Accepting new vCISO engagements | CyberCAAT Delivery Platform
CyberCAAT · The Governance Platform Behind Every Engagement

You're already spending on security. Can you prove it's working?

Most small and mid-sized businesses have the tools. What they don't have is anyone accountable for confirming those tools were set up properly and still work a year later. CyberCAAT is the governance layer that closes that gap — a complete security program, pre-built, run by a virtual CISO who reports to you and answers to no one else.

SDVOSB · Established 2008 · 1,000+ risk assessments delivered

CyberCAAT unified control framework
01 — The Problem

Security spending is not the same as security assurance.

The failure is rarely dramatic. It looks like this:

The project finishes.

Nobody schedules the review that keeps it working.

The backups run.

Nobody has ever tried restoring one.

Access gets reviewed.

Once, during an audit. Then never again.

Two years later the organization is measurably weaker than the day it finished spending — and nobody noticed, because nobody was looking. More tooling does not fix that. Accountability and evidence do.

02 — What You Get

A complete security program, without building one.

A large enterprise runs governance with a control framework, a scored risk baseline, a policy set, a scheduled calendar of security work, and an evidence library. Those components are well understood. The reason smaller organizations don't have them is cost, not complexity. CyberCAAT supplies them pre-built — you pay to have them scoped, assessed, activated and run, not invented.

Know where you stand.

A scored assessment of your security against the frameworks your customers, insurers and regulators care about. One pass, one baseline, one number an executive can act on.

Know what to fix first.

Findings become a ranked, sized work list with owners, deadlines and a defined test for “done” — not a 60-page report nobody actions.

Know it keeps working.

113 scheduled security processes, each with a named owner, a cadence, and a defined piece of evidence proving it happened.

Prove it to anyone who asks.

An evidence library you own and can hand to an insurer, a customer, an auditor or an acquirer — without a scramble.

03 — How It Works

Four steps. Then it runs.

01 · Scope

We establish what applies to your business. Your industry, systems, data and obligations decide which controls are in scope. Nothing is assessed that doesn't matter to you.

1–2 weeks
02 · Assess

A qualified assessor scores every in-scope control against evidence, not assertion. You get a baseline and a gap analysis your board can read.

6 weeks
03 · Activate

Policies are issued, the security calendar is loaded, and every recurring task gets an owner — your IT team, your MSP, your monitoring provider, or us.

Separate engagement
04 · Run and prove

The calendar runs. We oversee the work, chase the evidence, and report to your executive quarterly. At month twelve we reassess, and the movement is the proof.

Ongoing
04 — Who Does What

We govern the program. Your team and providers run the operations.

This is the part most people ask about, so here it is plainly. Of 113 scheduled processes, the virtual CISO performs 42 — governance, risk, policy, supplier assurance and executive reporting. The other 71 are performed by your own IT staff, your MSP, your monitoring provider, HR, Legal or a specialist. We set the requirement, define what evidence proves it, review what comes back, and escalate what doesn't.

Deliver

42 processes

We perform it. Governance, risk, policy, supplier assurance, executive reporting.

Oversee

Governed by us

Your team or provider performs it; we set the standard and check the result.

Delegate

Verified by us

Routine operational work performed by others; we sample and confirm the control operated.

Why you can trust our reporting. The virtual CISO holds no authority over anyone who does the work. We cannot hire, direct, discipline, contract or budget for your staff or your providers. Approval of risk sits with an executive of yours, outside IT and security. Your evidence library stays yours — portable, and available to any external party you appoint. We are not marking our own homework, because we don't do the work.
Partnered, never built. Penetration testing, forensic investigation, 24×7 monitoring and audit attestation stay with specialist providers. We govern their output — because a firm that runs the SOC cannot credibly govern the SOC.

The virtual CISO / Operations boundary

Everything above the boundary is the practice. Everything below is Operations. Every layer derives from the one above it, making the chain traceable in both directions.

  • Planning document
  • Risk assessment
  • Gap analysis
  • Corrective action plan
  • Policies
  • Process list
  • Process steps
Practice above · Operations below
  • Runbooks
  • SOPs
  • Evidence
05 — Proof

You shouldn't have to wait a year to know it's working.

The strongest proof is maturity movement between two assessments, and that arrives at month twelve. We're not going to pretend otherwise. Here is what you see before then:

Quarter 1

Corrective actions closing in priority order. Evidence arriving on schedule.

Quarter 2

Governance foundation complete. Remediated controls re-scored. Provider performance measured against what their contract implies.

On demand

A customer questionnaire or insurance renewal answered from your evidence set instead of from memory.

Month 12

Full reassessment on the same framework and scope. The movement is the return on the year's spending.

06 — Why This Is Different

Not another tool. Not another audit.

201 controls · 9 authoritative sources

Assessed once, reported against every framework that control answers. NIST CSF 2.0, ISO/IEC 27001:2022 and CIS Controls v8.1 are covered simultaneously by 173 of them.

113 scheduled processes

Every obligation your policies create, consolidated into scheduled work with an owner, a cadence and defined evidence.

54 of 56

CIS essential cyber hygiene safeguards covered. The baseline insurers and customers ask about first.

Frameworks covered today: NIST CSF 2.0 · ISO/IEC 27001:2022 Annex A · CIS Controls v8.1 · ISO/IEC 27701 · NIST AI RMF · ISO/IEC 42001 · NIST SP 800-218 · ISA/IEC 62443 · ISO/IEC 27035-2

Working to a framework not listed — CJIS, FFIEC, FDIC, CMMC, HITRUST, PCI DSS? These are absorbed into the same control set on engagement rather than assessed as a separate program. Ask in the briefing.

A mapping means two requirements address related outcomes. It does not mean satisfying one satisfies the other in the eyes of a regulator. Our assessment is internal and first-party — the kind ISO 27001, HIPAA and NIST all require you to perform. Where certification or attestation is needed, an accredited external body does that, and we make their job short.
07 — Pricing

Priced for the organization you actually are.

A full-time chief information security officer costs $250,000 to $400,000 a year, and one person still cannot cover governance, provider oversight, assessment and supplier assurance at the same time. A CyberCAAT program starts at $2,600 per month, scaled to your size and the scope you need, with a separate platform license from $500 per month and a one-off onboarding engagement.

Essential

Governance layer only

The governance layer, delivered by us. For smaller organizations, or where the IT function is capable but ungoverned.

Comprehensive

Everything, plus AI and operational technology scope

Broader scope including AI and operational technology. Where a regulator, contract or acquirer requires it.

The retainer does not remove your team's operational work. It makes that work auditable.

Get pricing for your organization →
08 — Founder

Bill Leach, Jr.

Owner · Practicing Virtual CISO · U.S. Navy Veteran

CISSP · CRISC · CGEIT · CMMC-CP · PMP · CSM

Service-Disabled Veteran-Owned Small Business · Established June 2008

Technical Detail

Want the detail?

The CyberCAAT Technical Brief covers the full control mapping, the 17 domains, the process register, activation sequencing, and complete package pricing. (Email required.)

09 — Briefing

Start with a complimentary pre-assessment.

Every meaningful engagement begins with a short diagnostic. Share a few details about your organization and current posture — we'll respond within two business days with a no-cost briefing and a scoped path forward tailored to your environment, regulatory exposure, and priorities.

01 About Your Organization
02 Your Information
03 CyberCAAT Fit

Request received.

Your pre-assessment request has been sent. Bill will review your diagnostic and reach out within two business days to schedule your briefing.