
ארגון של עשרות עד כמה מאות עובדים צריך מישהו שאחראי על אבטחת המידע באופן אישי: שמכיר את המערכות, יושב בוועדת ההיגוי, עומד מול הרגולטור, הלקוחות והמבטח, ודואג שההחלטות מתבצעות. לרוב הארגונים האלה משרה מלאה היא יותר ממה שהם צריכים. שירות ה-CISO החיצוני נותן את התפקיד הזה בהיקף שמתאים לארגון, עם תוכנית עבודה שנתית, דיווח חודשי ואחריות אישית של יועץ אחד שמכיר אתכם.
An organization of tens to a few hundred employees needs someone personally accountable for information security: someone who knows the systems, sits on the steering committee, faces the regulator, customers and insurers, and makes sure decisions are carried out. For most of these organizations a full-time position is more than they need. The virtual CISO service provides that role at a scale that fits the organization, with an annual work plan, monthly reporting and the personal accountability of one consultant who knows you.

הערכת מצב פתיחה, הגדרת יעדים לשנה לפי סיכון ורגולציה, תקציב ואבני דרך, מאושרת על ידי ההנהלה ונבדקת רבעונית.
Roadmap · תקציבימי עבודה קבועים בחודש, בארגון או מרחוק: טיפול בשוטף, ייעוץ לצוות ה-IT, סקירת שינויים ופרויקטים, ומענה לשאלות ההנהלה והעובדים.
היקף קבוע · זמינותישיבת היגוי רבעונית, דוח סטטוס חודשי, רישום סיכונים מתעדכן ומצגת שנתית לדירקטוריון, בשפה עסקית ולא טכנית.
Governanceאחריות על מערך המסמכים והבקרות: עדכון שנתי, התאמה לשינויים בארגון וברגולציה, ובדיקה שהנהלים באמת מיושמים.
ISO 27001 · תקנות אבטחת מידעהערכת ספקים לפני התקשרות, נספחי אבטחה בחוזים, ליווי בביקורות של לקוחות, מבטחים ורגולטורים, ומענה לשאלוני אבטחה.
Third parties · Auditsייצוג הארגון מול הרשות להגנת הפרטיות ומערך הסייבר, מענה לדרישות אבטחה של לקוחות גדולים, וליווי בתהליכי הסמכה.
Regulators · CustomersBaseline assessment, yearly objectives set by risk and regulation, budget and milestones, approved by management and reviewed quarterly.
Roadmap · BudgetFixed working days each month, on site or remote: day-to-day issues, guidance for the IT team, review of changes and projects, and answers for management and staff.
Fixed scope · AvailabilityQuarterly steering meeting, monthly status report, a living risk register and an annual board presentation, in business language rather than technical jargon.
GovernanceOwnership of the document set and controls: annual update, adaptation to organizational and regulatory change, and verification that procedures are actually followed.
ISO 27001 · Data Security RegulationsVendor assessment before engagement, security annexes in contracts, support through customer, insurer and regulator audits, and responses to security questionnaires.
Third parties · AuditsRepresenting the organization before the Privacy Protection Authority and the National Cyber Directorate, meeting the security requirements of large customers, and guiding certification processes.
Regulators · Customersשנה של ליווי בנויה כמחזור: מעריכים, מתכננים, מבצעים, מדווחים, ומעדכנים.
סקר פתיחה של המערכות, הנהלים, הספקים והרגולציה שחלה, ומפת פערים ראשונית.
יעדים, תקציב ואבני דרך לשנה, מתועדפים לפי סיכון, מאושרים בהנהלה.
ימי ליווי קבועים, ניהול המשימות מול צוות ה-IT והספקים, ומענה שוטף.
ועדת היגוי, עדכון רישום הסיכונים ודוח התקדמות מול התוכנית.
סיכום שנה, מדידה מול היעדים, ובניית התוכנית לשנה הבאה.
A year of engagement runs as a cycle: assess, plan, execute, report, update.
Opening review of systems, procedures, vendors and applicable regulation, and an initial gap map.
Objectives, budget and milestones for the year, prioritized by risk, approved by management.
Fixed engagement days, task management with the IT team and vendors, and ongoing support.
Steering committee, risk register update and progress report against the plan.
Year-end summary, measurement against objectives, and the plan for the coming year.
שיחת היכרות קצרה, ואחריה הצעה להיקף ליווי שמתאים לגודל הארגון ולסיכונים שלו.
לחץ כאן ליצירת קשרA short intro call, followed by a proposal for an engagement scope that fits the organization's size and risks.
Contact us