ARMOR

CISO חיצוני

Virtual CISO
מנהל אבטחת מידע במיקור חוץ · ליווי חודשי קבוע · תוכנית עבודה שנתית · דיווח להנהלה

Virtual CISO

Outsourced information security leadership
Fixed monthly engagement · Annual work plan · Board-level reporting · One accountable consultant
ARMOR IT & SECURITY LTD.

מנהל אבטחת מידע, בלי משרה מלאה

ארגון של עשרות עד כמה מאות עובדים צריך מישהו שאחראי על אבטחת המידע באופן אישי: שמכיר את המערכות, יושב בוועדת ההיגוי, עומד מול הרגולטור, הלקוחות והמבטח, ודואג שההחלטות מתבצעות. לרוב הארגונים האלה משרה מלאה היא יותר ממה שהם צריכים. שירות ה-CISO החיצוני נותן את התפקיד הזה בהיקף שמתאים לארגון, עם תוכנית עבודה שנתית, דיווח חודשי ואחריות אישית של יועץ אחד שמכיר אתכם.

ARMOR IT & SECURITY LTD.

A security leader, without the full-time position

An organization of tens to a few hundred employees needs someone personally accountable for information security: someone who knows the systems, sits on the steering committee, faces the regulator, customers and insurers, and makes sure decisions are carried out. For most of these organizations a full-time position is more than they need. The virtual CISO service provides that role at a scale that fits the organization, with an annual work plan, monthly reporting and the personal accountability of one consultant who knows you.

SCOPE

מה כולל השירות

תוכנית עבודה שנתית

הערכת מצב פתיחה, הגדרת יעדים לשנה לפי סיכון ורגולציה, תקציב ואבני דרך, מאושרת על ידי ההנהלה ונבדקת רבעונית.

Roadmap · תקציב

ליווי חודשי קבוע

ימי עבודה קבועים בחודש, בארגון או מרחוק: טיפול בשוטף, ייעוץ לצוות ה-IT, סקירת שינויים ופרויקטים, ומענה לשאלות ההנהלה והעובדים.

היקף קבוע · זמינות

ועדת היגוי ודיווח להנהלה

ישיבת היגוי רבעונית, דוח סטטוס חודשי, רישום סיכונים מתעדכן ומצגת שנתית לדירקטוריון, בשפה עסקית ולא טכנית.

Governance

מדיניות, נהלים ובקרות

אחריות על מערך המסמכים והבקרות: עדכון שנתי, התאמה לשינויים בארגון וברגולציה, ובדיקה שהנהלים באמת מיושמים.

ISO 27001 · תקנות אבטחת מידע

ניהול ספקים וביקורות

הערכת ספקים לפני התקשרות, נספחי אבטחה בחוזים, ליווי בביקורות של לקוחות, מבטחים ורגולטורים, ומענה לשאלוני אבטחה.

Third parties · Audits

ממשק מול רגולטורים ולקוחות

ייצוג הארגון מול הרשות להגנת הפרטיות ומערך הסייבר, מענה לדרישות אבטחה של לקוחות גדולים, וליווי בתהליכי הסמכה.

Regulators · Customers
SCOPE

What the service covers

Annual work plan

Baseline assessment, yearly objectives set by risk and regulation, budget and milestones, approved by management and reviewed quarterly.

Roadmap · Budget

Fixed monthly engagement

Fixed working days each month, on site or remote: day-to-day issues, guidance for the IT team, review of changes and projects, and answers for management and staff.

Fixed scope · Availability

Steering committee and reporting

Quarterly steering meeting, monthly status report, a living risk register and an annual board presentation, in business language rather than technical jargon.

Governance

Policies, procedures and controls

Ownership of the document set and controls: annual update, adaptation to organizational and regulatory change, and verification that procedures are actually followed.

ISO 27001 · Data Security Regulations

Vendor management and audits

Vendor assessment before engagement, security annexes in contracts, support through customer, insurer and regulator audits, and responses to security questionnaires.

Third parties · Audits

Interface with regulators and customers

Representing the organization before the Privacy Protection Authority and the National Cyber Directorate, meeting the security requirements of large customers, and guiding certification processes.

Regulators · Customers
METHOD

איך אנחנו עובדים

שנה של ליווי בנויה כמחזור: מעריכים, מתכננים, מבצעים, מדווחים, ומעדכנים.

