reporting each quarter
  • Certification programme steered (ISO 27001, SOC 2)
2 days / week
Active programme

Series-C onward, a small in-house team, live audit cycles.

  • Everything in the 1-day plan
  • Monthly risk committee chaired
  • Security team mentoring and hiring support
  • Architecture review on every material change
4 days / week
Interim or regulated

Regulated firms, M&A diligence, cover during a CISO transition.

  • Everything in the 2-day plan
  • Regulator inspection response led end to end
  • Incident command with DFIR under the same contract
  • Structured handover to the incoming full-time CISO
The calendar

Not an advisor who emails recommendations.

The difference between a consultant and a CISO is accountability that recurs. Here is what recurs.

  • C-level security leadership at 25–40% of the fully-loaded in-house cost
  • Board + risk-committee reporting handled by someone who has done it before
  • Regulator-facing interlocutor (CERT-In · RBI · SEBI · DPDP Authority · DESC / NCA in GCC)
  • Mentorship pipeline for your in-house engineers (career-ladder, training plan)
  • Continuity through founder departures, fundraises and M&A diligence
Operating rhythm · 1, 2 or 4 days a week
Reports to your CEO or COO, not to us
Weekly
  • Leadership stand-up, in your calendar not ours
  • Architecture review on every material change
  • Security-team 1:1s and mentoring
  • Vendor and third-party risk decisions
Monthly
  • Risk-committee meeting, chaired
  • Risk register reviewed and signed off
  • KRI / KPI pack against agreed thresholds
  • Remediation-progress escalation where it has stalled
Quarterly
  • Board pack: trend chart, top risks, regulator status, hiring plan
  • Policy-stack review against what actually changed
  • Audit and certification readiness checkpoint
  • Budget re-forecast
Annual
  • Maturity reassessment against NIST CSF and ISO 27001
  • Twelve-month strategy and budget refreshed for board sign-off
  • Audit-readiness sign-off
  • Succession planning toward a full-time hire, where that is the goal
And whenever it goes wrong
  • Incident Commander during High and Critical events
  • Breach communications and regulator notification
  • Macksofy DFIR forensics pulled in under the same contract
Regulator-facing

Someone who has sat in that room before.

An inspection is a bad time to learn how an inspection goes. The vCISO is your named interlocutor across the Indian and GCC regulators that apply to your licence.

Regulator interlocutor · India + GCC
India GCC
CERT-In
Indian Computer Emergency Response Team, MeitY

Incident reporting under the 2022 directions, log retention, and an annual audit by an empanelled organisation.

RBI
Reserve Bank of India

Cyber-security framework compliance, System Audit reporting, and board-level oversight for regulated entities.

SEBI
Securities and Exchange Board of India

CSCRF alignment for market intermediaries, with periodic audit evidence and governance sign-off.

IRDAI
Insurance Regulatory and Development Authority of India

Information and cyber-security guidelines for insurers, with inspection response and observation closure.

DPDP
Data Protection Board of India, under the DPDP Act

Lawful processing, breach notification and data-principal rights handling across your systems and processors.

DESC
Dubai Electronic Security Center

Dubai Cyber Security Standard alignment for entities operating in the emirate.

NCA
National Cybersecurity Authority, Saudi Arabia

Essential Cybersecurity Controls compliance for in-scope organisations.

Obligations summarised at the level the published directions state them. Which apply to you depends on your licence, sector and where you operate — establishing that map is month-one work.

First twelve months

Baseline by month one. Board sign-off by month two.

Stage 1
Onboarding (Month 1)
  • Stakeholder interviews (board, CEO, CTO, CFO, audit, legal, ops)
  • Asset, vendor and regulator inventory
  • Current-state risk register + maturity baseline (NIST CSF · ISO 27001)
  • 12-month security strategy + budget draft
Stage 2
Strategy ratification (Month 2)
  • Strategy presented to board / risk committee
  • Policy stack reviewed or rewritten (information security · acceptable use · incident response · vendor risk · DPDP / GDPR)
  • KRIs and KPIs agreed with leadership
Stage 3
Operate (Months 3–12)
  • Monthly risk-committee chair + quarterly board reporting
  • Regulator engagement (CERT-In · RBI · SEBI · DESC · NCA · DPDP)
  • Architecture review on every major change (cloud, third-party, product)
  • In-house team mentoring + recruitment / interview support
  • Incident command during High / Critical incidents
Stage 4
Annual cycle
  • Annual maturity reassessment + strategy refresh
  • Annual board pack + audit readiness sign-off
  • Succession-planning for in-house CISO hire (if applicable)
Engagement snapshots

Three shapes of the same problem.

