Skip to content

    Articles tagged: Security Program

    8 articles on Security Program from the Top Floor insights library.

    • 2026-08-25

      What Does a vCISO Cost?

      Almost every vCISO price you can find online is either a lead magnet or an average of unpublished retainers. Here are our published tiers, the engagement arithmetic one platform vendor has actually printed, and the questions that tell you what a retainer really buys.

    • 2026-08-23

      How to Write an AI Acceptable Use Policy

      Six sections and two pages. ISACA's 2026 research puts formal AI policy adoption at 38 percent against 90 percent believing employees already use AI, which means most organizations are governing the tools after the fact rather than before.

    • 2026-08-23

      What Belongs in an AI System Inventory

      Nine fields, one row per system, and a definition of system that includes the tools you did not buy. The inventory is the artifact every AI governance framework assumes you have and the one companies most often do not.

    • 2026-08-20

      What Should a vCISO Deliver in the First 90 Days?

      Four artifacts by day 90: a real inventory, a risk assessment with a prioritized and costed roadmap, a first tranche of closed gaps, and a report you could hand an investor or an insurer. If all you have is policy templates, you bought documents.

    • 2026-08-19

      How Many vCISO Hours a Month Do You Actually Need?

      Published engagement data puts a typical vCISO client at 20 to 40 hours a month, clustering at 20 to 30. What drives the number for your situation, and why it should fall after a build phase rather than sit flat forever.

    • 2026-08-18

      How to Choose a vCISO: The Questions That Separate Providers

      Ranked lists of vCISO firms are written by vCISO firms. Here are the four question groups that actually discriminate, including the client-load arithmetic a vCISO platform vendor published against its own category.

    • 2026-08-17

      vCISO or Full-Time CISO: Which Does Your Company Need?

      Headcount and revenue are the wrong triggers. The honest test for hiring a full-time CISO is whether security leadership generates decisions every day, and at most companies asking this question it does not yet.

    • 2026-03-24

      Virtual CISO: When Your Organization Needs Fractional Security Leadership

      A full-time CISO at a small or midmarket company averages $415K in total compensation, but most mid-market organizations need strategic security leadership without the executive price tag. Here is how a virtual CISO works, what they deliver, and when the model makes sense.