1

הערכת מצב

סקר פתיחה של המערכות, הנהלים, הספקים והרגולציה שחלה, ומפת פערים ראשונית.

2

תוכנית שנתית

יעדים, תקציב ואבני דרך לשנה, מתועדפים לפי סיכון, מאושרים בהנהלה.

3

ביצוע חודשי

ימי ליווי קבועים, ניהול המשימות מול צוות ה-IT והספקים, ומענה שוטף.

4

דיווח רבעוני

ועדת היגוי, עדכון רישום הסיכונים ודוח התקדמות מול התוכנית.

5

עדכון שנתי

סיכום שנה, מדידה מול היעדים, ובניית התוכנית לשנה הבאה.

METHOD

How we work

A year of engagement runs as a cycle: assess, plan, execute, report, update.

1

Baseline

Opening review of systems, procedures, vendors and applicable regulation, and an initial gap map.

2

Annual plan

Objectives, budget and milestones for the year, prioritized by risk, approved by management.

3

Monthly execution

Fixed engagement days, task management with the IT team and vendors, and ongoing support.

4

Quarterly reporting

Steering committee, risk register update and progress report against the plan.

5

Annual review

Year-end summary, measurement against objectives, and the plan for the coming year.

STANDARDS

תקנים ורגולציה

תורת ההגנה בסייבר 2.0 · מערך הסייבר הלאומיתקנות הגנת הפרטיות (אבטחת מידע) 2017תיקון 13 לחוק הגנת הפרטיותISO/IEC 27001:2022NIST CSF 2.0CIS Controls v8

תוצרים

  • תוכנית עבודה שנתית מאושרת הנהלה
  • דוח סטטוס חודשי ורישום סיכונים מתעדכן
  • מצגת רבעונית לוועדת ההיגוי ושנתית לדירקטוריון
  • מערך מדיניות ונהלים מעודכן
  • תיק אבטחה ארגוני מוכן לביקורת של לקוח, מבטח או רגולטור

התחייבויות

  • יועץ אחד קבוע. אותו אדם מלווה את הארגון לאורך כל השנה ומכיר את המערכות, האנשים וההיסטוריה.
  • עצמאות מספקים. ההמלצה היא תמיד מה שנכון לארגון, כי אנחנו יועצים ולא משווקים.
  • היקף שקוף. מספר ימי הליווי בחודש מוגדר מראש, וכל חריגה מתואמת ומאושרת לפני שהיא קורית.
  • סודיות. כל מה שנחשף בעבודה מטופל תחת הסכם סודיות, גם מול ספקים ומבטחים.
STANDARDS

Standards and regulation

INCD Cyber Defense Doctrine 2.0Privacy Protection Regulations (Data Security) 2017Amendment 13 to the Privacy Protection LawISO/IEC 27001:2022NIST CSF 2.0CIS Controls v8

Deliverables

  • Annual work plan approved by management
  • Monthly status report and a living risk register
  • Quarterly steering presentation and annual board presentation
  • Up-to-date policy and procedure set
  • Organizational security file ready for a customer, insurer or regulator audit

Our commitments

  • One permanent consultant. The same person accompanies the organization all year and knows the systems, the people and the history.
  • Vendor independence. The recommendation is always what is right for the organization, because we are advisors, not resellers.
  • Transparent scope. The number of engagement days per month is set in advance, and any extra work is agreed before it happens.
  • Confidentiality. Everything we see is handled under NDA, including toward vendors and insurers.

בואו נבנה את השנה הקרובה

שיחת היכרות קצרה, ואחריה הצעה להיקף ליווי שמתאים לגודל הארגון ולסיכונים שלו.

לחץ כאן ליצירת קשר
ארמור אי.טי. אנד סקיוריטי בע"מ · רחוב תוצרת הארץ 3, פתח תקווה · info@armor.co.il

חזרה לכל השירותים

Let's plan the coming year

A short intro call, followed by a proposal for an engagement scope that fits the organization's size and risks.

Contact us
Armor IT & Security Ltd. · 3 Totzeret HaAretz St., Petah Tikva, Israel · info@armor.co.il

Back to all services
כל הזכויות שמורות לחברת ארמור בע"מ © 2026 · מדיניות פרטיות · הצהרת נגישות© 2026 Armor IT & Security Ltd. All rights reserved. · Privacy policy · Accessibility