Series-C Fintech (Bengaluru)

Scope · vCISO 2 days/week for 14 months

What happened · Built security from 1-person to 4-person team; passed SOC 2 Type 2 and SEBI CSCRF; supported successful Series-D due diligence

Strategic — avoided estimated ₹2.5 Cr/yr full-time CISO cost during pre-IPO scaling phase

Listed Insurance MNC (Mumbai BKC)

Scope · vCISO 4 days/week — interim coverage during in-house CISO transition

What happened · Continuity through 7-month CISO transition; chaired IRDAI inspection response; closed 14 of 17 audit observations before handover

Material — zero regulatory observation carried into the new CISO tenure

GCC SaaS (Dubai)

Scope · vCISO 1 day/week + 24×7 IR on-call

What happened · Built UAE PDPL + ISO 27001 program from scratch; passed ISO certification within 9 months of engagement

Strategic — unlocked GCC enterprise sales channel previously blocked on certification gap

Designed to end

When you hire a full-time CISO, that is the win.

Several of our vCISO engagements end in a recruited in-house CISO, and the outgoing vCISO runs that search. A provider whose incentive is to stay forever is the wrong provider for this role.

Writes the job description

Scoped to the organisation you have become during the engagement, not a template pulled off a job board.

Sits on the interview panel

Screens the shortlist on technical and board-facing capability, and advises on the package the market actually clears at.

Runs a 4–8 week handover

Risk register, regulator relationships, open audit observations and the board narrative all transfer deliberately.

Working stack

Your tools where you have them. Ours where you do not.

Risk treatment is tracked in the tracker your engineers already use. Where you already license a compliance-automation platform, the vCISO operates inside it rather than beside it.

Tools we operate
Macksofy risk-register platformVanta · Drata · Sprinto (compliance automation, if client-licensed)JIRA / Linear (risk-treatment tracking)Confluence / Notion (policy stack)
Retainer-based engagement

Senior CISO leadership, priced for your stage.

vCISO retainers run ₹4–18 L per month depending on day-count, seniority and regulatory footprint. 12-month minimum. Tell us where you are in your security journey and we’ll send a scoped proposal within 48 hours.

What's included

What the engagement covers

  • 12-month security strategy + budget signed off by board
  • Policy stack (10–14 core policies) — drafted or refreshed
  • Monthly risk-committee meetings chaired
  • Quarterly board pack (trend chart, top risks, regulator status, hiring plan)
  • Regulator interlocutor for CERT-In · RBI · SEBI · DPDP · DESC · NCA
  • Incident command during High / Critical events
  • Mentorship + interview support for in-house security hires
  • Annual maturity reassessment (NIST CSF + ISO 27001)
Industries

Sectors we operate in

Fintech & PaymentsSaaS & Product CompaniesBanking & Financial ServicesInsurance & InsurTechHealthcare & HealthTechE-commerce & D2CGovernment & PSUSeries-A to Series-D startups
What clients say · Trusted India + UAE

Empanelled by CERT-In. Accredited by EC-Council.

CERT-In Empanelled
Govt of India · MeitY
EC-Council ATC
Authorized Training
ISO 27001 Certified
Info Security Mgmt
CompTIA Authorized Partner
Training Delivery
We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.
LF
Information Security Manager
Listed Fintech · BKC, Mumbai
The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.
MP
Cyber Cell
Maharashtra Police · Mumbai
Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.
HS
DevSecOps Lead
Healthcare SaaS · Hyderabad
FAQ

What boards ask before approving this.

A senior practitioner. Macksofy vCISOs are 15–22 years experienced, every one of them has held an in-house CISO or Deputy CISO role at a regulated firm. We do not staff this with junior consultants. You meet the named vCISO before contract sign-off.
1, 2 or 4 days/week are standard. 1-day plans suit early-stage startups (governance + policy + board reporting). 4-day plans suit mid-market firms in active regulatory cycles or M&A. We don't sell hourly — the engagement is for outcomes, with time committed up-front.
Hybrid by default — typically 1 day/week on-site (Mumbai · Bengaluru · Delhi NCR · Dubai · Abu Dhabi) plus remote attendance at all leadership and risk-committee meetings. Fully on-site engagements are available for sensitive sectors.
Yes — they are your Incident Commander during High / Critical events, work alongside your IT lead, manage breach communications and regulator notifications, and bring in Macksofy DFIR forensics as needed under the same contract.
The vCISO supports the search — writes the JD, interviews shortlist, advises on package, then runs a structured 4–8 week handover. Several Macksofy vCISO engagements end in a recruited full-time CISO; that's a success metric, not a churn risk.
₹4–18 L per month depending on day-count and seniority. Quote within 48 hours of a discovery call. 12-month minimum.
Delivery footprint

Where Macksofy delivers vCISO.

On-site engagements across India's BFSI, fintech, government and SaaS metros plus the UAE. Senior consultants fly from Mumbai BKC for kickoff, key reviews and exit briefings; remote weeks run through the rest of the engagement.

References & standards

Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • Thousands of professionals trained
  • India + UAE engagements